KEV + EPSS Threat Intel
CVSS tells you how bad a vulnerability could be. Threat intelligence tells you whether anyone is actually exploiting it. The Immortal Defender fuses both into a single risk score, so your report reads in the order attackers would strike.
CISA KEV
Known Exploited Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency maintains the authoritative catalog of vulnerabilities confirmed to be exploited in the wild. A KEV match means attackers are using this flaw right now — it jumps the queue no matter its CVSS score.
FIRST EPSS
Exploit Prediction Scoring System
The Forum of Incident Response and Security Teams publishes a daily probability that each CVE will be exploited in the next 30 days. EPSS separates the 5% of vulnerabilities attackers actually weaponize from the 95% they ignore.
The P1–P5 Ladder
KEV-listed or critical severity with high exploit probability — actively dangerous.
High severity with meaningful exploit likelihood.
Moderate severity or elevated probability — schedule it.
Low residual risk after intel weighting.
Informational; negligible exploitation signal.
Fix What Attackers Use First
KEV-first, probability-weighted reporting ships in every fortress.