Vulnerabilities
EPSS: what the Exploit Prediction Scoring System tells you
Most CVEs are never exploited. EPSS estimates which ones will be. It gives every published CVE a daily probability of exploitation in the next 30 days, so you can rank a backlog by likelihood instead of by severity alone.
Updated
What is EPSS?
The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability that a published CVE will be exploited in the wild in the next 30 days. It is maintained by the EPSS Special Interest Group at FIRST, the same forum that publishes CVSS. Scores are generated by Empirical Security and published free of charge, with no registration.
Every day, each published CVE gets two numbers:
- Probability, from 0 to 1. The estimated chance of exploitation activity in the next 30 days. 0.02 means 2%.
- Percentile, from 0 to 1. The share of all scored CVEs with the same or a lower probability. It tells you where a CVE ranks, not how likely it is to be exploited.
Scores move. A CVE can sit near zero for months and jump overnight when exploit code is published or attacks are observed, so read them daily rather than once at triage.
How EPSS is calculated
EPSS is a machine-learning model trained on observed exploitation. FIRST describes about 2,850 input features in five groups:
- Exploit code and tooling: public exploits, exploitation frameworks, scanner templates.
- Chatter: mentions by security vendors, disclosure programs and aggregators.
- Vulnerability characteristics: the individual CVSS metrics and tags from the description. The CVSS score itself is not used.
- Age and references: how old the CVE is and how many references it has.
- Exploitation activity: malware telemetry, honeypots, intrusion detection and threat intelligence from data partners.
The current model is EPSS v5 (v2026.06.15), published since June 15, 2026. Earlier versions were v4 (March 2025), v3 (March 2023) and v2 (February 2022). FIRST retrains when performance degrades, not on a fixed calendar.
EPSS vs CVSS
| EPSS | CVSS | |
|---|---|---|
| Measures | Likelihood of exploitation in the next 30 days | Severity if exploited |
| Scale | Probability 0 to 1, plus a percentile | 0 to 10, with severity ratings |
| Changes | Daily, as threat data changes | Rarely; the base score is fixed per CVE |
| Produced by | A model trained on observed exploitation | Expert judgment against a specification |
| Current version | v5 (2026) | 4.0 (2023) |
FIRST is clear that the two are not interchangeable. CVSS base scores measure severity, not risk, and should not be used alone for patch prioritization. EPSS is not a severity score and not a complete risk score either. And multiplying them together, FIRST warns, is never a good idea: one is a calibrated probability, the other an ordinal ranking. Use them side by side.
EPSS thresholds
EPSS has no official cutoff. FIRST publishes reference points that help you pick one:
| EPSS probability | Roughly |
|---|---|
| 0.10 (10%) | 95th percentile. Commonly cited, but with no special authority from EPSS. |
| 0.04 (4%) | 90th percentile. A queue about the size of the one CVSS critical would give you. |
| 0.008 (0.8%) | About the top 48%. A queue about the size of CVSS high and critical combined. |
| 0.007 (0.7%) | The median. Half of all CVEs score lower. |
Work backward from capacity. If your team can handle fifty urgent findings a month, choose the threshold that produces about fifty in the software you ship.
How to use EPSS for prioritization
- Start with confirmed exploitation. A CVE in CISA's KEV catalog is being exploited already. FIRST itself says recent confirmed exploitation is a strong signal on its own, whatever the score.
- Rank the rest by EPSS, above your chosen threshold first.
- Break ties with CVSS and your context: whether the component ships, whether it is exposed, and how important the product is.
- Re-rank daily, because EPSS does.
The full method, with where SSVC and reachability fit, is in vulnerability prioritization.
Limits of EPSS
- It does not know your environment. A high score says the CVE is likely to be exploited somewhere, not that the vulnerable code is present, reachable or important in your product.
- Published CVEs only. Vulnerabilities without a CVE, and reserved CVE IDs, get no score.
- It is a forecast. Low scores are not guarantees, which is why KEV and other exploitation evidence come first.
How to get EPSS scores
- API:
https://api.first.org/data/v1/epss?cve=CVE-2021-44228returns the current probability and percentile. Add&scope=time-seriesfor the history. The API is meant for lookups, not bulk access. - Daily CSV: the full list of scores, updated shortly after 13:30 UTC, with an archive back to 2021.
- Your tools: many scanners and vulnerability management platforms show EPSS next to their findings, among them Grype, Dependency-Track, Tenable and Qualys.
EPSS needs an accurate inventory
An EPSS score ranks a CVE. It cannot tell you whether you ship the affected package. That comes from your inventory, and a scanner that reads lockfiles reports development dependencies that never ship while missing packages the build downloaded outside the package manager.
CRACI records the packages each GitHub Actions job actually fetched, including transitive dependencies, packages restored from caches and hidden dependencies no lockfile lists, and re-evaluates monitored SBOMs continuously. Build history shows which past builds contained a vulnerable dependency, so when a CVE's score jumps you know which releases carry it. See vulnerability tracking.
EPSS: frequently asked questions
What is EPSS?
EPSS, the Exploit Prediction Scoring System, is a machine-learning model maintained by FIRST that estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Scores are published daily, for every CVE, free of charge.
What is a good EPSS score?
There is no universal cutoff. FIRST says a probability of about 0.04 (4%) sits around the 90th percentile, roughly the share of CVEs that CVSS would rate critical, and 0.10 (10%) sits around the 95th percentile. The mean score is about 2.8% and the median about 0.7%. Pick the threshold that gives your team a queue it can clear.
What is the difference between the EPSS probability and percentile?
The probability is the model's estimate that the CVE will be exploited in the next 30 days. The percentile ranks that probability against all other scored CVEs. A probability of 0.05 can be a high percentile, because most CVEs score far lower.
Should I multiply EPSS by CVSS?
No. FIRST says multiplying the two never gives probability times severity, because EPSS is a calibrated probability and CVSS is an ordinal ranking. Use them side by side instead: EPSS for likelihood, CVSS for severity.
What is the current EPSS version?
EPSS v5 (model v2026.06.15), published since June 15, 2026. FIRST retrains the model when its performance degrades, which has historically been about once a year.
How do I get EPSS scores?
Query the FIRST API, for example https://api.first.org/data/v1/epss?cve=CVE-2021-44228, or download the daily CSV of all scores. No registration is needed. Many scanners, including Grype, also show EPSS next to their findings.
Know which vulnerable packages you actually ship
An EPSS score ranks a CVE. Book a demo to see which of your GitHub Actions builds contain it, from a record of what each build fetched.
Book a demo