EPSS
Exploit Prediction Scoring System
System zur Vorhersage von Exploit-Wahrscheinlichkeiten
EPSS estimates the probability that a vulnerability will actually be exploited within the next 30 days, as a value between 0 and 1. It thus answers a different question than Common Vulnerability Scoring System (CVSS): not „how severe would exploitation be“ but „how likely is it“. Together the two values align the patch order with the real threat rather than with theoretical severity.
History. EPSS was first presented at Black Hat in 2019; in 2020 a dedicated Special Interest Group formed within Forum of Incident Response and Security Teams (FIRST), and from 2021 values were published publicly. The model has been fundamentally revised several times — version 2 (2022), version 3 (2023) and the current version 4, released on 17 March 2025, which introduced additional threat data and more accurate modelling.
Facts. EPSS is a data-driven, machine-trained model that links a vulnerability's features with observed exploitation activity and provides daily-updated probabilities for all public CVEs. It does not replace Common Vulnerability Scoring System (CVSS) but complements it; the United States of America (US) agency Cybersecurity and Infrastructure Security Agency (USA) (CISA) recommends combined use with its Known Exploited Vulnerabilities Catalog (KEV) catalogue. Importantly, an EPSS value is never exactly zero.
Outlook & recommendation. With tens of thousands of new CVEs per year, no one can patch everything — EPSS shifts the focus from „theoretically critical“ to „realistically at risk“. In prioritisation it realises its value only in combination: high severity (CVSS) and high exploitation probability (EPSS), together with relevance to one's own asset, mark the cases that belong first.