EPSS estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Use it to help rank remediation effort, especially when combined with known exploitation, technical severity and asset context. Do not treat EPSS as a complete risk score or as a prediction about a specific asset.
External reference
FIRST describes EPSS as a data-driven model that estimates the probability of a published CVE being exploited in the wild in the next 30 days, with scores updated daily. FIRST also states that EPSS is not a complete risk score.
Primary source →Practical workflow
Use current scores
Because EPSS is updated daily, retain the score date with the decision rather than treating an old probability as permanently valid.
Separate probability from impact
EPSS estimates exploitation likelihood; asset criticality, business consequence and compensating controls must be assessed separately.
Combine with known exploitation
A KEV listing provides observed-exploitation evidence and should be distinguished from a probabilistic EPSS signal.
Combine with technical severity
CVSS communicates vulnerability characteristics and severity; EPSS answers a different question about exploitation probability.
Record the decision trail
Retain the score/date, affected assets, contextual factors, treatment decision and any threshold or exception used by the organisation.
Relevant Cybatar sources
Claim boundary
EPSS does not measure business impact, prove that a specific system will be attacked, or replace asset and environmental context. Cybatar does not claim to own, certify or independently validate the EPSS model.
These pages are Cybatar-authored exposure-management and vulnerability-prioritisation guidance. CISA, FIRST and NIST are external sources. References do not create certification, endorsement, guaranteed exploit prediction, guaranteed remediation outcomes or proof that a vulnerability affects a specific environment.