The Known Exploited Vulnerabilities (KEV) catalog is a list, maintained by the US Cybersecurity and Infrastructure Security Agency (CISA), of software and hardware flaws that attackers are known to be exploiting in the real world. A flaw is added only when there is evidence of active exploitation, so a KEV entry means “this is being used against organizations now”, not “this could be exploited someday”.
Why the KEV catalog matters
Thousands of vulnerabilities are published every year, and most are never used in an attack. KEV helps defenders cut through that volume. If a flaw in your environment is on the list, it should move to the front of the patching queue, ahead of flaws that merely have a high severity score.
How a vulnerability gets added
CISA adds a flaw to the catalog when three conditions are met:
- it has an assigned CVE ID;
- there is reliable evidence that it has been exploited in the wild;
- there is clear remediation guidance, such as a vendor patch or a mitigation.
Due dates and who must follow them
Every entry has a due date. Under CISA Binding Operational Directive 22-01, issued in November 2021, US federal civilian agencies must remediate KEV entries by that date. Private companies are not bound by the directive, but many use the due dates as a practical deadline. Each entry also states whether it is known to be used in ransomware campaigns.
How to use the catalog
- Match the list against your asset inventory, so you know which entries apply to you.
- Patch or apply the vendor mitigation by the due date. If neither is possible, restrict access to the affected system or take it offline.
- Assume compromise is possible. A flaw may have been exploited before you patched, so check logs and look for unexpected accounts, processes and outbound connections.
- Watch the catalog or its feed, so you hear about new entries quickly.
How we use KEV in our articles
Every vulnerability article has an “At a glance” box. Its KEV row says whether the flaw is listed and gives the due date. We read this from the official catalog and link to it as a primary source. Read it together with the EPSS and CVSS rows: KEV shows what is already being exploited, EPSS estimates what is likely to be exploited next, and CVSS describes how severe a flaw is.
The official catalog is published by CISA at cisa.gov.
