Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Vulnerability scores help describe severity, estimate exploitation likelihood, or flag exploitation already observed—but none gives you a complete, organization-specific patch order. CVSS, EPSS, and CISA’s Known Exploited Vulnerabilities (KEV) catalog represent different kinds of evidence. Use them with verified asset inventory, exposure, business importance, and remediation constraints.

What does each vulnerability signal tell you?

Signal What it represents What it does not know How to use it
CVSS Standardized technical severity information about an individual vulnerability. The CVSS version, metrics, and vector provide context for the score. Your deployed assets, local exposure, controls, business impact, or the risk created by vulnerability chains. Use the score and vector to understand severity, then interpret them in the context of affected systems and your environment.
EPSS A time-sensitive estimate of the probability that a vulnerability will be exploited in the wild within the next 30 days. FIRST’s EPSS FAQ explains what the estimate means. Whether the vulnerable product is installed in your environment, whether an attacker can reach it, or whether exploitation is already confirmed on your assets. Use the dated score as an exploitation-likelihood signal alongside severity and local asset context; do not treat it as proof of local exposure or exploitation.
CISA KEV Catalog membership indicates that exploitation in the wild has been observed for the listed vulnerability. CISA calls KEV its authoritative source for such vulnerabilities. Whether you run an affected version, how exposed the asset is, or how remediation fits your service and operational constraints. Check the catalog entry, map it to your inventory, and apply your organization’s response process. FIRST advises treating KEV-listed vulnerabilities as actively exploited regardless of EPSS score.

CVSS severity, EPSS probability, and KEV observed exploitation are not interchangeable scales. A high value in one does not mean the same thing as a high value in another. FIRST’s EPSS overview describes EPSS as a probability signal for prioritization, while CISA’s KEV catalog records vulnerabilities known to have been exploited in the wild.

Why isn’t a CVSS score a patch order?

CVSS describes an individual vulnerability, not the total risk of a particular organization’s systems. NIST’s CVSS Implementation Guidance cautions against using the base score alone to determine risk, adding scores together to create a system score, or overlooking environmental context and vulnerability chaining. The guide is older; its cautions about context do not make it a guide to the latest CVSS version.

The vector matters because it shows the metrics behind the number. FIRST’s CVSS v4.0 Frequently Asked Questions says: “One important note is that while the CVSS numeric score is a useful shorthand for vulnerability severity, the score itself does not describe the important context that can be conveyed as part of the entire vector string.” Check the CVSS version and vector rather than treating a number without its context as a complete assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVSS also cannot tell you whether a vulnerable component is actually deployed, reachable by an attacker, protected by compensating controls, or important to a business-critical service. FIRST’s CVSS v4.0 specification positions the standard as part of vulnerability management—not a substitute for organization-specific risk decisions.

How should you interpret EPSS and KEV?

Read EPSS as a time-bounded probability estimate

EPSS estimates the probability of exploitation in the wild over the coming 30 days; it is not a severity rating and does not predict with certainty what will happen to a particular asset. Its value can change, so record the score and the date it was checked. FIRST’s EPSS usage guidance explains how to use the score without treating it as local asset knowledge.

For example, FIRST says that if 100 vulnerabilities each have an EPSS score of 0.05, the probability that at least one is exploited within 30 days is approximately 99.4%. This is an illustrative group calculation under an independence-style interpretation—not a measured population statistic, and not a 99.4% chance for any one of those vulnerabilities.

Treat KEV membership as observed exploitation evidence

A KEV listing is stronger evidence of exploitation activity than a forecast: CISA includes vulnerabilities known to have been exploited in the wild. The catalog changes over time, so inspect the entry and check current membership rather than relying on an old copy. FIRST’s EPSS guidance says to treat a KEV-listed vulnerability as actively exploited regardless of its EPSS score. That still does not establish that your own affected system has been compromised; local confirmation is a separate task.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should you do when the signals disagree?

Consider the hypothetical case of one vulnerability with severe potential impact but little current exploitation signal, and another, less severe flaw already listed in KEV on an internet-facing critical asset. The first may warrant attention because of its impact; the second combines observed exploitation evidence with local exposure and asset importance. The scores alone cannot settle the order. Your organization’s verified deployment and risk context must do that.

Compare the evidence for each issue before deciding:

  • CVSS: Check the score, version, metrics, and vector. Understand which characteristics drive the severity assessment.
  • EPSS: Record the score and check date, and interpret it as a 30-day exploitation probability—not a severity measure.
  • KEV: Confirm whether the vulnerability is listed and review the current catalog entry.
  • Asset match: Verify that the affected product and version are actually present in your inventory.
  • Exposure: Determine whether the vulnerable component is reachable and consider applicable controls.
  • Business impact: Identify the service or process at risk and the plausible consequences of exploitation.
  • Remediation: Assess feasibility, dependencies, and operational constraints; record the evidence source and when it was checked.

FIRST explicitly notes that EPSS does not know what is in your environment, whether attackers can reach an asset, or whether exploitation has already been confirmed there. Its EPSS model and methodology explain the model’s role; asset inventory and local investigation remain necessary to turn its estimate into a decision.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do you turn signals into a defensible patch decision?

  1. Verify the affected asset. Match the vulnerability to the product and version in your inventory before assigning local priority.
  2. Establish exposure and impact. Determine reachability, relevant controls, asset criticality, and plausible business consequences.
  3. Interpret each signal on its own terms. Use CVSS and its vector for technical severity, EPSS for a dated 30-day likelihood estimate, and KEV for observed exploitation evidence.
  4. Apply your organization’s policy. Set response priorities in line with risk tolerance, regulatory duties, service criticality, and remediation capacity. No universal weighting formula or patch deadline follows from these signals alone.
  5. Record the decision and reassess changing evidence. Note the sources and dates checked, the local facts that drove the decision, and any constraint affecting remediation. Refresh time-sensitive EPSS and KEV information as appropriate.

A useful prioritization process makes clear why one issue is being handled ahead of another: what was observed or estimated, which asset is affected, how it is exposed, what could be harmed, and what operational decision follows. Scores make those inputs easier to compare, but the organization—not a score—owns the final order.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.