Cybatar Security Hub
Exposure Management / EPSS prioritisation
Exposure-management guide

Using EPSS in Vulnerability Prioritisation

What does an EPSS score mean, and how should it be used?

Direct answer

EPSS estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Use it to help rank remediation effort, especially when combined with known exploitation, technical severity and asset context. Do not treat EPSS as a complete risk score or as a prediction about a specific asset.

External reference

Forum of Incident Response and Security Teams (FIRST) — Exploit Prediction Scoring System (EPSS)

FIRST describes EPSS as a data-driven model that estimates the probability of a published CVE being exploited in the wild in the next 30 days, with scores updated daily. FIRST also states that EPSS is not a complete risk score.

Primary source →

Practical workflow

Step 1

Use current scores

Because EPSS is updated daily, retain the score date with the decision rather than treating an old probability as permanently valid.

Step 2

Separate probability from impact

EPSS estimates exploitation likelihood; asset criticality, business consequence and compensating controls must be assessed separately.

Step 3

Combine with known exploitation

A KEV listing provides observed-exploitation evidence and should be distinguished from a probabilistic EPSS signal.

Step 4

Combine with technical severity

CVSS communicates vulnerability characteristics and severity; EPSS answers a different question about exploitation probability.

Step 5

Record the decision trail

Retain the score/date, affected assets, contextual factors, treatment decision and any threshold or exception used by the organisation.

Relevant Cybatar sources

Claim boundary

EPSS does not measure business impact, prove that a specific system will be attacked, or replace asset and environmental context. Cybatar does not claim to own, certify or independently validate the EPSS model.

These pages are Cybatar-authored exposure-management and vulnerability-prioritisation guidance. CISA, FIRST and NIST are external sources. References do not create certification, endorsement, guaranteed exploit prediction, guaranteed remediation outcomes or proof that a vulnerability affects a specific environment.

Evidence