An Explainable Machine-Learning Framework for Prioritizing Cybersecurity Vulnerabilities in the Post-Mythos Era

Authors

DOI:

https://doi.org/10.32996/jcsts.2026.8.8.14

Keywords:

Vulnerability prioritization, Exploit prediction, Explainable Machine learning, CVSS, EPSS, CISA KEV, SHAP

Abstract

AI-enabled vulnerability discovery is increasing both the volume and speed of newly identified security flaws, while organizations continue to face limited remediation capacity. This paper presents EVPD, an explainable machine-learning framework that ranks newly disclosed CVEs by their likelihood of entering the CISA Known Exploited Vulnerabilities Catalog within 180 days. The dataset combines 156,444 CVEs from NVD and MITRE records with historically aligned EPSS observations and CISA KEV dates. After temporal eligibility filtering, 134,875 vulnerabilities were divided chronologically into training, validation, and 2025 test partitions. A stacked ensemble combining a random-forest score, EPSS, and CVSS achieved a test PR-AUC of 0.0600, compared with 0.0337 for a tuned CVSS–EPSS baseline and a no-skill value of 0.0016. A paired bootstrap analysis produced a mean PR-AUC improvement of 0.0242, with a 95% confidence interval of 0.0032–0.0511. When remediation capacity was limited to the top 1% of the test backlog, EVPD identified 27.0% of the vulnerabilities that later entered KEV, compared with 17.6% for CVSS–EPSS and 12.2% for CVSS alone. SHAP analysis showed that historical EPSS, affected-configuration breadth, and CVSS impact measures con-tributed most strongly to the predictions. The results indicate that temporally aligned and explainable ranking can improve early vulnerability selection when remediation capacity is highly constrained.

Author Biography

  • Nandita Das, Researcher, New Jersey, USA
    Nandita Das is a Senior Manager in Cybersecurity and Data Protection at EY, with over 15 years of experience advising Fortune 500 organizations, private equity firms, utilities, and regulated industries on cybersecurity strategy, privacy, identity security, and enterprise risk management. Her expertise spans data protection, AI governance, cryptography, post-quantum cryptography (PQC), privileged access management (PAM), non-human identities (NHI), and cyber transformation programs. Nandita has led large-scale initiatives involving data classification, governance, cloud security, and cyber resilience. She is a published author, researcher, and conference speaker, presenting on topics such as AI trust, quantum-resilient security, machine authority in cyber governance, and privacy-preserving technologies. She holds the Certified Information Privacy Technologist (CIPT) certification and actively contributes to research and industry forums focused on the intersection of cybersecurity, emerging technologies, and governance.

Downloads

Published

2026-07-26

Issue

Section

Research Article

How to Cite

Das, N. (2026). An Explainable Machine-Learning Framework for Prioritizing Cybersecurity Vulnerabilities in the Post-Mythos Era. Journal of Computer Science and Technology Studies, 8(8), 213-221. https://doi.org/10.32996/jcsts.2026.8.8.14