logo

EPSS and vulnerability management: New scoring system shows promise

ID: ec6762d4-dad1-519a-b5b3-b10c1585871d

STIX ID: report--ec6762d4-dad1-519a-b5b3-b10c1585871d

Feed Name: ReversingLabs Blog

Date Published: 2024-09-03

Date Updated: 2026-04-29

Author: [email protected] (Jaikumar Vijayan)

...
...

A research review by Cyentia Institute and FIRST finds that EPSS more effectively prioritizes vulnerabilities likely to be exploited than CVSS severity alone and is complementary to CISA’s KEV. Key insights include that exploitation often targets older CVEs, many exploits occur soon after disclosure (notably within the first month to year), and exploitation intensity/duration varies widely across vulnerabilities. The report recommends using EPSS in conjunction with CVSS, KEV, and environmental context to optimize remediation, while noting EPSS is data-dependent and not infallible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.