Last computed: August 13, 2026 from the FIRST EPSS feed and the official CISA KEV catalog. Updated daily. Companion dataset: the CISA KEV Lag Tracker.
As of August 2026, 56.5% of the vulnerabilities CISA confirmed as actively exploited were not in the top 10% of EPSS risk the day before that confirmation. EPSS forecasts which CVEs will be exploited; the CISA KEV catalog records which ones were. Almost everyone compares the two on the same day, which proves nothing — EPSS reacts to the KEV listing. This page compares the forecast as it stood on the eve of each listing, across 1,665 KEV entries, and publishes the miss rate in both directions.
Headline Numbers
- 1,665 KEV entries measured; 1,376 had an EPSS score on the eve of their listing
- 289 (17.4%) had no EPSS score at all the day before CISA confirmed exploitation — typically because the CVE was not yet published
- Only 43.5% were in the top 10% of EPSS risk (percentile ≥ 90%)
- Only 23% carried a raw probability above 50%
- Median EPSS probability on the eve of confirmation: 4.3% (median percentile: 84.0%)
- EPSS scored 358,265 CVEs on August 12, 2026 (model v2026.06.15); 3,587 sit in its top 1%, and 815 of those are confirmed exploited
Where the Forecast Placed Them
Each confirmed-exploited CVE, bucketed by its EPSS percentile on the day before CISA listed it. The percentile is the primary measure here rather than the raw score: EPSS has changed model version several times since 2021, so a probability of 0.10 in 2022 does not mean what a 0.10 means today, while relative position within that day’s universe stays comparable.
| EPSS percentile on the eve of KEV listing | CVEs | Share |
|---|---|---|
| Top 1% (percentile ≥ 99) | 275 | 20% |
| Top 10% (90–99) | 323 | 23.5% |
| Top 25% (75–90) | 186 | 13.5% |
| Upper half (50–75) | 186 | 13.5% |
| Bottom half (below 50) | 406 | 29.5% |
The correction is visible in EPSS’s own numbers. Across the 1,376 entries where we hold both figures, the median probability was 4.27% on the eve of the KEV listing and is 63.27% today. The forecast moved after the confirmation, not before it — which is exactly why the eve-of-listing measurement is the only one worth reporting.
The pattern does not improve for the entries that matter most: of the 278 confirmed-exploited CVEs that CISA also flags as used in ransomware campaigns, 48.6% were in the top decile of EPSS risk the day before they were listed.
Is the Forecast Getting Better?
The same measurement split by the year each CVE entered the KEV catalog. Years with fewer than 20 measured entries are omitted. EPSS has shipped several model versions over this period, so this is the closest thing available to an outcome-based read on whether the newer models forecast real-world exploitation better than the older ones.
| Year added to KEV | Entries measured | Median percentile (eve) | Median probability (eve) | In top 10% |
|---|---|---|---|---|
| 2021 | 287 | 92.7% | 7.95% | 54% |
| 2022 | 507 | 90.0% | 9.03% | 50.1% |
| 2023 | 127 | 42.7% | 0.18% | 26.8% |
| 2024 | 136 | 59.2% | 0.21% | 33.1% |
| 2025 | 184 | 57.9% | 0.33% | 32.1% |
| 2026 | 135 | 74.6% | 1.17% | 37.8% |
What the Forecast Did Not See Coming
The 15 confirmed-exploited CVEs with the lowest EPSS percentile on the eve of their KEV listing. Every one of these was being exploited in the wild while the forecast placed it in the quiet part of the distribution — the ones a strictly EPSS-driven patch queue would have left for later.
