Code Security

EPSS vs CVSS: Why "Critical" Doesn't Mean "Fix First"

CVSS measures how bad exploitation would be. EPSS measures how likely it is in the next 30 days. Confusing the two is why teams patch alphabetically while the actually-exploited bug waits.

Webcuris Research

Security Engineering

·2 min read

CVSS = how bad. EPSS = how likely, in the next 30 days.

CVSS answers how bad would exploitation be — a severity score from 0 to 10 built from the vulnerability's characteristics. EPSS answers a different question entirely: how likely is this vulnerability to be exploited in the wild in the next 30 days — a probability from 0 to 1, re-estimated daily by FIRST from real exploitation telemetry. Teams that treat CVSS as a priority queue are sorting by the wrong axis: most critical-severity CVEs are never exploited at all, while some medium-severity ones are exploited within days.

What each score is made of

CVSSEPSS
MeasuresWorst-case impact and exploit characteristicsProbability of observed exploitation within 30 days
Produced byHumans scoring against a rubric, onceA model over live exploitation data, updated daily
Changes over timeRarely — the vulnerability is what it isConstantly — publication of a PoC can move it 100×
Scale0–10 severity bands0–1 probability (plus a percentile)
Blind spotSays nothing about whether anyone bothersSays nothing about how bad it is if they do

The two scores are not competitors; they are orthogonal axes. Every vulnerability in your backlog sits somewhere on the plane they span, and the quadrant it lands in is the priority decision:

The four quadrants

QuadrantExample shapeWhat to do
High CVSS · High EPSSRCE with a public PoC being sprayedNow. This is the drop-everything category — and it is small
High CVSS · Low EPSSCritical bug needing local access nobody hasSchedule it into normal patching — watch EPSS, it moves
Low CVSS · High EPSSInfo-leak being actively harvestedInvestigate your exposure — actively exploited beats theoretically severe
Low CVSS · Low EPSSThe long tail — most of the backlogBatch with routine updates; do not let it consume triage attention
The point of the exercise: the drop-everything set shrinks from "every critical" to a handful.
A quadrant chart with CVSS severity across and EPSS probability up: fix now, investigate exposure, schedule, and batch
Every vulnerability in the backlog lands in one of four cells, and the cell is the decision.

Where EPSS is honestly limited

  • It is population-level, not your-environment-level. EPSS models the internet's exploitation activity; it does not know your firewall rules, your compensating controls, or whether the vulnerable path is even reachable in your deployment.
  • It lags novel targeting. A probability model built on observed activity is quiet right up until activity is observed. Pair it with CISA's KEV catalog — KEV is confirmed exploitation, and membership overrides any score.
  • A low score is not permission to ignore. It is permission to schedule rather than to interrupt — which is precisely the distinction a priority system exists to make.

Using both without a spreadsheet

The practical version is a risk score that folds both axes together. When a Webcuris scan finds a vulnerable dependency — including a package name an AI invented, the finding's risk is computed from severity and the advisory's EPSS probability, alongside confidence and asset exposure — so the list you read is already in fix-first order, and a medium with a 0.9 exploitation probability outranks a critical with a 0.0004. The raw scores stay visible on every finding, because a prioritisation you cannot audit is a prioritisation you cannot trust.

Get the next one

One email when a new article goes out. No newsletter, no drip sequence, no sales follow-up.

Unsubscribe in one click. We never sell or share the address.

Keep reading

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

We reply to this address, so a disposable one will not reach you.

+91

0 / 4000