Methodology

How we rank the entries on CISA's list of exploited vulnerabilities, what each input means, when the pages update and where the data has breaks. Updated .

The rank, method version 1

Only the entries on CISA's list today are ranked. Each falls into one of three groups, and the groups never mix: every entry in Patch now comes before every entry in Patch this week.

  • Patch now: CISA requires forensic triage for it, or listed it in the last 14 days, or knows ransomware campaigns use it and listed it in the last 365 days.
  • Patch this week: any other entry that ransomware campaigns use, that has a Metasploit module, or that has an EPSS score of 0.50 or more.
  • Patch soon: every other entry.

The order inside a group

Inside a group the order is fixed, with no weights to tune: an entry with a Metasploit module comes first; then one with an Exploit-DB entry that Exploit-DB has verified; then the higher EPSS percentile, as shown on the page; then the more recent listing; then the CVE id. So every position can be explained by what its row shows.

A CVE page shows the group and the reasons, not the position: one new listing moves the position of every entry below it. Lists show both.

Why the groups are drawn where they are

Ransomware use is the strongest public sign that a flaw is worth an attacker's time. But with every ransomware entry in the top group, CISA's list of 30 September 2026 put 428 of its 1,730 entries in Patch now, 259 of them listed before 2024: a quarter of the list, and mostly old. Older ransomware entries move to Patch this week, which keeps Patch now short enough to act on (99 entries on that day).

A new listing goes to Patch now for 14 days because the first weeks after CISA's notice are when attacks spread and when agencies' deadlines fall. Forensic triage is CISA's own most urgent tier under BOD 26-04.

The inputs

What each input is and what the rank does with it.
InputSourceIn the rank
Listed as exploited, with its listing date and due dateCISA KEVThe groups, and the newer listing first
Ransomware campaign use (Known or Unknown)CISA KEVPatch now within a year of listing, else Patch this week
Forensic triageCISA KEV (since July 2026)Patch now
EPSS score and percentileFIRST EPSSPatch this week at 0.50 or more; the percentile orders each group
Metasploit moduleMetasploit Framework module metadataPatch this week, and first in each group
Verified Exploit-DB entryExploit-DB repository indexSecond in each group's order
CVE record: description, CWE, CVSS and CISA's SSVC valuesCVE Services and CISA VulnrichmentShown on the CVE page, not used in the rank

What the numbers mean

EPSS, the Exploit Prediction Scoring System from FIRST, estimates the probability that a vulnerability sees exploitation activity in the next 30 days. We show it to 2 decimals, and a score of 0.995 or more as 0.99: EPSS never reaches 1, and 1.00 would read as a certainty. Its percentile is the share of scored CVEs with the same or a lower score, rounded down to a whole number, so 99.8 shows as 99.

The due date is CISA's deadline for US federal civilian agencies, nobody else. We call it the US federal deadline. The ransomware flag is CISA's: Known when CISA knows of a ransomware campaign using the flaw, Unknown otherwise.

When the pages update

We read CISA's list every hour from CISA's own copy on GitHub, which trails the file on cisa.gov by half an hour to four and a half hours. EPSS publishes one file a day, at about 13:30 UTC. We read a CVE record minutes after CISA lists it and again whenever the record changes. Metasploit and Exploit-DB are read once a day, at about 05:00 UTC.

A page is rebuilt when any of its data changes. The date at the start of each page is the date of its data, not of the build.

Known breaks in the data

  • BOD 26-04, issued on 10 June 2026, changed what a due date means: it now follows CISA's urgency tier for the entry, 3 days or 14 days.
  • CISA's forensic triage flag exists only for entries listed since 1 July 2026.
  • EPSS changed its model on 7 March 2023, 17 March 2025 and 15 June 2026; each change moved nearly every score. The EPSS lines on CVE pages mark these days.
  • EPSS on the day CISA listed an entry is shown for entries listed since 4 February 2022, the first EPSS file in the format we read.
  • CISA's own file keeps only the latest state of each entry. Our change log begins with the history CISA keeps on GitHub, from January 2025. That history skips some days: the releases of 2, 3 and 5 June 2025 first appear on 9 June 2025, so changes between two of its records are dated at the later one.

What the rank is not

It is our reading of public data, not advice for your systems. It does not know which products and versions you run, whether they face the internet, or what your vendor has published since. Use it to choose what to look at first.

Changes to the method

  • Version 1, 5 October 2026: the first version.

Report an error

Write to hello@whattopatch.com. How we handle corrections is on the corrections page.