What is EPSS?
EPSS, the Exploit Prediction Scoring System from FIRST, estimates the probability that a vulnerability will be exploited in the wild over the next 30 days.
EPSS is an external exploit-likelihood signal used by DevSecure Intelligence to help vendors and security teams understand which vulnerabilities are more likely to be exploited.
EPSS, the Exploit Prediction Scoring System from FIRST, estimates the probability that a vulnerability will be exploited in the wild over the next 30 days.
Exploit probability helps separate widely exploitable issues from vulnerabilities that are severe on paper but less likely to be used in current attack activity.
DevSecure Intelligence uses EPSS as an exploit-likelihood signal alongside CVSS, CISA KEV, exploit evidence, source coverage, and patch intelligence.
Higher EPSS probability and percentile values can raise a CVE's rank when they align with severity, exposure, known exploitation, or patch signals.
DevSecure does not own or publish EPSS. FIRST maintains the official EPSS data and methodology.
Official FIRST EPSS page