Evaluating Vulnerability Prioritization Strategies Based on CVSS and EPSS

  • Felipe Curty do Rego Pinto BNDES

Resumo


The number of disclosed vulnerabilities should surpass 50,000 in 2026, making prioritization essential for allocating scarce remediation capacity to the vulnerabilities that most require attention. This paper empirically evaluates CVSS-based, EPSS-based, and combined CVSS+EPSS vulnerability prioritization strategies in terms of effectiveness and remediation effort, providing guidance on how to select among them. We built a corpus of 31, 779 vulnerabilities disclosed in 2024 from the National Vulnerability Database and used the CISA Known Exploited Vulnerabilities (KEV) catalog as ground truth to identify the vulnerabilities that warrant prioritization. Our results show that CVSS-based strategies provide broader coverage but produce substantially larger prioritized sets, whereas EPSS-based strategies are more selective and concentrate a higher share of known-exploited vulnerabilities in the prioritized set. Combined strategies based on OR conditions can provide balanced trade-offs by increasing coverage with a modest increase in remediation effort, while AND combinations offer limited advantage over EPSS alone. Finally, our results provide evidence to enable organizations to choose the best prioritization strategy considering their remediation capacity and tolerance for missing relevant vulnerabilities.

Referências

Allodi, L. and Massacci, F. (2014). Comparing Vulnerability Severity and Exploits Using Case-Control Studies. ACM Trans. Inf. Syst. Secur., 17(1):1:1–1:20.

Alomar, N., Wijesekera, P., Qiu, E., and Egelman, S. (2020). ”You’ve Got Your Nice List of Bugs, Now What?” Vulnerability Discovery and Management Processes in the Wild. pages 319–339.

Bozorgi, M., Saul, L. K., Savage, S., and Voelker, G. M. (2010). Beyond heuristics: learning to classify vulnerabilities and predict exploits. In Proceedings of the 16th ACM SIGKDD international conference on Knowledge discovery and data mining, KDD ’10, pages 105–114, New York, NY, USA. Association for Computing Machinery.

De Smale, S., Van Dijk, R., Bouwman, X., Van Der Ham, J., and Van Eeten, M. (2023). No one drinks from the firehose: How organizations filter and prioritize vulnerability information. In 2023 IEEE symposium on security and privacy (SP), pages 1980–1996. IEEE.

Elder, S., Rahman, M. R., Fringer, G., Kapoor, K., and Williams, L. (2024). A Survey on Software Vulnerability Exploitability Assessment. ACM Comput. Surv., 56(8):205:1–205:41.

FIRST (2024a). CVSS v4.0 Specification - 2024-06-18. Technical report.

FIRST (2024b). The EPSS Model.

FIRST (2026). FIRST Releases 2026 Vulnerability Report, Projecting Record-Breaking Common Vulnerabilities and Exposures.

Howland, H. (2022). CVSS: Ubiquitous and Broken. Digital Threats, 4(1):1:1–1:12.

Jacobs, J., Romanosky, S., Adjerid, I., and Baker, W. (2020). Improving vulnerability remediation through better exploit prediction. Journal of Cybersecurity, 6(1):tyaa015.

Jacobs, J., Romanosky, S., Edwards, B., Adjerid, I., and Roytman, M. (2021). Exploit Prediction Scoring System (EPSS). Digital Threats, 2(3):20:1–20:17.

Jacobs, J., Romanosky, S., Suciu, O., Edwards, B., and Sarabi, A. (2023). Enhancing Vulnerability Prioritization: Data-Driven Exploit Predictions with Community-Driven Insights. In 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), pages 194–206.

Pinto, F. C. d. R. (2024). O Impacto da Análise de Ameaças Cibernéticas na Classificação e Tratamento de Vulnerabilidades. Trabalho de Conclusão do Curso Superior de Segurança de Defesa Cibernética (CSSDC), Escola Superior de Guerra (ESG), Brasil.

Sabottke, C., Suciu, O., and Dumitraş, T. (2015). Vulnerability Disclosure in the Age of Social Media: Exploiting Twitter for Predicting Real-World Exploits. In Proceedings of the 24th USENIX Security Symposium.

Scarfone, K. and Mell, P. (2009). An analysis of CVSS version 2 vulnerability scoring. In 2009 3rd International Symposium on Empirical Software Engineering and Measurement, pages 516–525.

Sharma, R., Sibal, R., and Sabharwal, S. (2021). Software vulnerability prioritization using vulnerability description. International Journal of System Assurance Engineering and Management, 12(1):58–64.

Shimizu, N. and Hashimoto, M. (2026). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. IEEE Access, 14:31407–31424.

Spring, J., Hatleback, E., Householder, A., Manion, A., and Shick, D. (2021). Time to Change the CVSS? IEEE Security & Privacy, 19(2):74–78. Conference Name: IEEE Security & Privacy.

Wohlin, C. (2014). Guidelines for snowballing in systematic literature studies and a replication in software engineering. In Proceedings of the 18th international conference on evaluation and assessment in software engineering, pages 1–10.
Publicado
01/09/2026
PINTO, Felipe Curty do Rego. Evaluating Vulnerability Prioritization Strategies Based on CVSS and EPSS. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 613-627. DOI: https://doi.org/10.5753/sbseg.2026.26967.