EPSS Scoring of Risks
This feature is not available to all tiers, please contact us if you would like to discuss adding this feature to your Hexiosec ASM account.
What is EPSS?
EPSS stands for Exploit Prediction Scoring System. It’s an open and data-driven effort by the Forum of Incident Response and Security Teams (FIRST.org) designed to estimate the likelihood that a software vulnerability will experience exploitation activity in the wild within the next 30 days.
In addition to CVSS (Common Vulnerability Scoring System), which focus on technical characteristics of a vulnerability, EPSS adds a predictive layer by using real-world data to estimate how likely it is that a specific vulnerability will be targeted by attackers.
To generate a dynamic score that reflects current likelihood of exploitation activity EPSS combines:
- CVE metadata (from NVD)
- Real-world exploit data (from threat intelligence sources)
- Machine learning models
What does the EPSS Score mean?
The EPSS score is a probability often expressed as a percentage. It indicates the likelihood that a vulnerability will experience exploitation activity in the next 30 days.
For example:
- An EPSS score of 1% means the vulnerability is very unlikely to experience exploitation activity soon.
- An EPSS score of 85% suggests the vulnerability is highly likely to experience exploitation activity soon.
This score is recalculated regularly, and will update each time your scan runs, reflecting the latest insights and attacker trends.
What is the EPSS Percentile?
The EPSS percentile indicates the percentage of other vulnerabilities with lower or equal scores. This indicates the ranking of a vulnerability in the EPSS model, showing how a specific vulnerability compares to all other vulnerabilities.
For example:
- A vulnerability with an EPSS percentile of 95% (i.e. in the 95th percentile), means it is among the top 5% of vulnerabilities likely to experience exploitation activity.
- A vulnerability with an EPSS percentile of 10% (i.e. in the 10th percentile), means it is less likely to experience exploitation activity than 90% of others.
This helps you quickly rank and compare vulnerabilities, especially when managing a large volume of risks.
How to see EPSS scores in ASM
In Hexiosec ASM all Risks in the Vulnerability category (i.e. CVEs) will have an EPSS score and percentile. These values are visible from the following places:
- Vulnerabilities widget on the Overview page
- On the Risks for vulnerability risks
- Actions page in the Kanban and List views for each Action and its Risks
- Explore page for a given vulnerability Risk
It is also possible to view the EPSS model version and the last updated date of the scoring from the Explore page for a given Risk, and the expandable row section on the Risks page.
Model Version vs Last Updated Date
EPSS scores come with two key timestamps: the model version and the last updated date - they serve different purposes.
What is the Model Version?
The model version refers to the specific version of the EPSS algorithm used to generate the scores. It is date-based (e.g. v2025.07.07) and only changes when FIRST.org releases a new version of the underlying model. These releases may include improved prediction logic, additional data sources, or refinements in how risk is calculated.
Why does the Model Version not match the Last Updated date?
It is normal for the model version to appear older than the last updated date. This is because the model version only changes when the scoring algorithm itself is updated.
The last updated date reflects the most recent recalculation of EPSS scores and percentiles, based on new exploit data and threat intelligence. This happens regularly, and will update for a given scan each time it runs.
So even if the model version hasn’t changed recently, scores are still kept up to date with the latest activity observed in the wild.