{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/epss-exploitation-forecast-not-risk-score/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/",
        "slug": "epss-exploitation-forecast-not-risk-score",
        "url": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/epss-exploitation-forecast-not-risk-score/"
        },
        "title": "Use EPSS as a changing exploitation forecast—not a complete risk score",
        "summary": "EPSS estimates the probability that exploitation activity for a published CVE will be observed in the next 30 days. Combine the dated forecast with applicability, impact, controls, KEV, and direct evidence.",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:33:44+00:00",
        "modified_at": "2026-08-26T13:27:47+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 557,
        "potentially_affected": "Organizations using EPSS scores or percentiles in vulnerability-management dashboards, service-level targets, triage, or remediation prioritization.",
        "dse_recommendation": "Store dated EPSS probability and percentile values as dynamic threat signals, give confirmed exploitation precedence, and combine them with asset applicability, impact, exposure, controls, and supported remediation.",
        "primary_source": {
            "name": "FIRST Exploit Prediction Scoring System FAQ",
            "url": "https://www.first.org/epss/faq.html",
            "published_on": null,
            "authority": "www.first.org"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> EPSS is a dated forecast about observed exploitation activity for a CVE over the next 30 days. It does not know whether you run the product, how a successful exploit would affect you, or whether your controls change the outcome.</p>\n<h2>Source fact: what FIRST says EPSS measures</h2>\n<p>The official <a href=\"https://www.first.org/epss/faq.html\" target=\"_blank\" rel=\"noopener noreferrer\">FIRST EPSS FAQ</a> describes EPSS as a data-driven model that estimates the probability that exploitation activity associated with a publicly disclosed CVE will be observed in the wild within the next 30 days. Scores range from zero to one and are updated daily. FIRST distinguishes the probability from the percentile: probability is the model&#8217;s absolute forecast, while percentile ranks a vulnerability relative to the currently scored population.</p>\n<p>FIRST explicitly states that EPSS is not a complete risk score. It does not estimate impact, know an organization&#8217;s assets, or account for its compensating controls. The FAQ also distinguishes the forward-looking EPSS estimate from CISA&#8217;s Known Exploited Vulnerabilities catalog, which records confirmed exploitation, and says direct exploitation evidence should supersede a forecast.</p>\n<h2>What the source does not establish</h2>\n<p>A low EPSS score is not proof that exploitation is impossible or that remediation can be ignored. A high percentile can coexist with a modest absolute probability because the score distribution is not uniform. A score changes as inputs change, so an undated dashboard value is weak evidence.</p>\n<p>EPSS does not replace vendor severity, CVSS context, contractual deadlines, emergency directives, safety assessment, or environment-specific risk analysis. Combining unrelated scores through an invented formula can create a number without a defensible meaning.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Is the exact CVE applicable to an installed, reachable, and consequential asset?</li>\n<li>What EPSS probability, percentile, model information, and date were retrieved?</li>\n<li>Is there authoritative direct evidence of exploitation, including CISA KEV or a vendor or agency statement?</li>\n<li>What would successful exploitation mean for confidentiality, integrity, availability, safety, customers, and recovery?</li>\n<li>Which supported fix or mitigation exists, and what is the operational cost and risk of delay or change?</li>\n</ul>\n<h2>DSE recommendation: use EPSS as one time-sensitive signal</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<ol>\n<li>Store the CVE, EPSS probability, percentile, retrieval date, and data source. Refresh according to the workflow&#8217;s decision cadence and retain history for material decisions.</li>\n<li>Give confirmed exploitation and binding emergency requirements precedence over a predictive score. Record the authoritative source and date.</li>\n<li>Confirm product, version, configuration, exposure, and ownership before creating or closing remediation work.</li>\n<li>Combine the forecast qualitatively or through a documented risk method with impact, asset criticality, exposure, controls, safety, recovery, patch availability, and change risk.</li>\n<li>Define threshold behavior as a work-queue rule, not a claim that every vulnerability above the line will be exploited or every one below it is safe.</li>\n<li>Measure the program: review prioritized, deferred, exploited, and false-assumption cases and adjust the workflow transparently.