CVSS Is Not Enough: Risk-Based Vulnerability Prioritization with EPSS
Published on 2025-09-15 by Security Research Team
The Alert Fatigue Problem
The Common Vulnerability Scoring System (CVSS) has been the standard for vulnerability prioritization for nearly two decades. A vulnerability with a CVSS score of 9.8 is treated as critical regardless of whether it has ever been exploited in the wild or whether it affects an internet-facing system. This severity-only approach generates massive alert volumes: organizations with tens of thousands of vulnerabilities in their backlog cannot remediate all critical and high findings, leading to alert fatigue and arbitrary triage decisions.
Analysis of historical CVE data reveals a striking disconnect between CVSS scores and actual exploitation. Only about 5% of published CVEs are ever exploited in the wild, yet CVSS rates roughly 50% of all CVEs as high or critical severity. This means organizations following CVSS-based prioritization are spending the majority of their remediation effort on vulnerabilities that will never be attacked.
How EPSS Works
The Exploit Prediction Scoring System (EPSS), maintained by FIRST (Forum of Incident Response and Security Teams), uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The model ingests data from multiple sources including CVE metadata, exploit database entries, social media discussions, dark web monitoring, and observed exploitation telemetry.
EPSS scores range from 0 to 1, representing the probability of exploitation. A score of 0.95 means the model predicts a 95% chance the vulnerability will be exploited within 30 days. Importantly, EPSS is dynamic: scores update daily as new threat intelligence becomes available. A vulnerability with a low EPSS score can spike to high probability when a proof-of-concept exploit is published or when threat actors begin scanning for it.
Combined Prioritization Strategies
The recommended approach combines CVSS severity with EPSS exploitability and asset criticality. CISA's Known Exploited Vulnerabilities (KEV) catalog provides a third signal: confirmed active exploitation by threat actors. A vulnerability that appears in the KEV catalog should be prioritized regardless of its CVSS or EPSS scores.
SSVC (Stakeholder-Specific Vulnerability Categorization), developed by Carnegie Mellon's SEI, provides a decision-tree framework that incorporates all three signals. Instead of a single numerical score, SSVC produces an action recommendation: Track, Track*, Attend, or Act. This decision-tree approach acknowledges that vulnerability prioritization is context-dependent and requires multiple inputs, not a single score.
This article is part of our ongoing security research series. Related data is available through the linked endpoints.