Vulnerability prioritisation guide
Fix the vulnerabilities attackers actually use, first.
Rank Kubernetes vulnerabilities with CISA's Known Exploited Vulnerabilities catalogue and FIRST's EPSS score. Fix KEV-listed CVEs first, then high EPSS scores, then whatever is exposed, and let CVSS break the ties.
CISA KEV tells you a vulnerability is already being exploited in the wild. FIRST EPSS estimates how likely exploitation is in the next 30 days. Together they turn a scanner report full of CVEs into a short list your team can actually finish.
CVSS still matters, because it says how bad a flaw could be. It says nothing about whether anyone is using it, so a list sorted by severity alone puts rarely exploited CVEs right next to the few that attackers are using today.
Four signals, four questions
Each signal answers something different. Good prioritisation uses all of them in a fixed order.
CVSS asks how bad it could be
The Common Vulnerability Scoring System rates the technical severity of a flaw from 0 to 10. A critical score describes the worst case, not how likely anyone is to try it.
CISA KEV asks if it is exploited now
CISA's Known Exploited Vulnerabilities catalogue lists CVEs with confirmed exploitation in the wild, with the date each was added, a remediation deadline for US federal agencies and whether ransomware campaigns use it. CISA says organisations should use it as an input to their prioritisation.
FIRST EPSS asks how likely it is soon
The Exploit Prediction Scoring System estimates the probability that a published CVE is exploited in the wild in the next 30 days. FIRST publishes a score from 0 to 1, with a percentile, every day for every CVE.
Exposure asks if an attacker can reach it
Whether the vulnerable package runs at all, in which workloads, and whether those workloads accept traffic from outside or sit behind tight network policies. No public feed knows this part. Your cluster does.
The findings list opens
with what is being exploited.
Ankra's Security Center reads Trivy Operator's reports from your clusters and joins every CVE id with the KEV catalogue and EPSS on the platform. No image data leaves your cluster, Trivy Operator needs no extra configuration, and both feeds refresh every six hours.
Findings are sorted by exploitability by default, KEV listing first, then EPSS, then severity. A KEV-listed finding shows CISA's remediation deadline, turns red once that deadline has passed, and carries a ransomware marker where CISA reports one. The detail view quotes CISA's required action.
# fleet totals and the exploited-in-the-wild summary
ankra security overview
# only findings CISA lists as exploited, deadline first
ankra security findings --known-exploited
# CISA's entry, deadline and required action for one finding
ankra security finding <id>An exploited-in-the-wild banner
When CISA lists any of your actionable findings, the Overview, the Findings page and each cluster's Security tab open with a banner counting them, including those past CISA's deadline and those linked to ransomware.
Remediation ranked by exploitation
Remediation candidates on the Overview rank known-exploited CVEs first, ahead of CVSS severity, with CISA's deadline beside each one.
Alerts on new KEV listings
Alert on known-exploited findings per cluster, or on known-exploited CVEs that are new since the previous scan. The built-in new severe CVE notification flags KEV listings of any severity.
Find the package fast
With bills of materials switched on, the SBOM tab answers where you run a package when a new CVE lands. Each image lists its CVEs with the fixed version, the KEV listing and EPSS.
Network exposure
The Network Exposure tab scores how tightly NetworkPolicies scope your workloads and lists every workload with no policy at all, a useful second filter once you know what is vulnerable.
Decisions that expire
Accepting a risk takes a written reason and a review date, and the decision can expire on its own the moment a fixed version is available.
A prioritisation order that works
Work down the list in this order. Each step shrinks what is left for the next one.
- 1
Fix KEV-listed findings first
A KEV listing means attackers already use the flaw. Start with entries past CISA's deadline and those linked to ransomware, then upgrade or patch the image.
ankra security findings --known-exploited - 2
Then rank the rest by EPSS
Among findings not on KEV, a high EPSS probability or a top percentile marks the CVEs most likely to be exploited soon. Pick a threshold your team can actually clear, and remember that scores change daily.
- 3
Weigh exposure and reachability
A vulnerable package in an internet-facing workload with no NetworkPolicy outranks the same package in an internal job behind default deny. Check that the package is in a running container at all.
