CISA Known Exploited Vulnerabilities (KEV)
The CISA Known Exploited Vulnerabilities (KEV) Catalog is a list, maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), of software and hardware security flaws that have been observed being actively used in real-world attacks. Because these vulnerabilities are confirmed to be exploited rather than merely theoretical, the catalog helps organizations prioritize which flaws to fix first. It is published for free and updated as CISA adds new vulnerabilities based on evidence of active exploitation.
The KEV Catalog is an authoritative, CISA-maintained reference of vulnerabilities, identified by CVE, for which there is evidence of active exploitation in the wild. CISA adds entries as active exploitation is confirmed and publishes the catalog in machine-readable CSV and JSON formats to support automated ingestion into vulnerability management workflows. Each entry ties a vulnerability to a specific product and weakness (for example, an improper pathname limitation to a restricted directory). The National Vulnerability Database (NVD) cross-references KEV membership on its CVE detail pages, allowing practitioners to identify KEV-listed vulnerabilities within existing CVE-based processes. The catalog is intended to drive risk-based prioritization and remediation of the vulnerabilities most likely to be exploited, rather than serving as a comprehensive list of all known vulnerabilities.
Why it matters
Most organizations face far more open vulnerabilities than they can realistically remediate at once, and severity scores alone do not indicate which flaws attackers are actually using. The KEV Catalog addresses this gap by focusing attention on vulnerabilities for which CISA has evidence of active exploitation in the wild. For a virtual or fractional CISO advising a client, KEV membership provides a defensible, evidence-based signal for prioritization: rather than debating theoretical risk, security leaders can direct limited remediation resources toward flaws that are demonstrably being weaponized.
The catalog also functions as a common reference point across governance, risk, and technical teams. Because the NVD cross-references KEV membership on its CVE detail pages, practitioners can identify KEV-listed vulnerabilities within existing CVE-based processes without adopting an entirely new toolchain. This makes it easier for a security leader to translate technical findings into board-level and risk-committee conversations about exposure and remediation urgency.
It is important to frame the KEV Catalog accurately when advising clients. It is not a comprehensive inventory of all known vulnerabilities, and absence from the catalog does not mean a vulnerability is safe to ignore. A vulnerability may be exploited before it is added, and prioritization decisions should account for the client's own asset exposure, compensating controls, and business context. A virtual CISO advises on and directs how KEV is used within a program, but accountability for remediation decisions and outcomes remains with the client organization and its officers.
Who it's relevant to
Inside KEV
Common questions
Answers to the questions practitioners most commonly ask about KEV.