Skip to content

EPSS (Exploit Prediction Scoring System)

Definition

EPSS is a scoring system by FIRST that estimates for every CVE the probability that it will actually be exploited within the next 30 days, as a value between 0 and 1.

Also known asExploit Prediction Scoring SystemEPSS scoreEPSS percentile

Updated:

Fix firstsorted by risk
1CVE-2024-21762vpn.beispiel-gmbh.atKEV
2CVE-2024-21410mail.beispiel-gmbh.atKEV
3TLS 1.0 enabledshop.beispiel-gmbh.atMedium

Visuals show sample data.

How blacklens.io covers this

EPSS (Exploit Prediction Scoring System) is a scoring system operated by the Forum of Incident Response and Security Teams (FIRST) that estimates for every published CVE the probability that it will be exploited in practice within the next 30 days. The score ranges from 0 to 1 (0 to 100 percent) and is recalculated daily. The percentile additionally indicates how the score compares with all other CVEs.

Why EPSS matters

Tens of thousands of new CVEs are published every year, but only a small share of them is ever used in real attacks. Prioritising by CVSS treats a critical vulnerability in software nobody attacks with the same urgency as one currently used in ransomware campaigns. EPSS provides the missing dimension: not "how bad would it be" but "how likely is it to happen". Combined with CVSS and the CISA KEV catalogue, the list of vulnerabilities that urgently need fixing can be reduced considerably without overlooking the ones actually being exploited.

How EPSS works

EPSS is a machine-learning model that relates, for each CVE, features such as vendor, affected product, CWE category, CVSS metrics, the existence of public exploits or proofs of concept, mentions in security tools and references in the CVE description to actually observed exploitation attempts from sensor and honeypot data. This produces daily:

  • Score: the estimated probability of exploitation in the next 30 days, e.g. 0.92 for 92 percent.
  • Percentile: the share of all CVEs with a lower score. A percentile of 0.99 means the CVE belongs to the top one percent.

The model is revised regularly, most recently with version 4 in 2025. The data is freely available via an API.

How blacklens.io uses EPSS

blacklens.io shows the EPSS score and percentile for every finding with a CVE alongside CVSS v3/v4, CISA KEV status, exploit and PoC availability and the fixed version. If the EPSS value exceeds 0.80 and an exploit is available, the alert severity is raised automatically. The values are updated continuously via the threat-intel feed (including VulDB, NVD, EPSS, VulnCheck, CISA KEV), so a vulnerability that is unremarkable today and actively exploited tomorrow moves up in the prioritisation.

Does EPSS replace the CVSS score?

No. CVSS describes severity and impact, EPSS the probability of exploitation. Prioritisation needs both plus the asset context: is it reachable from the internet, what data does it process, are there compensating controls?

At what EPSS value should I act?

There is no official threshold. In practice, vulnerabilities with EPSS above 0.1 to 0.2 or a percentile above 0.9 are often treated as urgent; above 0.8 exploitation is very likely. More important than a fixed number is the combination with KEV status and reachability.

Why does the EPSS value of a CVE change?

Because the model recalculates daily and new information flows in: a published exploit, inclusion in attack frameworks, observed scans. A CVE can jump from 0.02 to 0.9 within a few days. That is why prioritisation should be updated automatically.

See which of these apply to your company.

The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings