Fix the vulnerabilities attackers actually use, first.

Rank Kubernetes vulnerabilities with CISA's Known Exploited Vulnerabilities catalogue and FIRST's EPSS score. Fix KEV-listed CVEs first, then high EPSS scores, then whatever is exposed, and let CVSS break the ties.

CISA KEV tells you a vulnerability is already being exploited in the wild. FIRST EPSS estimates how likely exploitation is in the next 30 days. Together they turn a scanner report full of CVEs into a short list your team can actually finish.

CVSS still matters, because it says how bad a flaw could be. It says nothing about whether anyone is using it, so a list sorted by severity alone puts rarely exploited CVEs right next to the few that attackers are using today.

Four signals, four questions

Each signal answers something different. Good prioritisation uses all of them in a fixed order.

CVSS asks how bad it could be

The Common Vulnerability Scoring System rates the technical severity of a flaw from 0 to 10. A critical score describes the worst case, not how likely anyone is to try it.

CISA KEV asks if it is exploited now

CISA's Known Exploited Vulnerabilities catalogue lists CVEs with confirmed exploitation in the wild, with the date each was added, a remediation deadline for US federal agencies and whether ransomware campaigns use it. CISA says organisations should use it as an input to their prioritisation.

FIRST EPSS asks how likely it is soon

The Exploit Prediction Scoring System estimates the probability that a published CVE is exploited in the wild in the next 30 days. FIRST publishes a score from 0 to 1, with a percentile, every day for every CVE.

Exposure asks if an attacker can reach it

Whether the vulnerable package runs at all, in which workloads, and whether those workloads accept traffic from outside or sit behind tight network policies. No public feed knows this part. Your cluster does.

How Ankra does it

The findings list opens
with what is being exploited.

Ankra's Security Center reads Trivy Operator's reports from your clusters and joins every CVE id with the KEV catalogue and EPSS on the platform. No image data leaves your cluster, Trivy Operator needs no extra configuration, and both feeds refresh every six hours.

Findings are sorted by exploitability by default, KEV listing first, then EPSS, then severity. A KEV-listed finding shows CISA's remediation deadline, turns red once that deadline has passed, and carries a ransomware marker where CISA reports one. The detail view quotes CISA's required action.

ankra cli
# fleet totals and the exploited-in-the-wild summary
ankra security overview

# only findings CISA lists as exploited, deadline first
ankra security findings --known-exploited

# CISA's entry, deadline and required action for one finding
ankra security finding <id>
Sorted by KEV, then EPSS, then severity

An exploited-in-the-wild banner

When CISA lists any of your actionable findings, the Overview, the Findings page and each cluster's Security tab open with a banner counting them, including those past CISA's deadline and those linked to ransomware.

Remediation ranked by exploitation

Remediation candidates on the Overview rank known-exploited CVEs first, ahead of CVSS severity, with CISA's deadline beside each one.

Alerts on new KEV listings

Alert on known-exploited findings per cluster, or on known-exploited CVEs that are new since the previous scan. The built-in new severe CVE notification flags KEV listings of any severity.

Find the package fast

With bills of materials switched on, the SBOM tab answers where you run a package when a new CVE lands. Each image lists its CVEs with the fixed version, the KEV listing and EPSS.

Network exposure

The Network Exposure tab scores how tightly NetworkPolicies scope your workloads and lists every workload with no policy at all, a useful second filter once you know what is vulnerable.

Decisions that expire

Accepting a risk takes a written reason and a review date, and the decision can expire on its own the moment a fixed version is available.

Step by step

A prioritisation order that works

Work down the list in this order. Each step shrinks what is left for the next one.

  1. 1

    Fix KEV-listed findings first

    A KEV listing means attackers already use the flaw. Start with entries past CISA's deadline and those linked to ransomware, then upgrade or patch the image.

    ankra security findings --known-exploited
  2. 2

    Then rank the rest by EPSS

    Among findings not on KEV, a high EPSS probability or a top percentile marks the CVEs most likely to be exploited soon. Pick a threshold your team can actually clear, and remember that scores change daily.

