Measured 2026-09-27 against the live CISA KEV catalogue (1,726 entries), 10,930 CVEs with public proof-of-concept repositories on GitHub, and the FIRST EPSS scores of 2025-09-27. Every number on this page is recomputed from those sources when the page rebuilds.
The question
When a proof-of-concept exploit for a CVE appears on GitHub, most security teams treat it as the moment a vulnerability becomes urgent. It is one of the oldest triage rules there is, and it feels obviously right: public code lowers the bar for attackers.
It is also rarely measured. This page checks the rule against the same scoreboard we used for EPSS in Does EPSS Predict What CISA Confirms?: CISA’s Known Exploited Vulnerabilities catalogue, where a listing means CISA has evidence of exploitation in the wild. Two questions. When CISA confirms exploitation, had the code been public first? And when code goes public, how often does confirmed exploitation follow?
Half 1 — when CISA confirms exploitation, was the exploit already on GitHub?
CISA added 545 vulnerabilities to KEV between 2024-09-27 and 2026-09-27. For each one we took the creation date of the earliest public GitHub repository carrying a proof-of-concept for it.
| First public PoC on GitHub | CVEs | Share |
|---|---|---|
| Before CISA listed it | 180 | 33% |
| Same day | 23 | 4% |
| After CISA listed it | 124 | 23% |
| Never — no public PoC repo to date | 218 | 40% |
The largest group is the one the rule cannot see. 40% of the vulnerabilities CISA confirmed as exploited have no public proof-of-concept repository on GitHub at all. Whoever exploited them did not publish there, and a process that waits for GitHub would still be waiting.
Where the code did come first (33%), it came early: the median gap between the first repository and the KEV listing was 40 days. That is a real warning window, though a wide one:
| PoC appeared before the listing by | CVEs | Share of the early group |
|---|---|---|
| 1-7 days | 45 | 25% |
| 8-30 days | 35 | 19% |
| 31-365 days | 63 | 35% |
| more than a year | 37 | 21% |
For another 23%, the first repository appeared only after CISA’s listing — a median of 4 days later. In those cases the public code followed the exploitation news rather than predicting it.
Half 2 — when code goes public, does exploitation follow?
Half 1 only looks at vulnerabilities that were exploited. To know whether a public PoC is a useful alarm, we also need the ones where the alarm went off and nothing happened. So we went back one year, to 2025-09-27, and took every CVE that EPSS scored that day and CISA had not yet listed: 294,454 vulnerabilities. Over the following year, 94 of them (0.032%) were added to KEV. We then split the population by how many public PoC repositories each CVE had on 2025-09-27.
| PoC repos on GitHub a year ago | CVEs | Reached KEV since | Hit rate | vs. all CVEs |
|---|---|---|---|---|
| no PoC repo | 288,081 | 58 | 0.02% | 0.6× |
| 1 repo | 5,051 | 14 | 0.28% | 8.7× |
| 2-4 repos | 1,039 | 13 | 1.25% | 39.2× |
| 5-9 repos | 189 | 3 | 1.59% | 49.7× |
| 10+ repos | 94 | 6 | 6.38% | 199.9× |
The signal is real and it has a gradient. A vulnerability with any public PoC was about 17.7 times more likely to reach KEV than the average CVE. The count matters more than the existence: a single repository is a weak signal (0.28%), while CVEs with ten or more repositories reached KEV at 6.4% — the strongest single signal on this page. In absolute terms it is still a minority: 94% of even the most-published vulnerabilities were not confirmed as exploited within the year. The top bands are also small (94 CVEs in the 10+ group), so treat their exact rates as indicative.
Head to head: a GitHub PoC or an EPSS score?
The same population lets us put the two most common early-warning signals side by side, using the EPSS > 0.9 threshold from our EPSS study. “Caught” is the share of the 94 vulnerabilities that reached KEV which the signal had already flagged a year earlier.
| Signal a year ago | CVEs flagged | Reached KEV | Hit rate | vs. all CVEs | Caught |
|---|---|---|---|---|---|
| Any public PoC repo | 6,373 | 36 | 0.56% | 17.7× | 38% |
| EPSS > 0.9 | 778 | 11 | 1.41% | 44.2× | 12% |
| Both | 465 | 6 | 1.29% | 40.4× | 6% |
| Neither | 287,768 | 53 | 0.02% | 0.6× | 56% |
They fail in opposite directions. The PoC signal is broad: it flagged 38% of what CISA went on to confirm, against 12% for EPSS > 0.9 — but it flags 6,373 vulnerabilities to do it, so each flag is worth less (0.56% against 1.41%). Used together they flagged 44% in advance. The remaining 56% of the vulnerabilities that reached KEV showed neither signal a year before.
What this means for triage
- Count the repositories, not just their existence. One repo moves the needle a little; many repos move it a lot.
- No PoC is not reassurance. 40% of recently confirmed exploited vulnerabilities never had public code on GitHub.
- No single public signal covers most of the risk. PoC and EPSS together flagged about 44% of next year’s KEV listings among existing CVEs. Exposure — whether the affected product faces the internet in your estate — has to carry the rest.
- KEV is the one list that is always actionable. Our daily KEV tracker and EPSS watchlist are refreshed every day.
Method and limits
- PoC data comes from the community-maintained PoC-in-GitHub index, which records public GitHub repositories named for a CVE. We count repositories, not verified exploits. Some are scanners or detection templates, some do not work, and some fake PoCs are malware aimed at researchers — we do not link to any of them.
- Repository creation date stands in for publication date. Code can be pushed later than the repository was created, which would make some leads look longer than they were.
- Deleted repositories are missing. GitHub removes malicious and infringing repositories, so PoC counts are a lower bound.
- KEV is CISA’s confirmation, not all exploitation. Exploited vulnerabilities CISA never lists count as misses here, for both signals.
- Half 2 covers CVEs that already existed a year ago. Most KEV additions are vulnerabilities published the same year; those are outside this population by design and are covered by Half 1.
Sources: CISA KEV catalogue, PoC-in-GitHub and FIRST EPSS. Recomputed monthly; last run 2026-09-27.