| CVE | Vendor / Product | Added to KEV | EPSS percentile (eve) | EPSS probability (eve) | Lag (days) | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-47827 | IGEL IGEL OS | October 14, 2025 | 0.2% | 0.01% | 131 | No |
| CVE-2025-47729 | TeleMessage TM SGNL | May 12, 2025 | 0.3% | 0.01% | 4 | No |
| CVE-2025-41244 | Broadcom VMware Aria Operations and VMware Tools | October 30, 2025 | 0.4% | 0.01% | 31 | No |
| CVE-2026-3502 | TrueConf Client | April 2, 2026 | 0.9% | 0.01% | 3 | No |
| CVE-2026-31431 | Linux Kernel | May 1, 2026 | 0.9% | 0.01% | 9 | No |
| CVE-2024-53150 | Linux Kernel | April 9, 2025 | 1.3% | 0.01% | 106 | No |
| CVE-2025-68461 | Roundcube Webmail | February 20, 2026 | 1.4% | 0.01% | 64 | No |
| CVE-2026-9082 | Drupal Core | May 22, 2026 | 1.7% | 0.01% | 2 | No |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | April 20, 2026 | 1.7% | 0.01% | 54 | No |
| CVE-2025-38352 | Linux Kernel | September 4, 2025 | 2.3% | 0.02% | 44 | No |
| CVE-2025-48928 | TeleMessage TM SGNL | July 1, 2025 | 2.5% | 0.02% | 34 | No |
| CVE-2025-8088 | RARLAB WinRAR | August 12, 2025 | 3.0% | 0.02% | 4 | No |
| CVE-2025-48384 | Git Git | August 25, 2025 | 3.5% | 0.02% | 48 | No |
| CVE-2025-43510 | Apple Multiple Products | March 20, 2026 | 3.5% | 0.02% | 98 | No |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manger | April 20, 2026 | 3.5% | 0.02% | 54 | No |
Watchlist: Highest EPSS Scores Not in the KEV Catalog
The other side of the same cross. These are the 25 CVEs carrying the highest EPSS probability on August 12, 2026 that CISA has not confirmed as exploited, restricted to CVE identifiers assigned in 2023 or later. 71 CVEs from that period currently score above 90% without a KEV listing. A further 257 CVEs assigned before 2023 also score above 90% without a KEV listing — the well-known old flaws that get scanned for constantly, which EPSS scores highly for that reason. They are excluded here to keep the list forward-looking.
Read this as a forecast, not a finding: a CVE on this list has not been confirmed as exploited by anyone, and the numbers above show the forecast misses in both directions. It is the list of what EPSS expects — published so it can be checked against what actually happens.
| # | CVE | EPSS probability | Percentile | Published (NVD) | Description |
|---|---|---|---|---|---|
| 1 | CVE-2023-50387 | 99.99% | 99.98% | February 14, 2024 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D… |
| 2 | CVE-2025-53771 | 99.91% | 99.96% | July 20, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| 3 | CVE-2024-29825 | 99.88% | 99.96% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. |
| 4 | CVE-2024-29826 | 99.88% | 99.96% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. |
| 5 | CVE-2024-29823 | 99.86% | 99.96% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. |
| 6 | CVE-2023-27372 | 99.64% | 99.94% | February 28, 2023 | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. |
| 7 | CVE-2025-1974 | 99.52% | 99.94% | March 25, 2025 | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the… |
| 8 | CVE-2024-6387 | 99.51% | 99.94% | July 1, 2024 | A security regression (CVE-2006-5051) was discovered in OpenSSH’s server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth… |
| 9 | CVE-2023-37679 | 99.43% | 99.93% | August 3, 2023 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. |
| 10 | CVE-2023-32560 | 99.43% | 99.93% | August 10, 2023 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at… |
| 11 | CVE-2025-29927 | 99.30% | 99.93% | March 21, 2025 | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas… |
| 12 | CVE-2023-23333 | 99.29% | 99.93% | February 6, 2023 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. |
| 13 | CVE-2023-34960 | 99.19% | 99.93% | August 1, 2023 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted… |
| 14 | CVE-2023-28341 | 98.70% | 99.92% | April 11, 2023 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorre… |
| 15 | CVE-2023-38646 | 98.68% | 99.92% | July 21, 2023 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server’s privilege level. Authentic… |
| 16 | CVE-2025-4123 | 98.36% | 99.91% | May 22, 2025 | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha… |
| 17 | CVE-2023-29084 | 98.17% | 99.91% | April 13, 2023 | Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. |
| 18 | CVE-2023-6553 | 97.85% | 99.90% | December 15, 2023 | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to… |
| 19 | CVE-2023-0315 | 97.65% | 99.90% | January 16, 2023 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. |
| 20 | CVE-2024-10914 | 97.43% | 99.89% | November 6, 2024 | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_us… |
| 21 | CVE-2023-2948 | 96.73% | 99.88% | May 28, 2023 | Cross-site Scripting (XSS) – Generic in GitHub repository openemr/openemr prior to 7.0.1. |
| 22 | CVE-2023-35708 | 96.68% | 99.88% | June 16, 2023 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identif… |
| 23 | CVE-2023-2442 | 96.06% | 99.87% | June 7, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge req… |
| 24 | CVE-2023-51467 | 96.00% | 99.87% | December 26, 2023 | The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code |
| 25 | CVE-2023-0297 | 95.84% | 99.87% | January 14, 2023 | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. |
Frequently Asked Questions
What is EPSS?