  3. 3

    Weigh exposure and reachability

    A vulnerable package in an internet-facing workload with no NetworkPolicy outranks the same package in an internal job behind default deny. Check that the package is in a running container at all.

  4. 4

    Let CVSS break the ties

    Severity is still the right tie-breaker between findings with similar exploitation signals, and it is the language most security policies are written in.

  5. 5

    Write down what you will not fix yet

    Accept the risk with a reason and a review date, so the decision comes back for review instead of hiding the finding forever.

    ankra security dispositions create --occurrence <id> \
      --disposition accepted_risk --reason "<why>" \
      --expire-when-fix-available

CVSS, KEV, EPSS and exposure side by side

None of them is enough on its own. Used in order, they give you a list you can finish.

What it answersHow often it changesHow to use it
CVSSHow severe the flaw is in the worst case, from 0 to 10When a score is published or reanalysedBreak ties, and meet policies written in severity
CISA KEVWhether exploitation in the wild is confirmedWhenever CISA adds an entryFix first, starting with entries past their deadline
FIRST EPSSThe probability of exploitation in the next 30 daysDaily, for every published CVERank everything that is not on KEV
ExposureWhether an attacker can reach the vulnerable workloadAs your workloads and network policies changeMove reachable findings up and walled-off ones down
Know before you start

What KEV and EPSS do not tell you

Both are strong signals, and both have gaps worth knowing before you build a policy on them.

  • KEV lists only exploitation CISA has confirmed. A CVE missing from it is not proven safe, and CISA invites nominations for exploited vulnerabilities it has missed.
  • EPSS is a probability, not a verdict. Read it as it changes rather than once, because a score can move when new exploitation activity appears.
  • Neither feed knows your environment. Whether the package runs, and whether anyone can reach it, is still your call.
  • Both feeds score CVEs. Benchmark failures and broad network policies need their own review.
  • In Ankra a newly found CVE gets its KEV status straight away and its EPSS score after the next refresh, which runs every six hours.
  • Ankra ranks what Trivy Operator reports. A container the scanner has no report for is marked Not scanned, never shown as clean.

Where the data comes from

The Known Exploited Vulnerabilities catalogue is maintained by CISA, the US Cybersecurity and Infrastructure Security Agency, as the authoritative source of vulnerabilities exploited in the wild. The Exploit Prediction Scoring System is run by FIRST, the Forum of Incident Response and Security Teams.

Ankra stores the whole KEV catalogue and the daily EPSS scores, and matches them by CVE id against the findings Trivy Operator already reported in your clusters. The same fields are on the API, the CLI and the MCP server, so you can pull them into your own reporting. The cluster security guide documents every field.

Questions teams actually ask

What is the difference between KEV and EPSS?+

CISA KEV is a catalogue of vulnerabilities with confirmed exploitation in the wild. FIRST EPSS is a daily probability, from 0 to 1, that a CVE will be exploited in the next 30 days. KEV tells you what is happening now, and EPSS estimates what is likely next.

Should I patch every critical CVSS vulnerability first?+

Not by default. CVSS measures how severe a flaw could be, not whether anyone exploits it. Fix KEV-listed findings first, then high EPSS scores, then weigh how exposed each workload is, and use CVSS to break ties.

How often do KEV and EPSS change?+

FIRST publishes new EPSS scores every day for every CVE, and CISA adds KEV entries as exploitation is confirmed. Ankra refreshes both feeds every six hours.

How does Ankra use KEV and EPSS?+

The Security Center sorts findings by exploitability, KEV listing first, then EPSS, then severity. KEV-listed findings show CISA's deadline, ransomware use and required action, and you can filter, alert and report on them across every cluster.

Do my container images leave the cluster for this?+

No. Ankra matches the feeds by CVE id against the findings Trivy Operator already reported, so no image data leaves your cluster and the operator needs no extra configuration.

Free tier available

See your exploited findings first

Import a cluster, add Trivy Operator as an add-on, and the Findings list opens ranked by KEV and EPSS. 30 worker vCPUs included and no credit card for the free tier.

CISA KEV and FIRST EPSS are public data sources maintained by CISA and FIRST, who are not affiliated with Ankra. Descriptions were checked against cisa.gov and first.org on 10 October 2026.