</li>\n</ol>\n<h2>Verification and evidence</h2>\n<p>Sample vulnerability decisions across high and low EPSS values. Reconstruct the dated score, applicability, direct exploitation checks, impact and exposure context, owner, remediation or acceptance decision, due date, change evidence, and reassessment. Confirm that a score change or KEV addition can update the queue.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://www.first.org/epss/faq.html\" target=\"_blank\" rel=\"noopener noreferrer\">FIRST EPSS Frequently Asked Questions</a> — Forum of Incident Response and Security Teams; living definition and limitations</li>\n<li><a href=\"https://www.first.org/epss/data_stats.html\" target=\"_blank\" rel=\"noopener noreferrer\">FIRST EPSS data and API</a> — Forum of Incident Response and Security Teams; official score access</li>\n<li><a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener noreferrer\">CISA Known Exploited Vulnerabilities Catalog</a> — Cybersecurity and Infrastructure Security Agency; confirmed-exploitation catalog</li>\n</ul>",
        "content_text": "Bottom line: EPSS is a dated forecast about observed exploitation activity for a CVE over the next 30 days. It does not know whether you run the product, how a successful exploit would affect you, or whether your controls change the outcome.\nSource fact: what FIRST says EPSS measures\nThe official FIRST EPSS FAQ describes EPSS as a data-driven model that estimates the probability that exploitation activity associated with a publicly disclosed CVE will be observed in the wild within the next 30 days. Scores range from zero to one and are updated daily. FIRST distinguishes the probability from the percentile: probability is the model’s absolute forecast, while percentile ranks a vulnerability relative to the currently scored population.\nFIRST explicitly states that EPSS is not a complete risk score. It does not estimate impact, know an organization’s assets, or account for its compensating controls. The FAQ also distinguishes the forward-looking EPSS estimate from CISA’s Known Exploited Vulnerabilities catalog, which records confirmed exploitation, and says direct exploitation evidence should supersede a forecast.\nWhat the source does not establish\nA low EPSS score is not proof that exploitation is impossible or that remediation can be ignored. A high percentile can coexist with a modest absolute probability because the score distribution is not uniform. A score changes as inputs change, so an undated dashboard value is weak evidence.\nEPSS does not replace vendor severity, CVSS context, contractual deadlines, emergency directives, safety assessment, or environment-specific risk analysis. Combining unrelated scores through an invented formula can create a number without a defensible meaning.\nApplicability questions\n\nIs the exact CVE applicable to an installed, reachable, and consequential asset?\nWhat EPSS probability, percentile, model information, and date were retrieved?\nIs there authoritative direct evidence of exploitation, including CISA KEV or a vendor or agency statement?\nWhat would successful exploitation mean for confidentiality, integrity, availability, safety, customers, and recovery?\nWhich supported fix or mitigation exists, and what is the operational cost and risk of delay or change?\n\nDSE recommendation: use EPSS as one time-sensitive signal\nThe following steps are DSE recommendations based on the cited source.\n\nStore the CVE, EPSS probability, percentile, retrieval date, and data source. Refresh according to the workflow’s decision cadence and retain history for material decisions.\nGive confirmed exploitation and binding emergency requirements precedence over a predictive score. Record the authoritative source and date.\nConfirm product, version, configuration, exposure, and ownership before creating or closing remediation work.\nCombine the forecast qualitatively or through a documented risk method with impact, asset criticality, exposure, controls, safety, recovery, patch availability, and change risk.\nDefine threshold behavior as a work-queue rule, not a claim that every vulnerability above the line will be exploited or every one below it is safe.\nMeasure the program: review prioritized, deferred, exploited, and false-assumption cases and adjust the workflow transparently.\n\nVerification and evidence\nSample vulnerability decisions across high and low EPSS values. Reconstruct the dated score, applicability, direct exploitation checks, impact and exposure context, owner, remediation or acceptance decision, due date, change evidence, and reassessment. Confirm that a score change or KEV addition can update the queue.\nOfficial references\n\nFIRST EPSS Frequently Asked Questions — Forum of Incident Response and Security Teams; living definition and limitations\nFIRST EPSS data and API — Forum of Incident Response and Security Teams; official score access\nCISA Known Exploited Vulnerabilities Catalog — Cybersecurity and Infrastructure Security Agency; confirmed-exploitation catalog",
