Skip to main content
Category: Vulnerability & Exposure Management

CISA Known Exploited Vulnerabilities (KEV)

Also known as: KEV, KEV Catalog, Known Exploited Vulnerabilities Catalog, CISA KEV Catalog
Simply put

The CISA Known Exploited Vulnerabilities (KEV) Catalog is a list, maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), of software and hardware security flaws that have been observed being actively used in real-world attacks. Because these vulnerabilities are confirmed to be exploited rather than merely theoretical, the catalog helps organizations prioritize which flaws to fix first. It is published for free and updated as CISA adds new vulnerabilities based on evidence of active exploitation.

Formal definition

The KEV Catalog is an authoritative, CISA-maintained reference of vulnerabilities, identified by CVE, for which there is evidence of active exploitation in the wild. CISA adds entries as active exploitation is confirmed and publishes the catalog in machine-readable CSV and JSON formats to support automated ingestion into vulnerability management workflows. Each entry ties a vulnerability to a specific product and weakness (for example, an improper pathname limitation to a restricted directory). The National Vulnerability Database (NVD) cross-references KEV membership on its CVE detail pages, allowing practitioners to identify KEV-listed vulnerabilities within existing CVE-based processes. The catalog is intended to drive risk-based prioritization and remediation of the vulnerabilities most likely to be exploited, rather than serving as a comprehensive list of all known vulnerabilities.

Why it matters

Most organizations face far more open vulnerabilities than they can realistically remediate at once, and severity scores alone do not indicate which flaws attackers are actually using. The KEV Catalog addresses this gap by focusing attention on vulnerabilities for which CISA has evidence of active exploitation in the wild. For a virtual or fractional CISO advising a client, KEV membership provides a defensible, evidence-based signal for prioritization: rather than debating theoretical risk, security leaders can direct limited remediation resources toward flaws that are demonstrably being weaponized.

The catalog also functions as a common reference point across governance, risk, and technical teams. Because the NVD cross-references KEV membership on its CVE detail pages, practitioners can identify KEV-listed vulnerabilities within existing CVE-based processes without adopting an entirely new toolchain. This makes it easier for a security leader to translate technical findings into board-level and risk-committee conversations about exposure and remediation urgency.

It is important to frame the KEV Catalog accurately when advising clients. It is not a comprehensive inventory of all known vulnerabilities, and absence from the catalog does not mean a vulnerability is safe to ignore. A vulnerability may be exploited before it is added, and prioritization decisions should account for the client's own asset exposure, compensating controls, and business context. A virtual CISO advises on and directs how KEV is used within a program, but accountability for remediation decisions and outcomes remains with the client organization and its officers.

Who it's relevant to

Virtual and Fractional CISOs
For security leaders working across one or multiple client organizations, the KEV Catalog offers an authoritative, no-cost input for building risk-based prioritization into a vulnerability management program. It helps a vCISO justify remediation sequencing to stakeholders using evidence of active exploitation rather than severity scores alone. The vCISO typically advises on how KEV is integrated and directs the program, but does not usually perform hands-on patching or tool administration unless that work is explicitly contracted, and accountability for remediation remains with the client.
Vulnerability and Patch Management Teams
Operational teams can ingest the catalog's CSV and JSON files into their tooling to automatically flag KEV-listed CVEs within their existing workflows. This supports faster triage of vulnerabilities confirmed to be exploited in the wild. Teams should treat KEV as one prioritization signal among several, since it is not a comprehensive list of all vulnerabilities and a flaw may be exploited before it appears in the catalog.
Governance, Risk, and Compliance Stakeholders
Risk and compliance leaders can use KEV membership as a defensible reference point when reporting exposure and remediation status to executives or risk committees. Because the NVD cross-references KEV on CVE detail pages, it fits into established CVE-based reporting. The value of this input depends on organizational maturity, asset visibility, and the client's willingness to act on prioritized findings.
Organizations Pursuing Framework Alignment
Organizations working toward alignment with frameworks such as NIST CSF or ISO 27001, or preparing for assessments, can reference KEV to support risk-based remediation as part of their vulnerability management processes. KEV use can support readiness efforts but does not by itself assert or guarantee compliance or certification against any framework.

Inside KEV

Catalog of Actively Exploited Vulnerabilities
The KEV is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) that identifies vulnerabilities for which there is reliable evidence of active exploitation in the wild. Inclusion signals that attackers are already using the flaw, not merely that a weakness theoretically exists.
CVE Identifier
Each KEV entry references a Common Vulnerabilities and Exposures (CVE) identifier, allowing organizations to cross-reference the vulnerability against their asset inventory, scanning tools, and vendor advisories.
Vendor, Product, and Vulnerability Name
Entries typically name the affected vendor and product along with a short description of the vulnerability, helping teams determine whether the affected technology is present in their environment.
Date Added and Required Action
Each entry records the date it was added to the catalog and describes the remediation action expected, such as applying vendor updates or mitigations. The catalog is associated with a Binding Operational Directive that sets remediation timelines for U.S. federal civilian executive branch agencies.
Due Date for Remediation
For in-scope federal agencies, entries carry a remediation due date. The KEV is widely referenced by private-sector organizations as a prioritization aid, though those remediation deadlines are not legally binding on entities outside the directive's scope.
Prioritization Signal for vCISO Programs
In a virtual CISO context, the KEV functions as an authoritative input to vulnerability management and risk prioritization. A vCISO typically advises on how to integrate KEV monitoring into governance and patch-management processes; the operational task of scanning, patching, and remediation validation generally remains with the client's technical teams unless explicitly contracted.

