Last computed: August 13, 2026 from the FIRST EPSS feed and the official CISA KEV catalog. Updated daily. Companion dataset: the CISA KEV Lag Tracker.

As of August 2026, 56.5% of the vulnerabilities CISA confirmed as actively exploited were not in the top 10% of EPSS risk the day before that confirmation. EPSS forecasts which CVEs will be exploited; the CISA KEV catalog records which ones were. Almost everyone compares the two on the same day, which proves nothing — EPSS reacts to the KEV listing. This page compares the forecast as it stood on the eve of each listing, across 1,665 KEV entries, and publishes the miss rate in both directions.

Headline Numbers

Where the Forecast Placed Them

Each confirmed-exploited CVE, bucketed by its EPSS percentile on the day before CISA listed it. The percentile is the primary measure here rather than the raw score: EPSS has changed model version several times since 2021, so a probability of 0.10 in 2022 does not mean what a 0.10 means today, while relative position within that day’s universe stays comparable.

EPSS percentile on the eve of KEV listingCVEsShare
Top 1% (percentile ≥ 99)27520%
Top 10% (90–99)32323.5%
Top 25% (75–90)18613.5%
Upper half (50–75)18613.5%
Bottom half (below 50)40629.5%

The correction is visible in EPSS’s own numbers. Across the 1,376 entries where we hold both figures, the median probability was 4.27% on the eve of the KEV listing and is 63.27% today. The forecast moved after the confirmation, not before it — which is exactly why the eve-of-listing measurement is the only one worth reporting.

The pattern does not improve for the entries that matter most: of the 278 confirmed-exploited CVEs that CISA also flags as used in ransomware campaigns, 48.6% were in the top decile of EPSS risk the day before they were listed.

Is the Forecast Getting Better?

The same measurement split by the year each CVE entered the KEV catalog. Years with fewer than 20 measured entries are omitted. EPSS has shipped several model versions over this period, so this is the closest thing available to an outcome-based read on whether the newer models forecast real-world exploitation better than the older ones.

Year added to KEVEntries measuredMedian percentile (eve)Median probability (eve)In top 10%
202128792.7%7.95%54%
202250790.0%9.03%50.1%
202312742.7%0.18%26.8%
202413659.2%0.21%33.1%
202518457.9%0.33%32.1%
202613574.6%1.17%37.8%

What the Forecast Did Not See Coming

The 15 confirmed-exploited CVEs with the lowest EPSS percentile on the eve of their KEV listing. Every one of these was being exploited in the wild while the forecast placed it in the quiet part of the distribution — the ones a strictly EPSS-driven patch queue would have left for later.

CVEVendor / ProductAdded to KEVEPSS percentile (eve)EPSS probability (eve)Lag (days)Ransomware
CVE-2025-47827IGEL IGEL OSOctober 14, 20250.2%0.01%131No
CVE-2025-47729TeleMessage TM SGNLMay 12, 20250.3%0.01%4No
CVE-2025-41244Broadcom VMware Aria Operations and VMware ToolsOctober 30, 20250.4%0.01%31No
CVE-2026-3502TrueConf ClientApril 2, 20260.9%0.01%3No
CVE-2026-31431Linux KernelMay 1, 20260.9%0.01%9No
CVE-2024-53150Linux KernelApril 9, 20251.3%0.01%106No
CVE-2025-68461Roundcube WebmailFebruary 20, 20261.4%0.01%64No
CVE-2026-9082Drupal CoreMay 22, 20261.7%0.01%2No
CVE-2026-20128Cisco Catalyst SD-WAN ManagerApril 20, 20261.7%0.01%54No
CVE-2025-38352Linux KernelSeptember 4, 20252.3%0.02%44No
CVE-2025-48928TeleMessage TM SGNLJuly 1, 20252.5%0.02%34No
CVE-2025-8088RARLAB WinRARAugust 12, 20253.0%0.02%4No
CVE-2025-48384Git GitAugust 25, 20253.5%0.02%48No
CVE-2025-43510Apple Multiple ProductsMarch 20, 20263.5%0.02%98No
CVE-2026-20122Cisco Catalyst SD-WAN MangerApril 20, 20263.5%0.02%54No

Watchlist: Highest EPSS Scores Not in the KEV Catalog

The other side of the same cross. These are the 25 CVEs carrying the highest EPSS probability on August 12, 2026 that CISA has not confirmed as exploited, restricted to CVE identifiers assigned in 2023 or later. 71 CVEs from that period currently score above 90% without a KEV listing. A further 257 CVEs assigned before 2023 also score above 90% without a KEV listing — the well-known old flaws that get scanned for constantly, which EPSS scores highly for that reason. They are excluded here to keep the list forward-looking.

Read this as a forecast, not a finding: a CVE on this list has not been confirmed as exploited by anyone, and the numbers above show the forecast misses in both directions. It is the list of what EPSS expects — published so it can be checked against what actually happens.

