Back to glossary

EPSS

2 min read

In vulnerability prioritisation, EPSS is the Exploit Prediction Scoring System: a model published by FIRST that estimates the probability a given vulnerability will be exploited in the wild in the near term. It answers how likely, where severity scoring answers how bad, and the two questions have different answers.

July 29, 2026
Compartir:

How it works

EPSS produces, for a catalogued vulnerability identifier, a probability between zero and one that exploitation activity will be observed in the next thirty days. The model is trained on observed exploitation together with features drawn from the vulnerability’s published characteristics, the affected product, the existence of public exploit code and other signals, and the scores are recalculated daily, so a value is a snapshot rather than a permanent attribute.

Alongside the probability, the published data includes a percentile, which is often the more usable figure in practice because it places the vulnerability against the whole population rather than asking anyone to interpret a small decimal.

What goes wrong

Three misreadings, all of which we have had to correct in client meetings. It is not a severity score and it does not replace CVSS: a flaw can be near-certain to be exploited and trivial in impact, or catastrophic and of no interest to anyone with a botnet. Using either number alone produces a bad queue, and using both produces a good one.

It is not a statement about your estate. The probability concerns exploitation activity in the world, not against you, so reachability and asset value still have to be applied on top. And it is a prediction, so it will be wrong in individual cases; the value is in ordering thousands of items, not in deciding a single one.

The sharpest point comes last. EPSS is a forecast; the KEV catalogue is an observation. When something appears in the catalogue the question of probability is closed, and the catalogue wins.

Where this shows up in an audit

When we hand back a queue we sort it by exploitability and reachability rather than by severity, and we say which signal moved each item, so a client can reproduce the ordering. It matters most on an external estate, where the number of missing patches is large and the number that a commodity attacker will actually reach for is small. Where a client’s programme still sorts by base score alone, that is written up as a finding about the process rather than about a host, because it is the process that produced the backlog. This is part of how we decide what to fix first on an internet-facing estate.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.