cvechain

Vulnerability intelligence

Not every CVE deserves a fire drill – learn which ones actually get exploited

About 61,000 CVEs were published in the last 12 months. Exploitation datasets observe attacks against only a fraction, but unobserved does not mean harmless. Combine the available signals with your affected assets to decide what to investigate and fix first.

  • Built on CVSS, EPSS & CISA KEV
  • Primary sources linked
  • Updated September 2026

What is a CVE

A CVE names the flaw. It doesn’t tell you what to do about it.

CVE is just an identifier. The decision – patch tonight, or next quarter – comes from the signals layered on top of it.

A CVE (Common Vulnerabilities and Exposures) is a unique public identifier for one specific security flaw – for example CVE-2024-3400. It is a name and a description, nothing more. It says a weakness exists; it does not say how dangerous it is to you.

To turn a CVE into a decision you add three signals. CVSS rates how severe the flaw is in the abstract. EPSS estimates how likely it is to be exploited in the next 30 days. The CISA KEV catalog records whether it is already being exploited in the wild.

Read together, CVE, CVSS, EPSS and KEV help distinguish known exploitation, forecast probability and technical severity. They support prioritisation; they cannot identify every future attack or replace your asset context.

The four signals

Read the chain, not just the score

Each signal answers a different question. Only together do they tell you what to do.

  1. CVE

    The identifier

    A unique ID (CVE-YYYY-NNNN) for one specific flaw, assigned by a CVE Numbering Authority. It’s the shared name everyone – vendors, scanners, feeds – uses to refer to the same vulnerability.

  2. CVSS

    The severity

    A 0–10 score describing how bad the flaw is if exploited (attack vector, complexity, impact). A Base score describes intrinsic severity; Threat and Environmental metrics add context. A Base score alone cannot set your remediation priority.

  3. EPSS

    The probability

    The Exploit Prediction Scoring System gives each CVE a 0–100% probability of being exploited in the next 30 days, updated daily from real-world data. It’s how you find the needles in the CVSS haystack.

  4. KEV

    The proof

    CISA’s Known Exploited Vulnerabilities catalog lists CVEs confirmed to be exploited in the wild. An entry confirms evidence of exploitation; it does not prove that your assets are affected or that attacks are occurring at this moment.

Prioritise like an attacker

From 61,000 CVEs to a short list

Attackers don’t sort by CVSS – they use what works and what’s reachable. Mirror that, and four tiers fall out.

  • Act now

    Known-exploited & exposed

    Confirmed in use against real targets, on an asset an attacker can reach. This is your fire.

    Signal: In CISA KEV, or high EPSS on an internet-facing asset

  • This week

    Likely & reachable

    Not confirmed exploited yet, but a strong probability and a path to the asset. Patch before it flips.

    Signal: High EPSS or critical CVSS on an exposed asset

  • Planned

    Severe but cold

    High CVSS but low exploit probability and no exposure. Schedule it into normal patch cycles.

    Signal: High CVSS, low EPSS, asset not exposed

  • Monitor

    Low signal

    Low probability and not reachable. Track it – EPSS can rise overnight when an exploit drops.

    Signal: Low EPSS, not exposed – re-check as the score moves

Free tool

Should you drop everything for this CVE?

Select the signals you have verified. This illustrative routing tool uses the 4% EPSS threshold FIRST gives as the effort-equivalent of a CVSS Critical policy, not a universal remediation rule. An unchecked item may be unknown; confirm affected versions, exposure and business impact before setting a deadline.

Interactive mode is not available. You can read the full reference content below. No answers are assessed and no result is calculated.

  • Listed in the CISA KEV catalog

    Confirmed exploited in the wild

  • EPSS ≥ 4% (≈ 90th percentile)

    FIRST’s effort-equivalent of a CVSS Critical policy

  • CVSS ≥ 9.0 (Critical)

    Severe impact if exploited

  • Internet-facing or attacker-reachable

    The affected asset is exposed

  • A fix or mitigation is available

    You can actually act on it

Where those signals route a finding

Act now Review urgently
You selected a KEV listing, or elevated EPSS with reachability. Confirm the affected product and version, then prioritise remediation using exposure, impact and applicable deadlines. Consider containment and signs of prior compromise where appropriate.
This week Schedule a remediation review
Your selections combine a severity or probability signal with exposure or an available fix. Confirm the missing context and assign an owner and deadline. The tool does not establish that the asset is reachable or that waiting a week is acceptable.
Planned Complete the remediation context
A severity or probability signal is selected. Verify reachability, business impact and available mitigations before choosing a patch cycle. Missing selections do not prove that exposure or exploitation is absent.
Review Check the missing signals
No KEV, elevated EPSS or Critical CVSS signal is selected. This does not establish low risk or lack of exposure. Check the current evidence and affected assets, then assign routine remediation or escalate where warranted.
Open Threat Radar
Toggle what you know about the CVE

Suggested triage route

Act now

Review urgently

You selected a KEV listing, or elevated EPSS with reachability. Confirm the affected product and version, then prioritise remediation using exposure, impact and applicable deadlines. Consider containment and signs of prior compromise where appropriate.

