Use EPSS as a changing exploitation forecast—not a complete risk score
EPSS estimates the probability that exploitation activity for a published CVE will be observed in the next 30 days. Combine the dated forecast with applicability, impact, controls, KEV, and direct evidence.
Read the explainer