Rank a vulnerability for patching from EPSS probability, KEV listing, exploit maturity, asset criticality and exposure.
The score deliberately gives the threat side up to 68 points and the asset side up to 35, because whether a vulnerability is being exploited matters more than how bad it would be if it were. KEV listing alone contributes a quarter of the scale: a catalogued CVE has documented in-the-wild use, which no CVSS metric captures. A deployed compensating control buys a 10-point reduction, enough to move a borderline case out of an emergency change but never enough to close it. CVSS ranks the whole world's vulnerabilities identically; this ranks yours, which is the only ordering that makes a finite patching team effective.
Patch Priority
Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100.
Decision bands
Score ≥ 70 Act, ≥ 50 Attend, ≥ 30 Track*, below that Track — the four SSVC stakeholder-specific decision outcomes.
Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100. The score deliberately gives the threat side up to 68 points and the asset side up to 35, because whether a vulnerability is being exploited matters more than how bad it would be if it were. KEV listing alone contributes a quarter of the scale: a catalogued CVE has documented in-the-wild use, which no CVSS metric captures. A deployed compensating control buys a 10-point reduction, enough to move a borderline case out of an emergency change but never enough to close it.
CVSS ranks the whole world's vulnerabilities identically; this ranks yours, which is the only ordering that makes a finite patching team effective.
This calculator takes 7 inputs: EPSS probability (30-day), Listed in CISA KEV, Exploit maturity, Asset criticality tier, Network exposure, Vendor patch available, Compensating control already deployed. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because that is typically half your findings and a small fraction of your actual risk. Roughly a few per cent of published CVEs are ever exploited in the wild, and EPSS plus KEV identify most of them, so prioritising on exploitation evidence reduces breach probability far more per engineer-hour.
The score still tells you the urgency, and the next-step output switches to mitigation. Virtual patching, disabling the feature, tightening the network path or moving the asset behind authentication all buy time; do them at the same SLA the patch would have had.