← Academy

Exploit Prediction Scoring System (EPSS)

EPSS predicts exploitation, CVSS scores severity. Where they disagree, how to combine them, and what to do when both say critical.

February 20, 2025
Exploit Prediction Scoring System (EPSS)

What is the Exploit Prediction Scoring System (EPSS)?

The Exploit Prediction Scoring System (EPSS) is a vulnerability management framework developed in 2019 that’s managed by the Forum of Incident Response and Security Teams (FIRST).

Using a machine learning model trained on comprehensive data ranging from vendor reports to white hat research, the EPSS estimates the probability that a vulnerability will be exploited within thirty days, reflected as a percentile score.

The model assigns this score to each newly discovered vulnerability based on over 1100 variables.

The EPSS is updated daily and can be downloaded from FIRST’s website in CSV format. Vulnerabilities in the EPSS are categorized by their Common Vulnerabilities and Exposures (CVE) identifiers per MITRE’s CVE List. Each vulnerability is also assigned two scores:

In addition to a percentile score, the EPSS groups vulnerabilities into one of four categories:

True Negatives: Vulnerabilities with a low EPSS score and no exploits in observed data.

Why EPSS is Important for Vulnerability Management

From a security perspective, EPSS is important because it supports better, more accurate vulnerability remediation.

Because the EPSS model is trained on real-world exploitation attempts and vulnerability databases, it can accurately predict how likely threat actors are to exploit a vulnerability. This adds valuable context to metrics, such as the Common Vulnerability Scoring System (CVSS), allowing teams to avoid wasting time and energy remediating vulnerabilities where exploitation is unlikely.

How the EPSS Model Works

When evaluating a vulnerability, the EPSS first ingests data on the vulnerability’s age, MITRE CVE listing, CVSS score, Common Weakness Enumeration (CWE), and associated vendor. The model also draws from the National Vulnerability Database and pulls data from security vendors, government agencies, exploitation records, and vulnerability databases. Other sources include the Cybersecurity and Infrastructure Agency’s (CISA’s) Known Exploited Vulnerabilities catalog and data gathered by FIRST and its partners.

The EPSS model processes and analyzes this data to generate a score for each vulnerability.

EPSS vs. Traditional Vulnerability Scoring Systems

EPSS differs from other vulnerability scoring systems in a few ways.

It’s measured as a percentage, representing the chance bad actors will exploit a vulnerability.

It’s also open-source and leverages machine learning for scoring, further setting it apart from traditional scoring.

EPSS vs. CVSS

FIRST also manages the Common Vulnerability Scoring System. This system measures how much damage a vulnerability can do if it’s exploited, a metric known as severity.

The system assigns vulnerabilities a severity score of 0-10, with 10 being the highest. The severity score is calculated based on the following groups of metrics:

Each CVSS vulnerability fits into one of four severity levels: None (0), Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9), or Critical (9.0-10.0).

EPSS vs. CWSS

The Common Weakness Scoring System (CWSS), developed as part of the Common Weakness Enumeration (CWE) project, measures flaws or security errors in software, known as weaknesses.

While not themselves vulnerabilities, these weaknesses are potentially exploitable by threat actors.MITRE created CWSS as a companion to its Common Weakness Enumeration (CWE) framework. This system is measured across three categories:

To calculate CWSS, each category is assigned a weighted subscore multiplied by the three scores to produce a score between 0 and 100.

Frequently Asked Questions

What is the Exploit Prediction Scoring System (EPSS)?

The Exploit Prediction Scoring System (EPSS) is a data-driven framework developed in 2019 by FIRST to predict how likely a vulnerability will be exploited in the wild within the next 30 days. Scores range from 0 to 1 indicating probability, and are ranked as percentiles to help security teams prioritize effectively.

How does EPSS differ from CVSS?

CVSS (Common Vulnerability Scoring System) measures the severity of a vulnerability based on its potential impact (e.g., damage, access complexity), using a 0 to 10 scale. EPSS, on the other hand, predicts real-world exploit likelihood, not severity, providing a complementary perspective focused on actual attacker behavior.

What data sources are used in EPSS scoring?

EPSS trains a machine learning model on data drawn from CVE details, CVSS, CWE, vendor reports, security vendor, and government databases (such as CISA’s Known Exploited Vulnerabilities), and real-world exploit telemetry.

How often is the EPSS score updated?

Scores are refreshed daily and published in a downloadable CSV via FIRST’s EPSS portal. This frequent update allows teams to respond quickly as new exploitation trends emerge.

Can organizations reliably use EPSS for vulnerability prioritization?

Yes. EPSS has demonstrated strong predictive accuracy. The current model achieves approximately an 82% performance improvement in distinguishing exploited vulnerabilities over earlier versions. Many security teams use it to focus remediation on vulnerabilities with higher real-world threat potential.

Are there limitations to using EPSS?

EPSS predicts only the probability of exploitation, not the potential impact of a vulnerability. Low-scoring vulnerabilities may still cause significant damage, depending on the environment. EPSS also relies on past data trends and may lag slightly in predicting novel threat techniques.

Naming the exposure is the easy half. Closing it safely is the other.

Tamnoon reads the findings your scanner already raised, closes what Tamnoon can prove safe through your own controls, and declines the rest in writing with the evidence why.