        "content_markdown": "Bottom line: EPSS is a dated forecast about observed exploitation activity for a CVE over the next 30 days. It does not know whether you run the product, how a successful exploit would affect you, or whether your controls change the outcome.\n\n## Source fact: what FIRST says EPSS measures\n\nThe official [FIRST EPSS FAQ](https://www.first.org/epss/faq.html) describes EPSS as a data-driven model that estimates the probability that exploitation activity associated with a publicly disclosed CVE will be observed in the wild within the next 30 days. Scores range from zero to one and are updated daily. FIRST distinguishes the probability from the percentile: probability is the model’s absolute forecast, while percentile ranks a vulnerability relative to the currently scored population.\n\nFIRST explicitly states that EPSS is not a complete risk score. It does not estimate impact, know an organization’s assets, or account for its compensating controls. The FAQ also distinguishes the forward-looking EPSS estimate from CISA’s Known Exploited Vulnerabilities catalog, which records confirmed exploitation, and says direct exploitation evidence should supersede a forecast.\n\n## What the source does not establish\n\nA low EPSS score is not proof that exploitation is impossible or that remediation can be ignored. A high percentile can coexist with a modest absolute probability because the score distribution is not uniform. A score changes as inputs change, so an undated dashboard value is weak evidence.\n\nEPSS does not replace vendor severity, CVSS context, contractual deadlines, emergency directives, safety assessment, or environment-specific risk analysis. Combining unrelated scores through an invented formula can create a number without a defensible meaning.\n\n## Applicability questions\n\n- Is the exact CVE applicable to an installed, reachable, and consequential asset?\n\n- What EPSS probability, percentile, model information, and date were retrieved?\n\n- Is there authoritative direct evidence of exploitation, including CISA KEV or a vendor or agency statement?\n\n- What would successful exploitation mean for confidentiality, integrity, availability, safety, customers, and recovery?\n\n- Which supported fix or mitigation exists, and what is the operational cost and risk of delay or change?\n\n## DSE recommendation: use EPSS as one time-sensitive signal\n\nThe following steps are DSE recommendations based on the cited source.\n\n- Store the CVE, EPSS probability, percentile, retrieval date, and data source. Refresh according to the workflow’s decision cadence and retain history for material decisions.\n\n- Give confirmed exploitation and binding emergency requirements precedence over a predictive score. Record the authoritative source and date.\n\n- Confirm product, version, configuration, exposure, and ownership before creating or closing remediation work.\n\n- Combine the forecast qualitatively or through a documented risk method with impact, asset criticality, exposure, controls, safety, recovery, patch availability, and change risk.\n\n- Define threshold behavior as a work-queue rule, not a claim that every vulnerability above the line will be exploited or every one below it is safe.\n\n- Measure the program: review prioritized, deferred, exploited, and false-assumption cases and adjust the workflow transparently.\n\n## Verification and evidence\n\nSample vulnerability decisions across high and low EPSS values. Reconstruct the dated score, applicability, direct exploitation checks, impact and exposure context, owner, remediation or acceptance decision, due date, change evidence, and reassessment. Confirm that a score change or KEV addition can update the queue.\n\n## Official references\n\n- [FIRST EPSS Frequently Asked Questions](https://www.first.org/epss/faq.html) — Forum of Incident Response and Security Teams; living definition and limitations\n\n- [FIRST EPSS data and API](https://www.first.org/epss/data_stats.html) — Forum of Incident Response and Security Teams; official score access\n\n- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) — Cybersecurity and Infrastructure Security Agency; confirmed-exploitation catalog"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/",
                "url": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Use EPSS as a changing exploitation forecast—not a complete risk score",
                        "item": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/#article",
                "identifier": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/",
                "url": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/",
                "headline": "Use EPSS as a changing exploitation forecast—not a complete risk score",
                "description": "EPSS estimates the probability that exploitation activity for a published CVE will be observed in the next 30 days. Combine the dated forecast with…",