- 4
Let CVSS break the ties
Severity is still the right tie-breaker between findings with similar exploitation signals, and it is the language most security policies are written in.
- 5
Write down what you will not fix yet
Accept the risk with a reason and a review date, so the decision comes back for review instead of hiding the finding forever.
ankra security dispositions create --occurrence <id> \ --disposition accepted_risk --reason "<why>" \ --expire-when-fix-available
CVSS, KEV, EPSS and exposure side by side
None of them is enough on its own. Used in order, they give you a list you can finish.
| What it answers | How often it changes | How to use it | |
|---|---|---|---|
| CVSS | How severe the flaw is in the worst case, from 0 to 10 | When a score is published or reanalysed | Break ties, and meet policies written in severity |
| CISA KEV | Whether exploitation in the wild is confirmed | Whenever CISA adds an entry | Fix first, starting with entries past their deadline |
| FIRST EPSS | The probability of exploitation in the next 30 days | Daily, for every published CVE | Rank everything that is not on KEV |
| Exposure | Whether an attacker can reach the vulnerable workload | As your workloads and network policies change | Move reachable findings up and walled-off ones down |
What KEV and EPSS do not tell you
Both are strong signals, and both have gaps worth knowing before you build a policy on them.
- KEV lists only exploitation CISA has confirmed. A CVE missing from it is not proven safe, and CISA invites nominations for exploited vulnerabilities it has missed.
- EPSS is a probability, not a verdict. Read it as it changes rather than once, because a score can move when new exploitation activity appears.
- Neither feed knows your environment. Whether the package runs, and whether anyone can reach it, is still your call.
- Both feeds score CVEs. Benchmark failures and broad network policies need their own review.
- In Ankra a newly found CVE gets its KEV status straight away and its EPSS score after the next refresh, which runs every six hours.
- Ankra ranks what Trivy Operator reports. A container the scanner has no report for is marked Not scanned, never shown as clean.
Where the data comes from
The Known Exploited Vulnerabilities catalogue is maintained by CISA, the US Cybersecurity and Infrastructure Security Agency, as the authoritative source of vulnerabilities exploited in the wild. The Exploit Prediction Scoring System is run by FIRST, the Forum of Incident Response and Security Teams.
Ankra stores the whole KEV catalogue and the daily EPSS scores, and matches them by CVE id against the findings Trivy Operator already reported in your clusters. The same fields are on the API, the CLI and the MCP server, so you can pull them into your own reporting. The cluster security guide documents every field.
Guides and comparisons
Questions teams actually ask
What is the difference between KEV and EPSS?+
CISA KEV is a catalogue of vulnerabilities with confirmed exploitation in the wild. FIRST EPSS is a daily probability, from 0 to 1, that a CVE will be exploited in the next 30 days. KEV tells you what is happening now, and EPSS estimates what is likely next.
Should I patch every critical CVSS vulnerability first?+
Not by default. CVSS measures how severe a flaw could be, not whether anyone exploits it. Fix KEV-listed findings first, then high EPSS scores, then weigh how exposed each workload is, and use CVSS to break ties.
How often do KEV and EPSS change?+
FIRST publishes new EPSS scores every day for every CVE, and CISA adds KEV entries as exploitation is confirmed. Ankra refreshes both feeds every six hours.
How does Ankra use KEV and EPSS?+
The Security Center sorts findings by exploitability, KEV listing first, then EPSS, then severity. KEV-listed findings show CISA's deadline, ransomware use and required action, and you can filter, alert and report on them across every cluster.
Do my container images leave the cluster for this?+
No. Ankra matches the feeds by CVE id against the findings Trivy Operator already reported, so no image data leaves your cluster and the operator needs no extra configuration.
See your exploited findings first
Import a cluster, add Trivy Operator as an add-on, and the Findings list opens ranked by KEV and EPSS. 30 worker vCPUs included and no credit card for the free tier.
CISA KEV and FIRST EPSS are public data sources maintained by CISA and FIRST, who are not affiliated with Ankra. Descriptions were checked against cisa.gov and first.org on 10 October 2026.