Exploit Prediction Scoring System (EPSS) score: what to expect from version 4.0?

The Exploit Prediction Scoring System (EPSS) offers a prioritization solution by calculating the probability that a given vulnerability will actually be exploited within the next 30 days. While the timeframe for this probability has been adjusted to align with organizational remediation schedules, its accuracy also continues to improve. EPSS v4 arrives on March 17, 2025, but what impact should we expect?

Let's look at the changes made to version 4 and their results.

Information sources and CVE scores have evolved

The data used to calculate the Exploit Prediction Scoring System score comes from a wide range of sources.

The latest article published by Jay Jacobs, Sasha Romanosky, Octavian Suciu, Benjamin Edwards, and Armin Sarabi in 2023 presents the third iteration of the EPSS model and mentions the following sources of information:

enhancing vulnerability prioritization
Table from the article “Enhancing Vulnerability Prioritization: Data-Driven Exploit Predictions with Community-Driven Insights”

‍

The EPSS model notably takes into account the exploitation history of vulnerabilities, mentions of the CVE in the CISA-KEV catalog and other sites, network activity, as well as data on available exploits or the affected vendors.

What adjustments have been made to these variables?

The EPSS score is now entering its fourth iteration, this time proposed by Empirical Security (a company founded by Jay Jacobs) in agreement with the Cyentia Institute.

With EPSS v4, the following changes are planned:

  • Improved data ingestion, processing, and monitoring;
  • Inclusion of malware activity and endpoint detection in vulnerability exploitation activity;
  • Addition of RSS/web mention data from a hundred sources;
  • Enrichment of NVD data with cve.org as a backup;
  • Addition of CVEs scanned by Shodan and HackerOne's Hacktivity reports;
  • Removal of several sources that are no longer updated.

These changes focus on adding CVE data to complement NVD information, including new mentions in reports and on the web, as well as new considerations regarding exploitation activity.

The more comprehensive the information gathered on a CVE, the better EPSS can calculate its probability of exploitation. It is therefore logical that maintaining these sources represents a significant portion of the modifications made to this version.

Do Exploit Prediction Scoring System v4 (EPSS v4) scores indicate a new trend?

Let’s first see if any changes are noticeable when comparing the full datasets from EPSS v3 and v4.

The following graph shows the distribution of CVEs based on EPSS scores.

Two groups are identified based on the activity observed in the CVE.

epss v3 vs epss v4
Distribution of EPSS scores by density

It is noticeable that CVEs for which no activity was observed—and which had a bounded score under EPSS v3—exhibit a smoother distribution curve under EPSS v4.

With these changes, the distribution of EPSS scores has shifted toward lower probability scores, adjusting the relevance of the EPSS score assigned to CVEs.

The scores for CVEs with observed activity have also shifted toward higher probabilities. Since a high score indicates a high likelihood that the CVE can be exploited, this will further emphasize their prioritization.

This change is also evident in the score distribution curve—this time shown as a percentile in the following graph—where the flattening of the EPSS v4 scores is visible for low probabilities.

The percentile indicates the percentage of CVEs with an EPSS score less than or equal to that of the vulnerability in question.

epss v3 vs epss v4
Distribution of EPSS scores by percentile

Again, low EPSSv4 scores are spread out, indicating that no solid evidence of exploitation has been found for these CVEs. Overall, the number of CVEs with a high EPSS v4 score is lower compared to EPSS v3 for the same EPSS score.

This is clearly distinguishable for CVEs with a score below 0.1%, also due to the logarithmic scale used.

This data must be linked to the EPSS score's predictive effort, which helps determine the urgency of patching a vulnerability.

Can EPSS v4 predict CVE exploitation?

The EPSS score, generated daily, provides a probability of vulnerability exploitation within the next 30 days. Does this score reflect reality?

The best way to determine the effectiveness of the probability provided by the EPSS v4 score is to compare the prediction with the actual observed exploitation activity of the CVE.

To do this, we can refer to the chart provided by Empirical Security, which presents a curve of the proportion of exploited CVEs based on their EPSS v4 score, covering 9,218 CVEs with activity over a 30-day period.

epss v4 prediction
Graph from the Empirical Security article on the prediction made by EPSS v4

The probability curve provided by EPSS v4 still follows the model's ideal curve, where the observed proportion is equal to the probability assigned to the CVEs.

In the given example, EPSS estimates a 1% probability of exploitation for 2,100 CVEs. The actual observed situation shows 28 exploited CVEs out of those scored.

This represents a proportion of 1.33%. The gap between the EPSS probability and the actual proportion seems significant, but it remains within the 95% confidence interval.

The goal is not so much to predict CVE exploitation as it is to judge the urgency of remediation. Indeed, between two CVEs with equivalent CVSS scores that are both critical, the EPSS score allows them to be classified into "Important and not urgent" and "Important and urgent" categories, because the number of CVEs with high CVSS scores is high (approximately 20% of critical CVEs published in 2025 to date), making prioritization necessary in this case.

EPSS v3 and v4 scores: what is the immediate impact on scores?

An CVE’s EPSS score changes constantly as new data is taken into account (published exploits, information on affected CPEs, etc.), but changes to the models used can suddenly alter all—or nearly all—of the assigned scores.

Surprisingly, the number of CVEs with a score above 90% dropped from 2,600 to just 956. This trend may be linked to an adjustment made to the calculation that would reclassify CVEs with very high EPSS scores—and thus those that are difficult to compare—to lower scores.

From this perspective, these declines are reassuring, as fewer CVEs are likely to be exploited in the coming days. This also makes it easier to quantify the urgency of the situation.

When examining the differences in scores for CVEs sorted by year of publication, the following changes are observed:

scores for cves sorted by year of publication
Changes in the EPSS score for CVEs, sorted by year of publication

We see that CVEs published in 2024 generally show an increase in their scores with the move to EPSS v4. 2024 was a year in which the NVD faced significant difficulties in processing vulnerabilities. Furthermore, these are the most recently published CVEs, along with those from 2025, and they do not benefit from as long an exploitation history as others.

The addition of sources to complement the NVD, combined with their recent publication date, may explain this phenomenon.

The EPSS v3 model appears to have limitations when it comes to classifying the latest CVEs.

Among the reclassified CVEs, well-known vulnerabilities such as CVE-2024-6387 regreSShion and CVE-2024-3094 in XZ Utils have seen their EPSS scores skyrocket.

For CVE-2024-6387, its EPSS v3 score was 0.28%, placing it in the 68.8th percentile; with the EPSS v4 score, it jumps to 86% (well above the 0.5% threshold considered significant) and now sits in the 99.4th percentile.

Similarly, CVE-2024-3094 had an EPSS v3 score of 34.4%, already placing it among the highest-scoring CVEs in the 97th percentile, and it now moves to a score of 91.9% in the 99.7th percentile.

The trend of such reclassification seems to be confirmed for these already well-known CVEs.

So, what should you prepare for?

The refinement and reclassification of EPSS scores affect the risk categories assigned to CVEs, and therefore potentially impact remediation strategies and timelines, particularly for flaws that cross the "urgent" EPSS threshold (which is set to 0.5% by default for vulnerabilities in Cyberwatch).

The new EPSS v4 approach and the resulting changes are worth paying attention to when it arrives on March 17, ensuring that high-risk items remain visible and that newly downgraded threats do not receive excessive attention.

You now have everything you need to prepare for the arrival of EPSS v4 on Cyberwatch!

Thanks for submitting the form.