GlossaryAttack surface and pentesting

EPSS

Short answer

EPSS (Exploit Prediction Scoring System) is a free, data driven model run by FIRST that estimates the probability that a published vulnerability (CVE) will be exploited in the wild in the next 30 days. It helps teams decide which vulnerabilities to fix first.

How it works

EPSS combines information about each CVE, such as the type of weakness, the vendor, the availability of exploit code and mentions in security sources, with observed exploitation activity. A machine learning model produces a score between 0 and 1, the probability of exploitation in the next 30 days, plus a percentile against all other vulnerabilities. Scores are updated daily and published free by FIRST.

EPSS and CVSS

CVSS measures how severe a vulnerability would be if it were exploited. EPSS estimates how likely it is to be exploited. Many vulnerabilities rated critical by CVSS are rarely exploited, while some with medium scores are widely used by attackers. Using both helps focus effort where real risk is concentrated.

Using it in practice

EPSS works best as one input in vulnerability management, together with whether the vulnerability is already in the KEV catalogue, whether the affected system is exposed to the internet and how critical it is. Many scanners and vulnerability platforms now show EPSS scores next to their findings.

Limits

EPSS is a probability across the whole internet, not a statement about a specific company's systems, and it only covers vulnerabilities that have a CVE. A low score does not mean a vulnerability can be ignored on a critical, exposed system.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub