Back to all articles

How to correlate threat intelligence with vulnerability data

Learn how to correlate threat intelligence with vulnerability data using EPSS, CISA KEV, and CVSS in 2026 — plus the priority order that actually works.

BRContent TeamAug 30, 2026 — 8 min read
How to correlate threat intelligence with vulnerability data

Correlating threat intelligence with vulnerability data means matching every CVE in your scanner feeds against real-world exploitation signals — EPSS scores, the CISA Known Exploited Vulnerabilities (KEV) catalog, and CVSS severity — so remediation teams in 2026 patch what attackers are actually using, not just what scored highest on a severity chart. The hidden cost most teams miss: a CVE with a 9.8 CVSS score but 0% EPSS probability routinely sits lower on the priority list than a 6.1 CVSS CVE carrying an EPSS score above 50% and a CISA KEV listing.

TL;DR
  • Correlating threat intelligence with vulnerability data means layering EPSS, CISA KEV, and CVSS on top of raw scan results, not scoring CVEs in isolation.
  • A CVE scoring 9.8 CVSS but 0% EPSS often waits behind a 6.1 CVSS CVE flagged in CISA KEV in 2026.
  • EPSS updates daily and predicts a 0-100% probability of exploitation within 30 days — CVSS never changes once published.
  • Federal civilian agencies must remediate CISA KEV vulnerabilities within roughly 2 weeks to 6 months under BOD 22-01.

Why this matters

A mid-size environment running four or five scanners across network, cloud, container, and application layers can produce thousands of open CVEs a month. Severity alone — the CVSS 0.0 to 10.0 scale — doesn't tell you which of those CVEs an attacker is actually going after in 2026. Correlating that raw list against threat intelligence feeds is how security teams cut the list down to the handful that matter this week, and it's the step most vulnerability programs skip because it means consolidating vulnerability data from multiple scanners before any scoring can happen.

Skip that step and you get two failure modes: patch teams burning cycles on high-CVSS CVEs nobody is exploiting, or a KEV-listed CVE with a mid-range CVSS score sitting unpatched for months because it never made the top-10 severity report.

How do you correlate threat intelligence with vulnerability data?

Correlating threat intelligence with vulnerability data follows a repeatable sequence, not a one-time export:

  1. Pull raw CVE data from every scanner — network, cloud, container, and application security testing tools all report CVEs differently, so normalize them into one asset-and-CVE inventory first.
  2. Attach an EPSS score to each CVE. EPSS (Exploit Prediction Scoring System), published daily by FIRST.org, gives a 0-100% probability that a CVE will be exploited in the wild within 30 days.
  3. Cross-reference against the CISA KEV catalog. This is a binary flag — a CVE is either confirmed exploited and in the catalog, or it isn't.
  4. Layer CVSS as severity context, not the primary sort key. A CVSS score tells you theoretical impact; it doesn't tell you exploitation likelihood.
  5. Add asset context — internet-facing exposure, crown-jewel data, or compliance scope — to weight the final priority number.

Here's what each method sees and misses on its own:

MethodWhat it measuresBlind spot
CVSS onlyTheoretical severity, 0.0-10.0 scaleIgnores real-world exploitation entirely
EPSS onlyProbability of exploitation in 30 days, 0-100%Ignores asset exposure and business context
CISA KEV onlyConfirmed active exploitationCovers only catalogued CVEs, not emerging ones
Correlated (CVSS + EPSS + KEV + asset context)Attacker-relevant risk to your actual environmentRequires scanner data consolidated first

Verdict: correlating CVSS, EPSS, and CISA KEV against asset context is the only method of the four that reliably predicts what to patch first in 2026 — any single score used alone leaves a measurable blind spot.

EPSS scoring: exploitation probability from 0% to 100%

EPSS is maintained by FIRST.org and refreshes daily, unlike CVSS which is set once at CVE publication. A score of 10% or higher, especially paired with internet-facing exposure, is treated by most security teams as a signal worth escalating regardless of the CVSS number attached. Teams building this into a repeatable process usually start with a dedicated framework for prioritizing vulnerabilities with EPSS scoring rather than pulling the feed manually every week.

Pros: updates daily, quantifies exploitation likelihood, works across any CVE regardless of vendor. Cons: it's a probability model, not a guarantee — a low EPSS score doesn't mean a CVE is safe to ignore forever, only that it isn't currently trending.

CISA KEV: the binary exploited-in-the-wild flag

The CISA Known Exploited Vulnerabilities catalog lists CVEs with confirmed evidence of active exploitation. Under Binding Operational Directive 22-01, federal civilian executive branch agencies work against fixed remediation windows for KEV entries — typically around 2 weeks for newly catalogued critical items and up to 6 months for older ones. Outside federal environments, most security teams still treat KEV membership as an automatic escalation trigger, independent of the CVE's CVSS score.

Pros: confirmed exploitation, not prediction — near-zero false positives. Cons: CISA adds entries only after exploitation is confirmed, so KEV membership is always a lagging indicator, never an early warning.

