CVSS, EPSS and KEV: how to prioritize vulnerabilities
Fix what is being exploited first, then what is likely to be exploited, then what would hurt most, always weighted by how much the affected system matters to you. KEV tells you the first, EPSS estimates the second and CVSS describes the third. Ranking a backlog by CVSS score alone confuses how bad something could be with how likely it is to happen.
What does each score measure?
| Signal | Question it answers | Published by |
|---|---|---|
| CVSS | How severe would exploitation be? | FIRST maintains the standard; vendors and databases publish scores |
| EPSS | How likely is exploitation activity in the next 30 days? | FIRST’s EPSS group, daily, for every published CVE |
| KEV | Has it been exploited in the wild? | CISA, as a catalogue |
What is the difference between CVSS, EPSS and KEV? CVSS rates how severe a vulnerability would be if exploited, EPSS estimates the probability it will see exploitation activity in the next 30 days, and KEV lists vulnerabilities with reliable evidence of exploitation in the wild. Severity, likelihood and fact.
Why is a CVSS score alone misleading?
The CVSS v4.0 specification describes the Base score as the intrinsic characteristics of a vulnerability, assuming the reasonable worst case. It expects consumers to add Threat metrics (is it being attacked?) and Environmental metrics (does it matter here?), and it makes applying those the consumer’s job. A score that arrives with an advisory is normally Base only, labelled CVSS-B, and when exploit maturity is not defined the calculation assumes the worst case: that it is being attacked.
So the myth to drop is that a 9.8 is always urgent. Should you still patch every critical CVSS finding first? Keep them on a defined schedule, but a critical score on an isolated internal server is less urgent than a KEV-listed flaw on an internet-facing gateway. Severity sets the routine track, not the emergency one.
What does EPSS tell you?
EPSS is a model that estimates the probability that a published CVE will see exploitation in the wild in the next 30 days, as a score from 0 to 1 with a percentile. Most scores are low because most vulnerabilities are never exploited; FIRST is explicit that a near-zero score is a prediction, not missing data.
It does not know your environment or the damage exploitation would do, so it ranks likelihood and nothing else. What EPSS threshold should you use? There is no universal number. Pick one that produces a queue your people can actually clear, check what it misses, and adjust. FIRST publishes both a probability and a percentile, so the threshold can be set either way.
What does KEV tell you?
CISA’s Known Exploited Vulnerabilities catalog adds an entry only when there is a CVE ID, clear remediation guidance and reliable evidence of exploitation in the wild. The remediation can be a vendor update, a mitigation or a workaround. That makes it short and actionable, but incomplete: a flaw exploited without a CVE ID, or without a clear action to take, will not appear there, so an absence from KEV is not evidence of safety.
Does KEV apply to Canadian organizations? Not as a legal requirement. As of September 2026, the KEV remediation deadlines bind US federal civilian agencies only, under CISA’s BOD 26-04. CISA strongly recommends that every organization review and monitor the catalogue and prioritize the listed vulnerabilities, and a list of vulnerabilities known to be exploited is as relevant in Canada as anywhere. The deadlines are set in BOD 26-04, which replaced BOD 22-01 on June 10, 2026 and carries its KEV criteria forward.
How should you rank the backlog?
- In KEV, or seen exploited against you: the emergency track, internet-facing and critical systems first.
- EPSS above your threshold on an exposed or critical system: the next track.
- Everything else: CVSS severity, adjusted for exposure and compensating controls, sets the routine schedule.
- Anything that cannot meet its track gets a mitigation, a named owner and an expiry date.
None of this works without an asset inventory that says what is internet-facing and what the business depends on. CISA makes the same point in its BOD 22-01 guidance: you cannot match KEV to your estate without knowing what you run. Write the tracks and their deadlines into policy so the decision is made once, not argued per ticket.
Building that is a vulnerability management program. Where scanning ends and testing starts is in pentest vs vulnerability scan, and exceptions that outlive their expiry belong in the risk register.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Testing and adversary simulation are carried out only with signed authorization, to a scope agreed in writing.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
What is the difference between CVSS, EPSS and KEV?
CVSS rates how severe a vulnerability would be if exploited, EPSS estimates the probability it will see exploitation activity in the next 30 days, and KEV lists vulnerabilities with reliable evidence of exploitation in the wild. Severity, likelihood and fact.
What EPSS threshold should we use?
There is no universal number. Pick one that produces a queue your people can actually clear, check what it misses, and adjust. FIRST publishes both a probability and a percentile, so the threshold can be set either way.
Should we still patch every critical CVSS finding first?
Keep them on a defined schedule, but a critical score on an isolated internal server is less urgent than a KEV-listed flaw on an internet-facing gateway. Severity sets the routine track, not the emergency one.
Does KEV apply to Canadian organizations?
Not as a legal requirement. As of September 2026, the KEV remediation deadlines bind US federal civilian agencies only, under CISA’s BOD 26-04. CISA strongly recommends that every organization review and monitor the catalogue and prioritize the listed vulnerabilities, and a list of vulnerabilities known to be exploited is as relevant in Canada as anywhere.
Set your tracks
Send us a scanner export and a rough asset list. The reply shows how the backlog reorders under this rule and what the tracks should be. More of our writing is indexed at writing.