Definition

EPSS (Exploit Prediction Scoring System)

A FIRST-maintained daily probability (0–1) that a CVE will be exploited in the wild in the next 30 days.

A data-driven model from FIRST that estimates, for every published CVE, the probability of exploitation activity in the next 30 days, updated daily and published with a percentile. EPSS complements CVSS (severity) with likelihood, which is what triage capacity should follow. A high EPSS score is a prioritisation signal and a reason to look for exploitation evidence; it is not evidence of exploitation in itself.

Reference: FIRST EPSS · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.