Predicting which new CVEs get exploited
A public, running test of Vulnerability Prioritisation v1 (VPv1). Every morning it scores the CVEs published in the previous 24 hours and names the ones it expects to be exploited within 90 days. Each day’s list is published here as it stands and never edited afterwards, so the predictions can be checked against what actually happens.
What VPv1 is
More than 72,000 CVEs have been published so far in 2026, and well under 1% of them are ever exploited. Nobody can patch everything at once, so the useful question on the day a CVE comes out is which ones to deal with first.
VPv1 answers that question. It looks at each new CVE using only information that is public on the day it is scored and ranks every CVE. The top 10% of that ranking forms the priority class, the CVEs it expects are most likely to be exploited within 90 days. Each priority CVE is also marked by how high it ranks: top 2%, top 5% or top 10%.
CVEs that are already known to be exploited when they are published, such as a vendor disclosing a zero-day that is under active attack, are left out. There is nothing to predict for those, and counting them would make the results look better than they are.
How well it performed in testing
VPv1 was tested on CVEs published between 17 March 2025 and 31 May 2026, the period in which EPSS v4 was the current version of EPSS. Each CVE was scored using only what was public on the day after it was published, and the model never saw outcomes from later than the point it was scoring. Zero-days already exploited at disclosure are excluded from both sides.
The table shows how many CVEs a team would need to review each year to catch a given share of the CVEs exploited within 90 days.
| Share of exploited CVEs caught | 50% | 70% | 80% | 90% |
|---|---|---|---|---|
| EPSS v4 | 3,554 | 13,583 | 19,586 | 35,059 |
| VPv1 | 569 | 1,702 | 2,874 | 6,712 |
| Difference | 2,985 fewer (6×) | 11,881 fewer (8×) | 16,712 fewer (7×) | 28,347 fewer (5×) |
CVEs reviewed per year, annualised from 17 March 2025 to 31 May 2026 (about 56,500 CVEs and 93 exploited within 90 days a year).
The priority class is the top 10% of VPv1’s ranking, split into three bands so a team can work down it in order:
| Band | CVEs per year | Per day | Exploited CVEs caught | EPSS v4, same number of CVEs | EPSS v4 CVEs needed for the same catch |
|---|---|---|---|---|---|
| Top 2% | 1,130 | 3.1 | 63% | 31% | 7,509 |
| Top 5% | 2,825 | 7.7 | 79% | 45% | 19,292 |
| Top 10% | 5,650 | 15.5 | 87% | 55% | 30,233 |
Each band includes the ones above it. Backtest, 17 March 2025 to 31 May 2026, zero-days already exploited at disclosure excluded.
Those are backtest results, worked out after the fact on historical data. The live test below is the real check.
How the live test works
- Every morning between 8am and 9am AWST, VPv1 scores every CVE published to the CVE List in the previous 24 hours.
- Every CVE scored since the start of the test is scored again with whatever has become public since. A CVE can join the priority class days after it was published if new information appears, such as public exploit code or exploitation of another flaw in the same product.
- A CVE joins the priority class when its score ranks in the top 10%, and is marked top 2%, top 5% or top 10%. The cut-offs are set each day from data available that morning, not from later results. If new information moves a CVE into a higher band, the move is recorded on the day it happens.
- Each day’s results are published as a separate dated file and are never changed afterwards. Each file records a SHA-256 fingerprint of the previous day’s file, so editing any earlier day would break the chain.
- The page and each daily file are captured by the Internet Archive’s Wayback Machine, which gives an independent record of what was predicted and when.
How it is scored
A CVE counts as exploited on the earliest of two dates: the first credible public report of exploitation in the wild, or its addition to the CISA KEV catalog. Credible reports are vendor advisories, government advisories and named security research or incident reporting, the same standard used for the rest of this site.
A prediction only counts if the CVE was in the priority class before its exploitation became public. Joining the class after the news broke earns nothing. When a CVE joins the class on the same day its exploitation becomes public, the time of day decides. The CVE joined at the time of that morning’s run, which is shown in each daily file. A report or KEV listing whose time is not known counts from the start of its day (00:00 UTC), so an unknown time never favours VPv1.
Reports of exploitation are searched for every day across every CVE in the test, not just the flagged ones, so neither VPv1 nor EPSS is checked more closely than the other. Each exploited CVE below links to the report its date comes from.
Each CVE in the priority class carries one of four statuses:
- Open: published less than 90 days ago, with no public exploitation yet.
- Exploited within 90 days: exploitation became public within 90 days of publication.
- Not exploited within 90 days: 90 days passed with no public exploitation.
- Exploited after 90 days: exploitation became public later than 90 days after publication.
A CVE later found to have been exploited on or before the day it was published is marked Excluded and left out of every result, because there was nothing to predict.
The results are reported in four ways:
- Coverage: the share of all CVEs exploited within 90 days that were in the priority class before exploitation became public.
- Hit rate: the share of priority CVEs that were exploited within 90 days.
- CVEs reviewed per exploit caught: how many CVEs a team working through the priority class reviewed for each exploited CVE it caught in time.
- Head-to-head with EPSS: each day, the same number of CVEs is taken from the top of that day’s EPSS scores for the same pool of CVEs, and scored the same way. EPSS released version 5 in 2026, so the live comparison is against EPSS v5, the version published each day. The model version is recorded in every daily file.
Results for a CVE become final 90 days after it is published, so the first complete numbers arrive about three months after the test starts. Until then the figures above count what has happened so far.
Results so far
VPv1 against EPSS v5 on the same CVEs and the same number of picks. “CVEs in both” counts the CVEs that both lists picked. The numbers keep changing until each CVE’s 90 days are up.
| CVEs flagged | CVEs in both | % CVEs in both | Exploits caught in time | Coverage | Hit rate | CVEs reviewed per exploit caught | |
|---|---|---|---|---|---|---|---|
| Loading… | |||||||
Exploited CVEs so far
Every CVE in the test whose exploitation in the wild has become public, whether or not it was flagged. A flag only counts if it came before the first public report or KEV listing. Times are UTC.
| CVE | Vendor | Product | Published | Exploitation public | CISA KEV | VPv1 | EPSS v5 |
|---|---|---|---|---|---|---|---|
| Loading… | |||||||
The priority list
Grouped by the day each CVE joined the priority class, newest first.
Loading…
Daily files
Every run, as published. Each file contains the SHA-256 of the one before it.
| Run date | CVEs published | Joined priority | File | SHA-256 |
|---|---|---|---|---|
| Loading… | ||||