EPSS is a model published by FIRST.org that gives every CVE a probability, between 0 and 1, of being exploited in the wild in the next 30 days. The model is retrained on observed exploitation and all scores are recalculated daily, so a score is always tied to a date.
Probability and percentile
The probability is the estimate. The percentile says how that estimate ranks among all scored CVEs. They diverge a lot: because the vast majority of CVEs score close to zero, a probability of 5% can already be above the 90th percentile. Use the probability to reason about likelihood and the percentile to compare CVEs with each other.
How to use it with KEV and CVSS
- If the CVE is in KEV, exploitation is confirmed. Fix it; the EPSS value no longer changes the decision.
- Outside KEV, a high EPSS says exploitation is likely soon. Treat it as the next queue.
- Use CVSS to judge the impact on your systems once you know the CVE is worth attention.
What it is not
EPSS is not a measure of severity, and it knows nothing about your environment. A low score is not a guarantee: new CVEs start low and can jump within days when exploit code is published, which is why this lookup always reads the current score from FIRST instead of a stored copy.