Common questions

Answers to the questions practitioners most commonly ask about KEV.

Does appearing on the CISA KEV catalog mean a vulnerability is more severe than others with high CVSS scores?
Not necessarily in terms of severity as measured by CVSS. The KEV catalog is built around evidence of active exploitation in the wild, not theoretical severity. A vulnerability with a moderate CVSS score can appear on the KEV list because it is being actively exploited, while some high-CVSS vulnerabilities may never be listed. The distinction matters: KEV inclusion signals real-world attacker use, which many organizations treat as a strong prioritization signal, but it is a different measure than severity scoring. A virtual CISO typically advises using KEV as one prioritization input alongside CVSS, asset exposure, and business context rather than as a standalone ranking of severity.
Is the CISA KEV catalog a legal mandate that applies to my private company?
The binding remediation timelines associated with the KEV catalog, established under CISA's Binding Operational Directive, apply to U.S. federal civilian executive branch agencies. Private-sector and non-federal organizations are generally not legally obligated to follow those timelines solely because a vulnerability is listed. That said, many private organizations voluntarily adopt the catalog as a prioritization reference, and specific contractual, regulatory, or sector requirements may reference it. A virtual CISO can help clarify whether any obligation applies in a given context, but the vCISO advises on this; accountability for compliance decisions typically remains with the client organization and its officers.
How can a virtual CISO help us operationalize the KEV catalog in our vulnerability management program?
In many engagements, a virtual CISO helps integrate the KEV catalog into existing vulnerability management workflows by advising on how to cross-reference the listed CVEs against your asset and software inventory, define prioritization rules that elevate KEV-listed items, and set internal remediation targets that reflect your risk tolerance. The vCISO generally provides governance and process guidance rather than performing the hands-on scanning, patching, or tool configuration, which typically remains with internal teams or a managed service provider unless explicitly contracted. The value of this support depends heavily on the accuracy of your asset inventory and the maturity of your existing processes.
How often should we check the KEV catalog and update our internal prioritization?
The KEV catalog is updated by CISA as new vulnerabilities meeting its criteria are identified, so it changes over time rather than on a fixed public schedule. A virtual CISO often recommends automating ingestion of the catalog where feasible so that new entries are reviewed against your environment on a regular cadence rather than manually and infrequently. The appropriate frequency may vary by provider and organization, but the goal is to ensure newly listed, actively exploited vulnerabilities are surfaced and triaged promptly. The vCISO advises on the cadence and process; execution of the monitoring itself is typically an operational function.
What should we do if a KEV-listed vulnerability affects a system we cannot patch immediately?
When immediate remediation is not feasible, a virtual CISO typically helps the organization evaluate compensating controls and interim risk-reduction measures, such as network segmentation, access restrictions, enhanced monitoring, or temporary isolation, and helps document the accepted risk through appropriate governance channels. The vCISO advises on and directs these decisions, but accountability for accepting residual risk usually rests with the client organization and its officers. The practicality of any given mitigation depends on the affected system, business dependencies, and available resources.
Can relying on the KEV catalog guarantee we address the vulnerabilities most likely to be used against us?
No. The KEV catalog reflects vulnerabilities with confirmed evidence of active exploitation known to CISA, but it does not capture every vulnerability that could be exploited, including newly emerging or targeted threats not yet cataloged. A virtual CISO generally positions KEV as a valuable prioritization signal within a broader, risk-based vulnerability management approach rather than a complete or guaranteed defense. Its usefulness depends on combining it with your own threat context, asset exposure, and other intelligence sources, and no prioritization method can guarantee breach prevention.

Common misconceptions

The KEV catalog lists all serious or high-severity vulnerabilities an organization needs to worry about.
The KEV is deliberately narrow: it focuses on vulnerabilities with evidence of active exploitation. Many high-severity vulnerabilities never appear on it, and the KEV is intended to complement, not replace, broader vulnerability management informed by severity scoring, asset criticality, and threat context.
The KEV remediation due dates legally apply to all organizations.
The remediation deadlines are tied to a Binding Operational Directive that applies to U.S. federal civilian executive branch agencies. Private-sector organizations often adopt the KEV voluntarily as a prioritization benchmark, but the deadlines are not, by themselves, a legal obligation for them. A vCISO advises on adoption while legal and compliance accountability remains with the client organization.
Engaging a virtual CISO who tracks the KEV means the vCISO will remediate the listed vulnerabilities.
A virtual CISO typically provides strategy, governance, and prioritization guidance around the KEV. Hands-on remediation, patch deployment, and validation are operational tasks usually performed by the client's staff or a separate service provider unless the engagement scope specifically includes them.

Best practices

Incorporate the KEV catalog as a priority input into your vulnerability management workflow, escalating KEV-listed items ahead of vulnerabilities lacking evidence of active exploitation, while still maintaining a broader program driven by asset criticality and severity.
Cross-reference KEV entries against a current asset inventory using the CVE identifiers so that remediation effort is focused on technologies actually present in your environment.
Treat federal remediation due dates as a useful benchmark rather than a universal legal requirement, and, where a vCISO is involved, have them help set internally defined remediation timelines aligned with your organization's risk tolerance.
Clarify in the engagement scope whether the virtual CISO's role is advisory prioritization only or whether it extends to overseeing or performing remediation, so accountability and responsibility are explicitly assigned.
Establish a recurring process to monitor KEV updates, since the catalog is added to over time, and document how new entries flow into ticketing, patch management, and executive risk reporting.
Use KEV-driven activity as evidence for governance and risk reporting to leadership, recognizing that KEV remediation supports, but does not by itself guarantee, compliance with any specific framework or regulation.