What is the Known Exploited Vulnerabilities Catalog (KEV)?
The Known Exploited Vulnerabilities Catalog is CISA’s evidence-based list of Common Vulnerabilities and Exposures (CVE) entries exploited in the wild. CISA requires an assigned CVE ID, reliable evidence of active exploitation, and clear remediation guidance before adding a vulnerability. KEV therefore adds exploitation evidence to vulnerability prioritization; it is not a list of every severe vulnerability.
What is the KEV Catalog used for?
Organizations use KEV as an input to Vulnerability Management and Patch Management, helping teams place actively exploited flaws ahead of vulnerabilities prioritized only by severity. Asset owners must still consider whether affected products are present, internet exposure, available mitigations, operational constraints, and potential organizational business risk and impact.
U.S. federal agencies use the catalog under applicable CISA directives, while other organizations can treat it as a high-value prioritization input rather than a general legal mandate. Leaders should connect KEV findings to accountable asset owners, risk-based remediation targets, documented exception governance, compensating controls, and technical closure evidence. The catalog should sharpen remediation decisions without substituting for asset context, business impact, threat analysis, or vulnerabilities and attack paths not represented in KEV.