EPSS Explained: Predicting Exploitation for CySA+ Vulnerability Management
EPSS — the Exploit Prediction Scoring System — estimates the probability that a given vulnerability will be exploited in the wild within the next 30 days. It exists because CVSS, for all its usefulness, answers a question that is not quite the one vulnerability managers need to answer. CVSS tells you how bad a vulnerability would be if exploited. EPSS tells you how likely it is that anyone will bother. Those are different questions, and conflating them is the single most expensive mistake in vulnerability management. The Problem EPSS Solves A typical enterprise scan returns thousands of findings, a large share of them rated High or Critical by CVSS. Patching all of them promptly is not possible, so teams work down the list by severity. The trouble is that severity is a poor predictor of what attackers actually use. Only a small minority of published CVEs are ever exploited in the wild — consistently measured in the low single-digit percentages. Meanwhile, plenty of CVSS 9.8...