The Exploit Prediction Scoring System (EPSS), published by FIRST, estimates the probability that a given CVE will be exploited in the wild within the next 30 days. It is a forecast, updated daily, and it is scored from 0 to 1. It is not a severity score: CVSS says how bad a flaw would be if exploited, EPSS says how likely exploitation is.
Does EPSS actually predict which vulnerabilities get exploited?
Partly. As of August 2026 we measured the EPSS forecast from the day before each CISA KEV listing across 1376 confirmed-exploited CVEs. 43.5% were in the top 10% of EPSS risk on the eve of confirmation; 56.5% were not. Only 23% carried a raw probability above 50%, and the median forecast was 4.3%.
Why measure the EPSS score from the day before, not today?
Because EPSS reacts to the KEV listing itself. Once CISA confirms exploitation, the score for that CVE rises — comparing today’s score against today’s KEV membership measures nothing. The only honest question is what the forecast said before the confirmation existed, which is what this dataset records.
Should I use EPSS to prioritise patching?
EPSS is useful for deprioritising: a low score on a CVE with no confirmed exploitation is a reasonable reason to wait. It is much weaker as a guarantee, because 56.5% of the vulnerabilities that were later confirmed as actively exploited sat outside its top decile the day before. The practical combination is EPSS for ordering the queue and the CISA KEV catalog for the entries that jump it.
How many CVEs does EPSS score?
358,265 CVEs carried an EPSS score on August 12, 2026, of which 3,587 sit in the top 1% by percentile. Only 815 of those top-1% CVEs are in the CISA KEV catalog — the rest are forecasts that have not been confirmed.
How often is this analysis updated?
Daily. Our automated tracking framework re-reads the EPSS feed and the CISA KEV catalog every day. The eve-of-listing score for each KEV entry is measured once from the FIRST API and never changes afterwards; the watchlist below is recomputed from the current day’s EPSS file.
Can I cite this dataset?
Yes — free to use and cite under CC BY 4.0 with attribution to CVEDaily (cvedaily.io/epss/).
Methodology
For every entry in the CISA KEV catalog we take the date CISA added it and query the FIRST EPSS API for that CVE’s score on the previous day — the last forecast published before the confirmation existed. Where EPSS did not publish on that date (its archive has occasional gaps), we step backwards one day at a time, never forwards: moving toward the listing date would contaminate the measurement with information published after CISA acted. Entries whose CVE had no EPSS score at all on that date are recorded as measured-without-data and excluded from the percentages, not silently dropped — they are reported above as their own figure.
Each eve-of-listing score is measured once and never revised. The current-day scores, the watchlist and the universe totals come from the daily EPSS score file and are recomputed every day. Nothing on this page is estimated or taken from a third-party summary: the figures come from FIRST, CISA and NVD records directly. This is an observational measurement of one forecast against one confirmation source, not a controlled evaluation of the EPSS model — CISA’s catalog is itself an incomplete record of real-world exploitation, and a CVE missing from it is not proof that nobody exploited it.
This dataset is free to cite with attribution to CVEDaily (CC BY 4.0).