CVSS says how bad, CISA KEV says whether it is being exploited, EPSS says how likely it is next. On our Exploited & Unpatchable feed they openly disagree — a confirmed-exploited FortiOS flaw sits at 1.26% EPSS while a TeamCity flaw at CVSS 9.8 sits at 10.7%. How to read all three, and what changes when the software is end-of-life.
The three questions, precisely stated
| Signal | Question it answers | Tense | Who produces it |
|---|---|---|---|
| CVSS | How bad would this be if exploited? | Conditional | The vendor (as CNA) and/or NVD |
| CISA KEV | Is this being exploited, in reality? | Past & present | CISA, on evidence |
| EPSS | How likely is exploitation in the next 30 days? | Forecast | FIRST.org, a daily model |
What's covered
- The three questions, precisely stated
- Twelve vulnerabilities, scored three ways
- Case 1: confirmed exploited, lowest probability in the set
- Case 2: the highest severity, near the bottom for probability
- Case 3: the medium-severity flaw ransomware crews preferred
- The fourth disagreement: the scorers disagree with each other
- The column that changes the answer
- How to actually triage
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-scores-disagree
Top comments (0)