Ethiack Docs

CISA KEV and EPSS

What are CISA KEV and EPSS and how they are integrated in the findings

When reviewing findings in Ethiack, two risk indicators are shown alongside each vulnerability to help you assess threat level and prioritise remediation: KEV and EPSS.

Known Exploited Vulnerabilities (KEV)

The KEV catalogue is maintained by CISA (Cybersecurity and Infrastructure Security Agency) and identifies vulnerabilities with confirmed exploitation in real-world attacks. When a finding is listed in the KEV catalogue, it means there is documented evidence of it being actively used by threat actors — making it a proven threat that warrants urgent attention.

Visual indicators

IconMeaning
The vulnerability appears in the CISA KEV catalogue and requires immediate remediation.
Not currently listed in the KEV catalogue. Note that absence from the catalogue does not guarantee the vulnerability is safe.

Exploit Prediction Scoring System (EPSS)

EPSS projects the likelihood that a vulnerability will be exploited within the next 30 days, expressed as a percentage. It is designed to help security teams sequence their remediation efforts based on predicted exploitation risk rather than severity alone.

Risk categories

Score rangeIndicatorMeaning
< 3%Low risk of near-term exploitation.
3–10%Moderate exploitation probability — monitor closely.
> 10%High exploitation probability — prioritise remediation.
N/ANo score available; either a non-vulnerability finding or the EPSS assessment is pending.

Using KEV and EPSS together

KEV and EPSS complement each other: KEV tells you what is already being exploited, while EPSS tells you what is likely to be exploited soon. Combining both signals gives you a clearer picture of where to focus your remediation efforts — a finding that is both KEV-listed and has a high EPSS score should be treated as the highest priority.

On this page