CVSS vs EPSS vs KEV: Risk-Based Vulnerability Prioritization
CVSS vs EPSS vs KEV explained: CVSS 4.0 severity, exploit probability and known-exploited lists, combined into a practical vulnerability prioritization model.
By NetGuardUpdated: 8 min readنسخه فارسی

CVSS, EPSS and KEV answer three different questions about a vulnerability: how severe is it, how likely is it to be exploited soon, and is it already being exploited? In the CVSS vs EPSS vs KEV debate, the right answer is not to pick one. Vulnerability prioritization works best when you combine all three with your own asset context, instead of sorting a scanner report by CVSS score.
This matters because roughly 40,000 CVEs were published in 2024, and many of them carry High or Critical scores. No team can fix everything at once. A risk-based model lets you fix the small set of vulnerabilities that attackers actually use, on the systems that matter most, first, and defend that choice to auditors and management.
What is CVSS? Metric groups in CVSS 4.0
The Common Vulnerability Scoring System (CVSS) is maintained by FIRST. Version 4.0, released in November 2023, scores a vulnerability from 0 to 10 using four metric groups:
- Base: the intrinsic characteristics of the flaw. Exploitability metrics are Attack Vector, Attack Complexity, Attack Requirements, Privileges Required and User Interaction. Impact metrics cover confidentiality, integrity and availability of the vulnerable system and of subsequent systems.
- Threat: Exploit Maturity, which adjusts the score based on whether exploitation has been seen or proof-of-concept code exists. It replaces the Temporal group from CVSS 3.1.
- Environmental: your own security requirements and modified base metrics, so the same CVE can score differently on a payment server and a lab machine.
- Supplemental: extra context that does not change the score, such as Safety, Automatable, Recovery, Value Density, Vulnerability Response Effort and Provider Urgency.
CVSS 4.0 also asks you to label which groups were used: CVSS-B (Base only), CVSS-BT (Base and Threat), CVSS-BE and CVSS-BTE. Most public feeds publish CVSS-B. A typical vector looks like CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N: network-reachable, no privileges or user interaction needed, high impact on the vulnerable system.
CVSS severity bands
| Rating | CVSS score |
|---|---|
| None | 0.0 |
| Low | 0.1–3.9 |
| Medium | 4.0–6.9 |
| High | 7.0–8.9 |
| Critical | 9.0–10.0 |
Why CVSS alone overwhelms teams
CVSS measures technical severity, usually in a worst-case scenario. It was never meant to be a full risk score, yet many programs use the Base score as the only sorting key. The result is predictable:
- A large share of findings lands in High or Critical, so the "urgent" list is thousands of items long.
- The Base score does not know whether an exploit exists or whether attackers are using it.
- It does not know your environment: a Critical flaw on an isolated test VM gets the same score as one on an internet-facing VPN gateway.
- Teams miss SLAs, request blanket exceptions, and the few vulnerabilities that are actively exploited get buried among theoretical ones.
What is EPSS?
The Exploit Prediction Scoring System (EPSS), also maintained by FIRST, estimates the probability that a CVE will see exploitation activity in the wild in the next 30 days. Scores are updated daily and come in two forms: a probability between 0 and 1, and a percentile that shows how a CVE ranks against all others.
EPSS is useful for ranking large backlogs: it pushes the small fraction of CVEs that are likely to be targeted to the top. Keep its limits in mind:
- It covers only vulnerabilities with a CVE ID, not misconfigurations.
- It is not specific to your assets or exposure.
- Scores change over time, so a low score today is not a guarantee for next month.
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog has been published by CISA since November 2021. A vulnerability is added when it has a CVE ID, reliable evidence of active exploitation and a clear remediation action. US federal civilian agencies are required to fix KEV entries by the listed due dates, but any organization can use the catalog as a "fix now" list. It is available as a machine-readable feed, so scanners and ticketing systems can consume it automatically.
KEV is high-signal but not complete. Absence from KEV does not mean a vulnerability is not being exploited; it means CISA has not confirmed it.
CVSS vs EPSS vs KEV at a glance
| CVSS | EPSS | KEV | |
|---|---|---|---|
| Question answered | How severe is it? | How likely is exploitation in 30 days? | Is it already exploited? |
| Maintained by | FIRST | FIRST | CISA |
| Output | Score 0–10 plus vector | Probability and percentile | Listed or not, with due date |
| Updates | When the record changes | Daily | As new evidence appears |
| Best used for | Impact and environmental tuning | Ranking large backlogs | The must-fix-now list |

Asset criticality: the missing factor
None of these scores knows what an asset means to your business. Add your own context:
- Business criticality: does the system support revenue, safety or core operations?
