The security industry is shifting from relying solely on CVSS to combining CVSS, EPSS, and KEV for smarter vulnerability patch prioritization. CVSS
In today's DevOps and rapidly iterating software development environment, the number of vulnerabilities is experiencing explosive growth. Traditional strategies that rely solely on CVSS (Common Vulnerability Scoring System) scores to determine patch prioritization are now insufficient. According to an analysis by DevSecOps Taiwan community advisor Kao Yu-Jie (HackerCat) at the DevOpsDays event, many frontline developers and security newcomers remain unclear about the practical significance behind CVSS, EPSS (Exploit Prediction Scoring System), and KEV (Known Exploited Vulnerabilities). While CVSS provides a theoretical measure of危害程度 (harm severity), it lacks temporal dynamics and enterprise environmental context, making it difficult for security teams to accurately determine which vulnerabilities truly require immediate handling. For this reason, the security industry is shifting toward a filtering perspective that combines these three metrics, using layered filtering to identify the most urgently needed critical vulnerabilities for patching.
The core technical framework proposed by Kao Yu-Jie treats CVSS, EPSS, and KEV as complementary filtering perspectives. First, CVSS is the starting point, established by the international organization FIRST, categorizing risk into four levels: Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), and Critical (9.0–10.0). However, CVSS only measures vulnerability severity (e.g., Remote Code Execution [RCE] is almost always classified as Critical), which does not necessarily indicate that attackers are actively exploiting it. Second, EPSS focuses on predicting the probability that a vulnerability will be exploited within the next 30 days, with scores ranging from 0.0 to 1.0 (0%–100%). Kao Yu-Jie notes that vulnerabilities with an EPSS score greater than 1% fall into the high-risk category. EPSS is a machine learning model based on real threat intelligence, incorporating features such as public PoC or exploit code, making it more practical than CVSS. Finally, KEV, published by the U.S. CISA, directly confirms that a vulnerability has been targeted and actively exploited in the real world (Exploited in the wild). This means KEV vulnerabilities possess the highest urgency; even if their CVSS score is low, they should be prioritized. Through filtering with these three metrics, the most urgently needed vulnerabilities for patching can be identified.
The impact scope of this optimization strategy covers global security teams and development organizations, particularly enterprises facing massive vulnerability volumes and limited patching resources. Relying solely on CVSS may cause security teams to waste significant resources on theoretically severe but practically unexploited vulnerabilities, leading to extended Mean Time to Remediate (MTTR) and leaving truly dangerous vulnerabilities unpatched. Conversely, adopting the CVSS+EPSS+KEV framework allows enterprises to significantly reduce patching friction and concentrate resources on "prioritizing the right" vulnerabilities. Additionally, this strategy affects communication patterns: security personnel must shift from rigid score-based descriptions to concrete threat scenarios to enhance developer security awareness. For federal agencies and large enterprises, adhering to the CISA KEV list is not only a compliance requirement but also a key measure to reduce attack risk. However, the KEV list also has timeliness gaps (security vendors disclose first, then CISA adds) and geographic limitations (primarily reflecting U.S.-related threats), so enterprises must evaluate based on their own environments.
To effectively optimize vulnerability patch prioritization, organizations should implement the following protective measures: First, establish a scoring matrix combining CVSS and EPSS, classifying "High EPSS + High CVSS" vulnerabilities as "Patch Immediately" and "High EPSS + Low CVSS" as "Priority Attention." Second, treat weaknesses in the KEV list as highest priority and do not downgrade them solely due to low CVSS scores. Third, when a high EPSS score is detected but immediate patch updates are unavailable, immediately activate compensatory control measures, such as deploying WAF rules targeting the specific CVE signature in a Web Application Firewall (WAF) or strengthening detection at network boundaries. Fourth, promote tool automation: security teams should provide "one-click upgrade" PRs (Pull Requests) to reduce engineers' burden of manually querying and modifying package.json. Finally, cultivate 1 to 2 security seeds within each development team to lower internal communication costs, and regularly demonstrate trends in MTTR reduction and changes in total vulnerability counts so development teams can see progress.