An Explainable Machine-Learning Framework for Prioritizing Cybersecurity Vulnerabilities in the Post-Mythos Era
DOI:
https://doi.org/10.32996/jcsts.2026.8.8.14Keywords:
Vulnerability prioritization, Exploit prediction, Explainable Machine learning, CVSS, EPSS, CISA KEV, SHAPAbstract
AI-enabled vulnerability discovery is increasing both the volume and speed of newly identified security flaws, while organizations continue to face limited remediation capacity. This paper presents EVPD, an explainable machine-learning framework that ranks newly disclosed CVEs by their likelihood of entering the CISA Known Exploited Vulnerabilities Catalog within 180 days. The dataset combines 156,444 CVEs from NVD and MITRE records with historically aligned EPSS observations and CISA KEV dates. After temporal eligibility filtering, 134,875 vulnerabilities were divided chronologically into training, validation, and 2025 test partitions. A stacked ensemble combining a random-forest score, EPSS, and CVSS achieved a test PR-AUC of 0.0600, compared with 0.0337 for a tuned CVSS–EPSS baseline and a no-skill value of 0.0016. A paired bootstrap analysis produced a mean PR-AUC improvement of 0.0242, with a 95% confidence interval of 0.0032–0.0511. When remediation capacity was limited to the top 1% of the test backlog, EVPD identified 27.0% of the vulnerabilities that later entered KEV, compared with 17.6% for CVSS–EPSS and 12.2% for CVSS alone. SHAP analysis showed that historical EPSS, affected-configuration breadth, and CVSS impact measures con-tributed most strongly to the predictions. The results indicate that temporally aligned and explainable ranking can improve early vulnerability selection when remediation capacity is highly constrained.

Aims & scope
Call for Papers
Article Processing Charges
Publications Ethics
Google Scholar Citations
Recruitment