                "abstract": "EPSS estimates the probability that exploitation activity for a published CVE will be observed in the next 30 days. Combine the dated forecast with applicability, impact, controls, KEV, and direct evidence.",
                "articleBody": "Bottom line: EPSS is a dated forecast about observed exploitation activity for a CVE over the next 30 days. It does not know whether you run the product, how a successful exploit would affect you, or whether your controls change the outcome.\nSource fact: what FIRST says EPSS measures\nThe official FIRST EPSS FAQ describes EPSS as a data-driven model that estimates the probability that exploitation activity associated with a publicly disclosed CVE will be observed in the wild within the next 30 days. Scores range from zero to one and are updated daily. FIRST distinguishes the probability from the percentile: probability is the model’s absolute forecast, while percentile ranks a vulnerability relative to the currently scored population.\nFIRST explicitly states that EPSS is not a complete risk score. It does not estimate impact, know an organization’s assets, or account for its compensating controls. The FAQ also distinguishes the forward-looking EPSS estimate from CISA’s Known Exploited Vulnerabilities catalog, which records confirmed exploitation, and says direct exploitation evidence should supersede a forecast.\nWhat the source does not establish\nA low EPSS score is not proof that exploitation is impossible or that remediation can be ignored. A high percentile can coexist with a modest absolute probability because the score distribution is not uniform. A score changes as inputs change, so an undated dashboard value is weak evidence.\nEPSS does not replace vendor severity, CVSS context, contractual deadlines, emergency directives, safety assessment, or environment-specific risk analysis. Combining unrelated scores through an invented formula can create a number without a defensible meaning.\nApplicability questions\n\nIs the exact CVE applicable to an installed, reachable, and consequential asset?\nWhat EPSS probability, percentile, model information, and date were retrieved?\nIs there authoritative direct evidence of exploitation, including CISA KEV or a vendor or agency statement?\nWhat would successful exploitation mean for confidentiality, integrity, availability, safety, customers, and recovery?\nWhich supported fix or mitigation exists, and what is the operational cost and risk of delay or change?\n\nDSE recommendation: use EPSS as one time-sensitive signal\nThe following steps are DSE recommendations based on the cited source.\n\nStore the CVE, EPSS probability, percentile, retrieval date, and data source. Refresh according to the workflow’s decision cadence and retain history for material decisions.\nGive confirmed exploitation and binding emergency requirements precedence over a predictive score. Record the authoritative source and date.\nConfirm product, version, configuration, exposure, and ownership before creating or closing remediation work.\nCombine the forecast qualitatively or through a documented risk method with impact, asset criticality, exposure, controls, safety, recovery, patch availability, and change risk.\nDefine threshold behavior as a work-queue rule, not a claim that every vulnerability above the line will be exploited or every one below it is safe.\nMeasure the program: review prioritized, deferred, exploited, and false-assumption cases and adjust the workflow transparently.\n\nVerification and evidence\nSample vulnerability decisions across high and low EPSS values. Reconstruct the dated score, applicability, direct exploitation checks, impact and exposure context, owner, remediation or acceptance decision, due date, change evidence, and reassessment. Confirm that a score change or KEV addition can update the queue.\nOfficial references\n\nFIRST EPSS Frequently Asked Questions — Forum of Incident Response and Security Teams; living definition and limitations\nFIRST EPSS data and API — Forum of Incident Response and Security Teams; official score access\nCISA Known Exploited Vulnerabilities Catalog — Cybersecurity and Infrastructure Security Agency; confirmed-exploitation catalog",
                "datePublished": "2026-08-25T21:33:44+00:00",
                "dateModified": "2026-08-26T13:27:47+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/epss-exploitation-forecast-not-risk-score/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Use EPSS as a changing exploitation forecast—not a complete risk score"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Advisory priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 557,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "FIRST Exploit Prediction Scoring System FAQ",
                    "url": "https://www.first.org/epss/faq.html"
                }
            }
        ]
    }
}