How it works
EPSS combines information about each CVE, such as the type of weakness, the vendor, the availability of exploit code and mentions in security sources, with observed exploitation activity. A machine learning model produces a score between 0 and 1, the probability of exploitation in the next 30 days, plus a percentile against all other vulnerabilities. Scores are updated daily and published free by FIRST.
EPSS and CVSS
CVSS measures how severe a vulnerability would be if it were exploited. EPSS estimates how likely it is to be exploited. Many vulnerabilities rated critical by CVSS are rarely exploited, while some with medium scores are widely used by attackers. Using both helps focus effort where real risk is concentrated.
Using it in practice
EPSS works best as one input in vulnerability management, together with whether the vulnerability is already in the KEV catalogue, whether the affected system is exposed to the internet and how critical it is. Many scanners and vulnerability platforms now show EPSS scores next to their findings.
Limits
EPSS is a probability across the whole internet, not a statement about a specific company's systems, and it only covers vulnerabilities that have a CVE. A low score does not mean a vulnerability can be ignored on a critical, exposed system.




