Known Exploited Vulnerabilities Catalog (KEV)

CISA’s Catalog for Exploitation-Based Vulnerability Prioritization

What is the Known Exploited Vulnerabilities Catalog (KEV)?

The Known Exploited Vulnerabilities Catalog is CISA’s evidence-based list of Common Vulnerabilities and Exposures (CVE) entries exploited in the wild. CISA requires an assigned CVE ID, reliable evidence of active exploitation, and clear remediation guidance before adding a vulnerability. KEV therefore adds exploitation evidence to vulnerability prioritization; it is not a list of every severe vulnerability.

What is the KEV Catalog used for?

Organizations use KEV as an input to Vulnerability Management and Patch Management, helping teams place actively exploited flaws ahead of vulnerabilities prioritized only by severity. Asset owners must still consider whether affected products are present, internet exposure, available mitigations, operational constraints, and potential organizational business risk and impact.

U.S. federal agencies use the catalog under applicable CISA directives, while other organizations can treat it as a high-value prioritization input rather than a general legal mandate. Leaders should connect KEV findings to accountable asset owners, risk-based remediation targets, documented exception governance, compensating controls, and technical closure evidence. The catalog should sharpen remediation decisions without substituting for asset context, business impact, threat analysis, or vulnerabilities and attack paths not represented in KEV.

Continue reading

CISA Zero Trust Maturity Model 2.0
A Capability Roadmap for Zero Trust
INCOSE Systems Engineering Handbook
Systems Engineering Body of Knowledge
ISO/IEC 27001
Information Security Management System Standard

Please note!
Any use of this website requires prior agreement to our Terms of Use, Privacy Policy, and Cookie Policy.
If you do not fully agree to all of them, do not use this website.