CVSS severity: context, not a priority queue

CVSS scores run from 0.0 to 10.0 and describe theoretical impact and exploitability as scored by the vendor or NVD at publication. It's useful for setting a baseline severity floor, but 2026 exploitation data keeps confirming what researchers have flagged for years: plenty of 9-plus CVSS CVEs sit unexploited indefinitely while mid-range CVSS CVEs get weaponized within days of disclosure.

Pros: standardized, universally reported, easy to compare across vendors. Cons: static once published, and it carries no signal about real-world attacker behavior.

See correlated risk scoring in action

Brinqa layers EPSS, KEV, and CVSS across every scanner feed automatically.

Why correlation scores vary

Two security teams running the same scanners can end up with different final priority scores for the same CVE. The gap usually comes down to a handful of factors:

  • Scanner coverage gaps — a network scanner won't catch a cloud misconfiguration CVE, and vice versa, so the raw CVE count is already incomplete before correlation starts.
  • Asset criticality weighting — an internet-facing server and an isolated internal test box carry the same CVE but very different real risk.
  • EPSS score volatility — because it updates daily, a CVE's EPSS score can move from 2% to 40% overnight as exploit code circulates.
  • CISA KEV catalog lag — entries appear only after confirmed exploitation, so a CVE can be actively exploited for weeks before it shows up in KEV.
  • Duplicate CVE records across scanners — the same CVE reported by three different tools inflates raw counts and skews manual triage.
  • Compliance-driven overrides — CVEs on assets in SOC 2 or HIPAA scope frequently get bumped to the top of the queue regardless of EPSS or CVSS.

Is EPSS better than CVSS for vulnerability prioritization?

EPSS is better for predicting near-term exploitation risk on a 0-100% scale, while CVSS measures theoretical severity on a 0-10 scale — the two answer different questions, so mature programs in 2026 use EPSS to set urgency and CVSS to gauge worst-case impact rather than picking one over the other.

Does CISA KEV replace the need for EPSS or CVSS scoring?

No, CISA KEV only flags CVEs with confirmed real-world exploitation, which means it says nothing about the thousands of CVEs that haven't been weaponized yet — EPSS fills that predictive gap, and CVSS still sets the severity baseline underneath both.

How often should threat intelligence be re-correlated against vulnerability data?

Daily is the practical minimum in 2026, since EPSS scores refresh daily and CISA adds new KEV entries as exploitation gets confirmed, meaning a CVE that was low priority yesterday can require escalation this morning.

Once the correlation logic is running against a normalized asset inventory, the same layered approach — EPSS, KEV, CVSS, asset context — extends naturally into risk-based prioritization for security operations teams handling high CVE volumes without expanding headcount.

FAQ

What's the best way to correlate threat intelligence with vulnerability data in 2026?

Layer EPSS scores, CISA KEV membership, and CVSS severity on top of normalized scanner output, then weight the result by asset exposure — CVSS alone or EPSS alone leaves a measurable blind spot.

Is EPSS better than CVSS for vulnerability prioritization?

EPSS predicts a 0-100% probability of exploitation in the next 30 days, while CVSS measures theoretical severity on a 0-10 scale — use EPSS to rank urgency and CVSS to gauge impact rather than substituting one for the other.

Does correlating threat intel reduce the vulnerability backlog?

Yes, filtering a raw CVE list by EPSS score and CISA KEV membership typically narrows it down to the small subset attackers are actually targeting, though the exact reduction depends on scanner overlap and asset scope.

Does CISA KEV replace CVSS or EPSS scoring?

No, CISA KEV only flags CVEs with confirmed real-world exploitation, so it says nothing about the CVEs that haven't been weaponized yet, which is where EPSS and CVSS still matter.

How often should vulnerability data be re-correlated with threat intelligence?

Daily, since EPSS scores update daily and CISA adds new KEV entries as exploitation gets confirmed, so a CVE's priority can shift overnight.

What's a good EPSS score threshold for prioritization?

Many teams treat any CVE above 10% EPSS combined with internet-facing asset exposure as a priority-patch candidate, adjusting the threshold down for crown-jewel systems.

Can you correlate threat intelligence across multiple vulnerability scanners?

Yes, but only after consolidating CVE data from each scanner into one normalized asset inventory, since duplicate records across tools will otherwise skew the correlation.

Is CVSS score alone enough to prioritize patching?

No, CVSS measures theoretical severity, not real-world exploitation, so a 9.8 CVSS CVE with 0% EPSS probability can safely wait behind a lower-severity CVE already confirmed in the CISA KEV catalog.

One last thing

Published research from Cyentia Institute and Kenna Security has repeatedly found weak correlation between CVSS severity alone and confirmed real-world exploitation, which is exactly why the EPSS model and the CISA KEV catalog exist as separate signals in the first place. Treat CVSS as your severity floor in 2026, not your priority queue, and the CVE list your team works from next week will look nothing like the one sorted by severity score alone.

You might also like