CVSS, EPSS and KEV: three scores, three different questions

Severity, probability and observed reality are three separate axes. Most vulnerability queues sort on only the first.

CVSS, EPSS and KEV are three signals attached to the same vulnerabilities. CVSS rates how severe a flaw would be if exploited. EPSS estimates the probability that it will be exploited in the next 30 days. KEV is CISA's list of vulnerabilities that have already been exploited in the wild.

A modern feed carries all three per CVE, and they are routinely treated as interchangeable measures of "how bad". They are not. Each one answers a distinct question, and using the wrong one produces a queue that looks rigorous and points effort in the wrong direction.

The three signals

CVSS: HOW BAD IF EXPLOITED
A 0.0–10.0 severity score describing the intrinsic characteristics of the flaw: attack vector, complexity, privileges required, and the impact on confidentiality, integrity and availability. Assigned once, at publication. It says nothing about likelihood.
EPSS: HOW LIKELY TO BE EXPLOITED
The Exploit Prediction Scoring System, run by FIRST, gives a probability between 0 and 1 that a vulnerability will see exploitation activity in the next 30 days. A model produces it from observed signals and it is recalculated daily, so a CVE's EPSS score moves over time.
KEV: CONFIRMED EXPLOITED
CISA's Known Exploited Vulnerabilities catalogue. Not a score but a list. Membership means exploitation has been observed in the real world. It is evidence rather than prediction, and it is the strongest single signal of the three.

KEV carries extra weight in the US public sector. Binding Operational Directive 22-01 requires federal civilian agencies to fix catalogue entries by set deadlines, which is why many private teams adopted the same list as their own floor.

Why the distinction matters

The two failure modes are mirror images.

Sorting by CVSS alone fills the top of the queue with severe vulnerabilities nobody has ever built a working exploit for. Meanwhile a moderate flaw with a public exploit kit sits below the fold. Severity is not a stand-in for likelihood. A high score means the consequence would be bad, not that anyone is coming.

Sorting by EPSS alone has the opposite problem. It will happily rank a flaw that is likely to be exploited but harmless above a rare one that would hand over the whole account. Probability is not a stand-in for consequence either.

CVSS is consequence. EPSS is probability. KEV is observed fact. Risk needs at least two of the three.

CVSS vs EPSS vs KEV

CVSS, EPSS and KEV compared
AspectCVSSEPSSKEV
Maintained byFIRST (the standard), scored by vendors and NVDFIRSTCISA
FormatScore from 0.0 to 10.0Probability from 0 to 1, plus a percentileA catalogue: a CVE is either listed or not
Question it answersHow bad would exploitation be?How likely is exploitation in the next 30 days?Has this already been exploited in the wild?
How often it changesRarely after publicationDailyAs new evidence arrives, entries are added
CoverageAlmost every published CVE, eventuallyEvery published CVEOnly CVEs with reliable evidence of exploitation
Main weaknessIgnores likelihood and your environmentIgnores impact and your environmentAbsence from the list proves nothing

Combining them

A reasonable ordering, which most mature programmes end up with:

  1. In KEV and present in your estate. Exploitation is not hypothetical. This tier is small and should be emptied first.
  2. High EPSS and high CVSS. Likely to be attacked, bad if it succeeds.
  3. High CVSS, low EPSS. Genuinely dangerous, but no current exploitation pressure. Schedule it. Do not scramble.
  4. Low CVSS, high EPSS. Being exploited but limited on its own. Check whether it is the first hop on a path to something larger.

What these scores do not do

  • They do not describe your environment. All three are identical whether the package runs on your public API gateway or on a forgotten instance with no route in.
  • They do not cover misconfigurations. A public bucket has no CVE, so it has no CVSS, no EPSS and no KEV entry.
  • They do not arrive on time, always. In 2024 the National Vulnerability Database fell far behind on enrichment, and many new CVEs waited weeks for a score. A queue that requires a CVSS value to rank something will quietly drop those.
  • They do not say what happens next. None of them knows which role the vulnerable host can assume or what that role can read.

Common misconceptions

"An EPSS of 0.9 means 90% of companies will be hit." It is the probability that exploitation activity against that CVE is observed anywhere in the next 30 days. It is not a prediction about your company.

"If it is not in KEV, it is not being exploited." KEV only lists CVEs with reliable evidence and clear remediation guidance. Plenty of exploited flaws never make it in.

"EPSS replaces CVSS." It cannot. A flaw with an EPSS score of 0.02 can still be the one that would expose your whole account if anyone ever used it. Low probability is not the same as low impact.

"CVSS 10.0 means drop everything." Only if something can reach it. A 10.0 on an isolated build box can wait for the next patch window.

The fourth axis these all miss

All three signals describe the vulnerability. None of them describes your environment. Each score is identical for a CVE whether the affected package runs on an internet-facing gateway or on a decommissioned instance in a private subnet with no route in.

That is why the strongest input is usually neither a score nor a list. It is whether the affected asset sits on a reachable path to something worth taking. A KEV-listed CVE on an unreachable host may genuinely be less urgent than a low-EPSS one on your edge, and only a model of your own estate can tell you which case you are in.

See why a CVSS score cannot prioritise your cloud risk for how that reachability model is built, and blast radius for what it costs when a path completes. To see how different vendors fold these signals into their own ranking, the Orca comparison is a good place to start.

FAQ

Which is better, CVSS or EPSS?

Neither on its own. CVSS tells you the consequence and EPSS tells you the likelihood. A sensible queue uses both, with KEV membership on top as the strongest evidence.

How often is EPSS updated?

Daily. FIRST recalculates every CVE's probability each day from new exploitation signals, so a score can rise sharply when an exploit is published.

Who has to follow the KEV catalogue?

US federal civilian agencies, under CISA Binding Operational Directive 22-01. Many private companies use it voluntarily as a minimum standard because the list is short and the evidence is solid.

Can a vulnerability be in KEV but have a low CVSS score?

Yes. KEV is about evidence of exploitation, not severity. A medium-severity flaw that attackers use as a first step can be listed.

What should I do with a CVE that has no CVSS score yet?

Do not let it fall out of the queue. Use EPSS and KEV, which do not wait for NVD enrichment, and the vendor's own advisory until a score appears.

Secorvia shows CVSS, EPSS and KEV side by side for each CVE and ranks them by reachability.

Keep reading
Prioritisation · 6 min read

Why a CVSS score cannot prioritise your cloud risk

Fundamentals · 6 min read

What is an attack path in cloud security?

Fundamentals · 7 min read

What is Cloud Security Posture Management?

Try it against your own cloud account.