---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Understanding the Exploit Prediction Scoring System (EPSS) integration

# Understanding the Exploit Prediction Scoring System (EPSS) integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Understanding the Exploit Prediction Scoring System (EPSS) integration

The Exploit Prediction Scoring System (EPSS) integration enhances the Vulnerability Response module by importing data on common vulnerabilities and exposures (CVEs) from First.org.
This integration helps prioritize and remediate vulnerabilities based on the likelihood of exploitation in the wild, providing a score between 0 and 1 (or 0% to 100%).
A higher score indicates a greater probability of exploitation.
Show full answer Show less  

## Key Features

* The integration enriches existing NVD data in your instance and creates placeholders for missing NVD records.
* Initial EPSS data import is necessary before integrating vulnerability data from third-party scanners.
* Configured run-as user for integration records is set to VR.System, which should not be altered.
* Daily updates from the integration record are default; configure for scheduled jobs if needed.
* EPSS integration is included in the base system and is active by default, ensuring automatic synchronization with vulnerability management systems.
* New fields---EPSS Score, EPSS Percentile, and EPSS Last Modified---are added to the Vulnerability Entries table upon activation.

## Key Outcomes

After the initial data import, existing CVEs will auto-update with EPSS details. New CVEs added post-initial job will source their data from EPSS. The integration supports the overall vulnerability remediation lifecycle by keeping your instance synchronized with external systems, ultimately enhancing your organization's security posture.  
Overview of the EPSS integration with Vulnerability Response.

## Request apps on the Store {#epss-vr-integration-overview__section_wlq_1kz_thb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#epss-vr-integration-overview__inline-send-to-store}

## Overview {#epss-vr-integration-overview__section_mbh_nsq_fyb}

The Exploit Prediction Scoring System (EPSS) integration imports EPSS data related to common vulnerabilities and exposures (CVEs) from First.org to prioritize and remediate vulnerabilities. For more information see, <https://www.first.org>. The Exploit Prediction Scoring System (EPSS) is a data-driven effort for estimating the likelihood (probability) that a software vulnerability will be exploited in the wild. The EPSS model produces a
probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

Data imports from the EPSS integration, further enrich the NVD data in your instance. If NVD records are not present, then it will create a placeholder in the CVE table and add EPSS details in the same table. Run this integration as
part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.  
Important:  
There is a configured run-as user for each integration record. The default value for this user is VR.System. Do not change this value.

## Initial import of data with the EPSS integration {#epss-vr-integration-overview__section_akw_rvq_fyb}

1. Perform an initial import of EPSS data with the First.org EPSS Integration. For more information, see [Configure and run a scheduled job to update CVE records with EPSS data](https://servicenow-prod.fluidtopics.net/wA8UmlFgLVIH7u5fT2mpTg "Customize the base system scheduled job to update CVE records with EPSS data.").  
   Important:  
   You perform EPSS updates Daily from the integration record by default, and you must configure it if you want it to run as a scheduled job.
2. Third-party libraries are updated as scheduled jobs. For more information, see [Importing data with the NVD and CWE integrations and managing third-party libraries](https://servicenow-prod.fluidtopics.net/SDp7vDWErXHrLtUOsZ_~qw "If not already installed, download and run the NVD integration and run the CWE scheduled job as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. The Vulnerability Response Integration with NVD is available on the ServiceNow Store.").  
   Important:  
   It is recommended to perform NIST National Vulnerability Database Integration - API (CVE only) integrations before EPSS.

{#epss-vr-integration-overview__ol_lrs_vvq_fyb}Perform the EPSS imports prior to importing vulnerability data with a third-party product. Third-party libraries are updated as scheduled jobs. Refer to your integration documentation at Vulnerability Response integrations for more information about third-party integrations.  
Important:  
The following integration is included in the base system. The integration is active by default.

After the initial run, base system scheduled jobs run the integrations automatically in order. You can also execute individual scheduled jobs manually. Scheduled jobs simplify the vulnerability remediation life cycle by keeping the
instance synchronized with other vulnerability management systems.

On activation of the EPSS integration, the EPSS Score, EPSS Percentile, and EPSS Last Modified fields are added to the Vulnerability Entries table. For existing CVEs these fields are auto-updated on successful completion of the
initial import job. If there are new CVEs that are added to the Vulnerability Entries table after the completion of the EPSS scheduled job, the newly added CVEs will indicate their source as EPSS. The scores are rolled up to
existing TPEs from CVEs from the NVD table, using the base system Rollup EPSS score from NVD to TPEs calculator. You can also modify the calculator. For more information, see [Vulnerability Response Rollup Calculators](https://servicenow-prod.fluidtopics.net/01npMHRqJbc0QbxhB1PZEA "After your initial assessment of risk calculators in the Setup Assistant, use the vulnerability rollup calculators to configure how the cumulative risk score is computed for remediation tasks and imported vulnerabilities.").
**Related tasks**   

* [Create a Vulnerability Response calculator](https://servicenow-prod.fluidtopics.net/t3SSJgFp0qXo2xTC51RWwg "A vulnerability calculator is a pre-defined formula to calculate a target field when certain criteria are met. Calculators, which calculate the vulnerable item Risk Score, can contain Risk Rules.")