#CVEEPSS probabilityPercentilePublished (NVD)Description
1CVE-2023-5038799.99%99.98%February 14, 2024Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D…
2CVE-2025-5377199.91%99.96%July 20, 2025Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
3CVE-2024-2982599.88%99.96%May 31, 2024An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
4CVE-2024-2982699.88%99.96%May 31, 2024An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
5CVE-2024-2982399.86%99.96%May 31, 2024An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
6CVE-2023-2737299.64%99.94%February 28, 2023SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
7CVE-2025-197499.52%99.94%March 25, 2025A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the…
8CVE-2024-638799.51%99.94%July 1, 2024A security regression (CVE-2006-5051) was discovered in OpenSSH’s server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth…
9CVE-2023-3767999.43%99.93%August 3, 2023A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
10CVE-2023-3256099.43%99.93%August 10, 2023An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at…
11CVE-2025-2992799.30%99.93%March 21, 2025Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas…
12CVE-2023-2333399.29%99.93%February 6, 2023There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
13CVE-2023-3496099.19%99.93%August 1, 2023A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted…
14CVE-2023-2834198.70%99.92%April 11, 2023Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorre…
15CVE-2023-3864698.68%99.92%July 21, 2023Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server’s privilege level. Authentic…
16CVE-2025-412398.36%99.91%May 22, 2025A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha…
17CVE-2023-2908498.17%99.91%April 13, 2023Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
18CVE-2023-655397.85%99.90%December 15, 2023The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to…
19CVE-2023-031597.65%99.90%January 16, 2023Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
20CVE-2024-1091497.43%99.89%November 6, 2024A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_us…
21CVE-2023-294896.73%99.88%May 28, 2023Cross-site Scripting (XSS) – Generic in GitHub repository openemr/openemr prior to 7.0.1.
22CVE-2023-3570896.68%99.88%June 16, 2023In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identif…
23CVE-2023-244296.06%99.87%June 7, 2023An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge req…
24CVE-2023-5146796.00%99.87%December 26, 2023The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
25CVE-2023-029795.84%99.87%January 14, 2023Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

Frequently Asked Questions

What is EPSS?

The Exploit Prediction Scoring System (EPSS), published by FIRST, estimates the probability that a given CVE will be exploited in the wild within the next 30 days. It is a forecast, updated daily, and it is scored from 0 to 1. It is not a severity score: CVSS says how bad a flaw would be if exploited, EPSS says how likely exploitation is.

Does EPSS actually predict which vulnerabilities get exploited?

Partly. As of August 2026 we measured the EPSS forecast from the day before each CISA KEV listing across 1376 confirmed-exploited CVEs. 43.5% were in the top 10% of EPSS risk on the eve of confirmation; 56.5% were not. Only 23% carried a raw probability above 50%, and the median forecast was 4.3%.

Why measure the EPSS score from the day before, not today?

Because EPSS reacts to the KEV listing itself. Once CISA confirms exploitation, the score for that CVE rises — comparing today’s score against today’s KEV membership measures nothing. The only honest question is what the forecast said before the confirmation existed, which is what this dataset records.

Should I use EPSS to prioritise patching?

EPSS is useful for deprioritising: a low score on a CVE with no confirmed exploitation is a reasonable reason to wait. It is much weaker as a guarantee, because 56.5% of the vulnerabilities that were later confirmed as actively exploited sat outside its top decile the day before. The practical combination is EPSS for ordering the queue and the CISA KEV catalog for the entries that jump it.

How many CVEs does EPSS score?

358,265 CVEs carried an EPSS score on August 12, 2026, of which 3,587 sit in the top 1% by percentile. Only 815 of those top-1% CVEs are in the CISA KEV catalog — the rest are forecasts that have not been confirmed.

How often is this analysis updated?

Daily. Our automated tracking framework re-reads the EPSS feed and the CISA KEV catalog every day. The eve-of-listing score for each KEV entry is measured once from the FIRST API and never changes afterwards; the watchlist below is recomputed from the current day’s EPSS file.

Can I cite this dataset?

Yes — free to use and cite under CC BY 4.0 with attribution to CVEDaily (cvedaily.io/epss/).

Methodology

For every entry in the CISA KEV catalog we take the date CISA added it and query the FIRST EPSS API for that CVE’s score on the previous day — the last forecast published before the confirmation existed. Where EPSS did not publish on that date (its archive has occasional gaps), we step backwards one day at a time, never forwards: moving toward the listing date would contaminate the measurement with information published after CISA acted. Entries whose CVE had no EPSS score at all on that date are recorded as measured-without-data and excluded from the percentages, not silently dropped — they are reported above as their own figure.

Each eve-of-listing score is measured once and never revised. The current-day scores, the watchlist and the universe totals come from the daily EPSS score file and are recomputed every day. Nothing on this page is estimated or taken from a third-party summary: the figures come from FIRST, CISA and NVD records directly. This is an observational measurement of one forecast against one confirmation source, not a controlled evaluation of the EPSS model — CISA’s catalog is itself an incomplete record of real-world exploitation, and a CVE missing from it is not proof that nobody exploited it.

This dataset is free to cite with attribution to CVEDaily (CC BY 4.0).