Two findings both score CVSS 7.5 — how do EPSS and a known-exploited list change your order?
answer
- equal severity, unequal likelihood
- impact and probability are different axes
- one is a daily forecast, one is observed fact
- global signal, not your exposure
- low today can jump tomorrow
basics
~20 sThey break the tie on likelihood, which severity never measured. A finding in the top EPSS percentile and on a confirmed-exploitation list is being attacked now; an identical 7.5 in neither is a hypothesis. Same impact, very different urgency.
solid answer
~50 sTwo equal severities mean the two flaws would hurt about equally if used. That is impact, and it is only half a risk. EPSS supplies the other half: a daily-updated probability that exploitation activity will be observed for that vulnerability in the next thirty days, plus a percentile placing it against every other scored flaw. A public catalogue of vulnerabilities with confirmed in-the-wild exploitation gives a coarser, binary version of the same signal — someone has been seen doing this. When one 7.5 is in the top percentile and listed, and the other is in neither, the first goes first, and I can say why in one sentence to a non-security stakeholder. What I must not do is let the low-probability one become the never-fixed one: EPSS is a forecast that changes daily, and a flaw at the bottom today can move sharply the day a working exploit is published.
go deeper
Know that two findings with the same severity number are not automatically the same urgency, and that public data exists on whether a flaw is actually being exploited.
Be able to state precisely what EPSS predicts — observed exploitation activity in the near term, refreshed daily — and how that differs from a curated list of confirmed in-the-wild exploitation.
Show how you combine the two axes on a real backlog, including the case where high impact and low likelihood beat the opposite, and say how often you refresh the ordering.
Be ready to argue what your organisation's prioritisation function should be made of, and to defend it to an executive who has heard only the severity number quoted in the press.
## Severity is half a risk Risk is conventionally impact combined with likelihood. A CVSS score is largely an impact statement, softened by how hard the attack is to mount, but it contains no estimate of whether anyone will actually mount it. So two findings at the same score are equal on the axis CVSS measures and unranked on the axis it does not. Reaching for exploitation data is not a workaround for a deficient score; it is supplying the missing dimension. ## What EPSS is EPSS is a data-driven model that outputs, for a vulnerability, a probability between 0 and 1 that exploitation activity against it will be observed in the wild in the next thirty days. It is refreshed daily, and it also publishes a percentile so you can say where a given flaw sits relative to all others rather than reasoning about a raw probability that is small for almost everything. Two properties matter for how you use it. First, it is a forecast about the vulnerability across the internet, not about your organisation — it does not know whether you are a target. Second, it moves. A flaw that sat near the floor for a year can jump the day proof-of-concept code circulates, so a decision to defer on low probability is a decision to keep watching, not a decision to close the ticket. ## What a known-exploited catalogue is A public catalogue of vulnerabilities with confirmed exploitation in the wild is a different, blunter instrument: a curated list where inclusion asserts that exploitation has actually been observed, not predicted. It is high-confidence and low-resolution. Presence is a strong reason to move; absence proves very little, because observation and curation lag reality. The two signals complement each other. EPSS is continuous, broad and predictive; the catalogue is binary, narrow and evidential. Together they give you likelihood; CVSS gives you impact; your environmental rescoring gives you relevance. ## Working the tie Suppose finding A is in an internet-facing edge component and sits in the top percentile of EPSS and on the confirmed-exploitation list. Finding B carries the same 7.5 in an internal reporting service and appears in neither. The order is not close. A is being attempted against exposed hosts opportunistically, by an anonymous internet attacker who has no idea who you are and does not need to. B requires someone to choose you and build something. Both may be worth fixing this quarter; only one is worth fixing this week. Now flip one variable to see the discipline properly. If the low-probability finding B had an environmental score far above A because it sits on an asset where one property is critical, the order becomes an argument rather than a lookup — high impact and low likelihood against moderate impact and high likelihood. That is a real judgment call, and the right answer often involves buying time on the high-impact one with a compensating control while shipping the fix for the high-likelihood one. ## The misuses to avoid **Substituting EPSS for severity.** A high probability on something that leaks a public value is still low risk. Probability multiplies impact, it does not replace it. **Reading EPSS as an organisational probability.** It is a global forecast. Your exposure, your sector and your controls are not inputs to it — those live in your environmental rescoring. **Treating absence from a catalogue as safety.** Not-yet-observed and not-exploitable are different statements, and only one of them is in the data. **Freezing the ordering.** Because these signals update, an ordering computed once and never revisited quietly becomes wrong. Re-reading the probability data when you next touch the backlog is part of the method. **Using probability to argue impact away.** A finding on a payment path or a safety-relevant control does not become acceptable because current exploitation activity is low; it becomes a slower fix with a compensating control and a watch on the probability. ## How to say it One sentence works: severity says how much it would hurt, exploitation-probability data says how likely anyone is to try, and I need both before I can order the work. That framing also travels well outside the security team, which matters, because the person you are asking to delay a feature is rarely a security engineer.
- Does a high EPSS probability mean your organisation is likely to be attacked through that flaw?No. EPSS forecasts whether exploitation activity will be observed anywhere in the wild, not whether it will be aimed at you. Your own likelihood depends on exposure, attractiveness and controls — none of which are inputs to the model. Treat a high probability as evidence the technique is live, then use your own deployment context to decide whether that reaches you at all.
- What would make you fix the low-probability finding first anyway?A large gap in environmental impact. If the quiet 7.5 sits on a path where integrity is critical and a single successful attempt is unrecoverable, while the noisy one hits a component whose compromise is contained and detectable, high impact can outweigh high likelihood. In practice I would buy time on the high-impact one with a compensating control and still ship the high-likelihood fix first, because it is usually the cheaper of the two.
- Why keep the CVSS score at all if you have exploitation-probability data?Because the probability data is silent on consequences. It cannot distinguish a flaw that leaks a version banner from one that hands over a database, and both can be widely exploited. Dropping severity would let volume of activity dictate the roadmap. The two are orthogonal inputs, and the ordering you want comes from combining them, not from choosing one.
Severity is how hard a punch lands. Exploitation-probability data is how many people are currently throwing that punch.
saying these in an interview costs you the question
- Treats EPSS as a severity score on a different scale
- Reads EPSS as the probability of being attacked personally
- Takes absence from an exploited-vulnerability list as evidence of safety
- Computes an ordering once and never revisits the probability data
- Uses low exploitation probability to close a high-impact finding