This week

Schedule a remediation review

Your selections combine a severity or probability signal with exposure or an available fix. Confirm the missing context and assign an owner and deadline. The tool does not establish that the asset is reachable or that waiting a week is acceptable.

Planned

Complete the remediation context

A severity or probability signal is selected. Verify reachability, business impact and available mitigations before choosing a patch cycle. Missing selections do not prove that exposure or exploitation is absent.

Review

Check the missing signals

No KEV, elevated EPSS or Critical CVSS signal is selected. This does not establish low risk or lack of exposure. Check the current evidence and affected assets, then assign routine remediation or escalate where warranted.

Open Threat Radar

A teaching aid, not a scoring engine – the 4% EPSS threshold and suggested time bands are illustrative. Real triage also weighs asset value, compensating controls, binding deadlines and business context; unchecked is not evidence of absence.

The numbers

Why prioritisation is the whole game

Use current evidence to prioritise the vulnerabilities that actually affect your assets.

61,000
CVEs were published in the last 12 months, of which just over 10% carried a CVSS Critical rating – a catalog-wide figure, not the number affecting any one organisation.
Source: FIRST · Using EPSS, 2026
30 days
is the EPSS forecast horizon: the estimated probability that exploitation of a published CVE will be observed in the next 30 days, not the probability your organisation will be breached.
Source: FIRST · EPSS, 2026
1,709
CVEs are in CISA’s Known Exploited Vulnerabilities catalog – the “act now” set, confirmed in real attacks. Counted in catalog version 2026.09.11; it grows most weeks.
Source: CISA KEV (JSON feed), 2026
5 days
was the average time from disclosure to exploitation in 2023 once statistical outliers are excluded – 47 days with them. Prioritisation has to be fast.
Source: Mandiant: 2023 Time-to-Exploit Trends, 2024

Each figure links to its primary source. Numbers are approximate and updated as new reports are published.

For security teams

You can’t patch 61,000 CVEs. You can patch the ones that matter.

Turning the chain into a repeatable, continuous process is where prioritisation stops being a spreadsheet and starts being defence.

CISA’s Binding Operational Directive 26-04 requires U.S. federal civilian executive branch agencies to prioritise security updates by risk, building on the KEV catalog established under the now-revoked BOD 22-01 – a useful reference for organisations outside its binding federal scope.

Reference: CISA BOD 26-04

  • Enrich, don’t just scan

    A scanner gives you CVEs and CVSS. Layering EPSS and KEV on top turns a 10,000-line report into a short, ranked action list.

  • Exposure changes the priority

    Internet exposure can increase urgency. Internal reachability, privilege, sensitive data and critical functions also matter – isolation alone does not make a vulnerability routine.

  • Continuous, not quarterly

    EPSS updates daily and KEV grows weekly. A CVE that was “monitor” on Monday can be “act now” by Friday when an exploit lands.

  • Validate attack paths

    A scoped penetration test can demonstrate exploitation paths and assess controls. Failure to reproduce an exploit is not proof that exploitation is impossible.

Frequently asked questions

Short, clear answers

What is a CVE?

A CVE (Common Vulnerabilities and Exposures) is a unique public identifier for one specific security flaw, in the form CVE-YYYY-NNNN. It names and describes the vulnerability so everyone refers to the same thing, but it does not rank or score it.

What is the difference between CVSS and EPSS?

CVSS scores how severe a vulnerability is (0–10) based on its technical characteristics. EPSS estimates how likely it is to be exploited in the next 30 days (0–100%). Severity is not the same as probability – a Critical CVSS flaw can have a very low EPSS, and vice versa, which is why the two scores only work as a pair.

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities catalog is a list, maintained by the U.S. Cybersecurity and Infrastructure Security Agency, of CVEs confirmed to be exploited in real-world attacks. If a CVE is in KEV, it should be treated as an urgent, patch-first item.

How should I prioritise which vulnerabilities to patch first?

The prioritisation playbook starts with what is exploited and reachable: anything in CISA KEV, or with a high EPSS score, on an internet-facing or attacker-reachable asset. Then work down through high-probability and high-severity items. CVSS alone is a poor sorting key because severity alone does not establish urgency.

What does the EPSS score actually mean?

An EPSS score is the estimated probability that a vulnerability will be exploited in the wild within the next 30 days, from 0% to 100%. It is produced daily by FIRST from real exploitation and threat data, so it changes over time as the situation evolves.

Is a high CVSS score enough to justify emergency patching?

Usually not on its own. Because a large share of all CVEs score 7.0 or higher, a Base score alone cannot tell which assets need urgent remediation. Combine it with EPSS (probability) and KEV (confirmed exploitation) plus whether the asset is exposed before declaring an emergency.

Where do CVE, CVSS, EPSS and KEV data come from?

CVE IDs come from CVE Numbering Authorities (coordinated by MITRE/CVE.org). CVSS scores are published in the NVD and by vendors. EPSS is produced by FIRST. KEV is maintained by CISA. cvechain explains how they fit together and links to each primary source.

How can a team keep this up to date automatically?

Manual triage doesn’t scale when EPSS changes daily and KEV grows weekly. Teams typically feed CVE, EPSS and KEV data into their vulnerability workflow, weighted by exposure. Continuous services such as OffSeq Threat Radar automate the monitoring and enrichment.