Skip to content
Weekly Signal

Cyber-security glossary

EPSS

A daily estimate of the probability that a published CVE will be exploited in the wild during the next 30 days.

Exploit Prediction Scoring System

Definition

A daily estimate of the probability that a published CVE will be exploited in the wild during the next 30 days.

Why it matters

Use probability, percentile and movement together. EPSS helps rank a large population, but it must be combined with product presence, reachability, consequence and controls.

Use it in practice

Start with authoritative evidence, record the source and freshness, and be explicit about what this term can and cannot tell you. Connect it to asset context and a named action rather than treating it as an isolated label.

Related terms

CVE · KEV · Exploitability