- Exposure: is it reachable from the internet, from partner networks, or only internally?
- Data sensitivity: does it store personal, financial or classified data?
- Compensating controls: is the vulnerable service disabled, segmented or protected by a WAF?
Most organizations get far with three tiers: Tier 1 for crown-jewel and internet-facing systems, Tier 2 for important internal systems, Tier 3 for everything else.
A risk-based vulnerability prioritization model
A simple, defensible model applies the signals in order:
- In KEV? Priority 1, regardless of CVSS.
- High EPSS or a public exploit? Priority 1 on Tier 1 assets, Priority 2 elsewhere.
- No exploitation signal? Use CVSS severity combined with asset tier.
- Low severity on Tier 3 assets? Batch into regular maintenance or formally accept the risk.
The table below applies this model to five hypothetical findings. The EPSS threshold and target dates are examples; set your own based on capacity and risk appetite.
| Finding (hypothetical) | CVSS | EPSS | KEV | Asset | Priority | Target |
|---|---|---|---|---|---|---|
| A: Remote code execution on VPN gateway | 9.3 | 0.94 | Yes | Internet-facing, Tier 1 | P1 | 7 days |
| B: Privilege escalation on file server | 7.3 | 0.45 | Yes | Internal, Tier 2 | P1 | 7 days |
| C: SQL injection in customer portal | 8.7 | 0.12 | No | Internet-facing, Tier 1 | P2 | 30 days |
| D: Deserialization flaw in test app | 9.2 | 0.01 | No | Internal lab, Tier 3 | P3 | 90 days |
| E: Stored XSS in intranet wiki | 5.1 | 0.002 | No | Internal, Tier 3 | P4 | Next cycle |
Notice finding D: it has one of the highest CVSS scores but drops to P3 because there is no exploitation signal and the asset is low value. Finding B, scored only High, jumps to P1 because it is in KEV. That reordering is the whole point. Feed these priorities into remediation SLAs as part of your vulnerability management lifecycle and your patch management process. For the basics of identifiers, see what a CVE is; for extending this approach beyond CVEs, read about exposure management and CTEM.
How NetGuard helps
NetGuard's vulnerability scanner applies risk-based prioritization out of the box: findings are enriched with exploit intelligence, including known-exploited vulnerabilities and public exploit availability, and weighted by the asset criticality you assign. Authenticated scanning reduces false positives, rescans verify fixes, and executive and technical reports are available in Persian and English for on-premises or air-gapped deployments. Contact us to try it on your environment.
Frequently asked questions
What CVSS score is considered critical?
In CVSS 3.x and 4.0, a score from 9.0 to 10.0 is rated Critical, 7.0 to 8.9 is High, 4.0 to 6.9 is Medium, 0.1 to 3.9 is Low and 0.0 is None. A Critical rating describes technical severity only. Whether it should be fixed first also depends on exploitation evidence, such as KEV or EPSS, and on how important the affected asset is.
What is the difference between CVSS and EPSS?
CVSS describes how severe a vulnerability would be if exploited; EPSS estimates how likely it is to be exploited in the next 30 days. Both are maintained by FIRST. A vulnerability can have a high CVSS score but a very low EPSS probability, or the reverse, which is why using them together gives a better priority order.
What does KEV mean in cybersecurity?
KEV stands for Known Exploited Vulnerabilities, a catalog maintained by CISA since November 2021. It lists CVEs with reliable evidence of active exploitation and a clear remediation action. US federal agencies must remediate entries by set deadlines, and many organizations worldwide use KEV as their top-priority patch list.
Does CVSS 4.0 replace CVSS 3.1?
CVSS 4.0, released by FIRST in November 2023, is the current version and is gradually being adopted by CNAs, NVD and security vendors. Many records still carry CVSS 3.1 scores, so tools and teams will need to handle both for some time. Always check which version and which metric groups a score is based on.
Should we patch everything in the KEV catalog?
Every KEV entry that matches an asset you own should be treated as top priority, because attackers are confirmed to be using it. In practice, start with internet-facing and business-critical systems. If a patch cannot be applied quickly, use the remediation or mitigation guidance in the entry and document a short, time-limited exception.
- #CVSS vs EPSS vs KEV
- #vulnerability prioritization
- #CVSS 4.0
- #EPSS score
- #CISA KEV catalog
- #risk-based vulnerability management




