KNOWLEDGE CENTER
What is the CISA KEV Catalog?
TheΒ CISA Known Exploited Vulnerabilities (KEV) CatalogΒ is a publicly available catalog of software and hardware vulnerabilities that have been confirmed as actively exploited in real-world attacks.
The CISA Known Exploited Vulnerabilities (KEV) Catalog Explained
Maintained by theΒ Cybersecurity and Infrastructure Security Agency (CISA), theΒ catalogΒ serves as an authoritative source of vulnerability intelligence, helping organizationsΒ identifyΒ which vulnerabilities are currently beingΒ leveragedΒ by threat actors and should therefore be prioritized for remediation. CISA explicitly recommends that organizations use the KEV Catalog as an input to their vulnerability management prioritization strategy.Β
Unlike the broader Common Vulnerabilities and Exposures (CVE) database, whichΒ containsΒ hundreds of thousands of reported vulnerabilities, theΒ KEV Catalog focuses only on vulnerabilities for which CISA has reliable evidence of exploitation in the wild.Β This distinction makes the catalog one of the most valuable resources available for risk-based vulnerability management.Β
What Does KEV Stand For?Β
KEVΒ stands forΒ Known Exploited Vulnerabilities.Β
A vulnerability is added to theΒ CISA KEV Catalog only after there is evidence that attackers are actively exploiting it against public or private organizations. Rather than trying to predict which vulnerabilities might be dangerous, the KEV Catalog highlights vulnerabilities that have already crossed an important threshold: they have been weaponized and used by real threat actors.Β
This makes KEV listings especially useful for security teams that need to prioritize limited remediation resources.Β
Why Was the CISA KEV Catalog Created?Β
The catalog was created to help organizations focus on vulnerabilities that present an immediate and proven threat.Β
Historically, vulnerability management programs relied heavily on severity scoresΒ likeΒ CVSS toΒ determineΒ remediation priorities. While severityΒ remainsΒ useful, many highly rated vulnerabilities are never exploited, while some lower-scoring vulnerabilities become major attack vectors.Β
To address this gap, CISA launched the KEV Catalog as part ofΒ Binding Operational Directive (BOD) 22-01, an initiative requiring U.S. Federal Civilian Executive Branch agencies to remediate known exploited vulnerabilities within defined deadlines. The directiveΒ establishedΒ both the catalog itself and the operational framework for using exploit intelligence to drive remediation decisions.Β
The result was a standardized, publicly accessible source of verified exploitation data that both government agencies and private-sector organizations could use to prioritize security efforts.Β
CISA BOD 22-01 was superseded byΒ CISA BOD 26-04Β in June 2026. UnderΒ BOD 26-04, the KEV Catalog has become one of four factors that government agencies must consider whenΒ prioritizingΒ vulnerability remediation activities.Β
How the CISA KEV Catalog WorksΒ
When CISAΒ determinesΒ there is reliable evidence that aΒ vulnerability is being actively exploited, it may add that vulnerability to the KEV Catalog. Each entry typically includes:Β
- CVE identifier
- Vendor and product information
- Vulnerability description
- Date added to the catalog
- Remediation guidance
- Required remediation deadlines for federal agencies
- InformationΒ regardingΒ ransomware usage when availableΒ
The catalog is continuously updated as new exploitation activity isΒ identified. CISA also makes the dataset availableΒ in machine-readable formats, making it easy to integrate into vulnerability management and security operations workflows.Β
Why the KEV Catalog Matters for Vulnerability ManagementΒ
Most organizations face an impossible challenge: there are far more vulnerabilities than can reasonably be remediated.Β
A modern enterpriseΒ environment may contain thousands or even tens of thousands of detected vulnerabilities. While vulnerability scanners canΒ identifyΒ everything that is technically vulnerable, they cannot alwaysΒ determineΒ which issues poseΒ the greatest real-world risk.Β
The KEV Catalog helps solve this prioritization problem by answering a critical question:Β Which vulnerabilities are attackersΒ actually exploitingΒ today?Β
Because KEV entries represent confirmed exploitation, they are often considered among the highest-confidence indicatorsΒ availableΒ when deciding how toΒ allocateΒ remediation resources.Β
Many vulnerability management programs use KEV status alongside factors such as:Β
- CVSS severity
- Asset criticality
- Internet exposure
- Exploit availability
- Threat intelligence
- Business impactΒ
Together, these factorsΒ provideΒ a more realistic view of organizational risk than severity ratings alone.Β
CISA KEV vs CVE:Β What’sΒ the Difference?Β
One of the most common sources of confusion is the relationship betweenΒ CVEΒ andΒ KEV.Β
Think of the KEV Catalog as a curated list of the vulnerabilitiesΒ thatΒ security teams should pay attention to first.
| CVE | KEV |
|---|---|
| A catalog of publicly disclosed vulnerabilities | A catalog of vulnerabilities confirmed to be actively exploited |
| Managed by the CVE Program | Managed by CISA |
| Contains hundreds of thousands of vulnerabilities | Contains a much smaller subset of exploited vulnerabilities |
| Indicates a vulnerability exists | Indicates a vulnerability is being exploited in the wild |
| Not all CVEs are exploited | Every KEV entry is associated with a CVE |
Are Organizations Required to Remediate KEV Vulnerabilities?Β
For U.S. federal civilian agencies, compliance requirements originate from CISA’s Binding Operational Directives, whichΒ establishΒ remediation timelines for vulnerabilities added to the catalog.Β
Private-sector organizationsΒ are generally not required toΒ follow these directives. However, many security teams use KEV status as a critical prioritization signal because itΒ representsΒ verified attacker activity rather than theoretical risk.Β
As a result, KEV has become one of the most widely adopted sources of vulnerability intelligence across both public and private sectors.Β
Limitations of the CISA KEV CatalogΒ
While the KEV Catalog is one of the most valuable vulnerability intelligence resources available, it is not designed to predict future attacks.Β
A vulnerability mustΒ first be exploited,Β observed, andΒ validatedΒ before it can be added to the catalog. This means exploitation may begin days or weeks before a vulnerability appears in KEV. As Nucleus research has noted, KEV should be viewed as a confirmation signal of active exploitation rather than an early warning system.Β
For this reason,Β matureΒ security programs often combine KEV data withΒ additionalΒ threat intelligence sources, exploitability analysis, and business context to make faster risk decisions.Β
How Organizations Use CISA KEV Data TodayΒ
Security teams commonly use the KEV Catalog to:Β
- Prioritize remediation efforts
- Identify actively exploited vulnerabilities in their environment
- Support risk-based vulnerability management programs
- Drive patching and mitigation workflows
- Monitor newly exploited CVEs
- Meet regulatory or contractual security requirementsΒ
Many vulnerability management platforms enrich findings with KEV status to make identification and prioritization easier at scale.Β Β
Bringing CISA KEV Into Your Vulnerability Management ProgramΒ
The CISA Known Exploited Vulnerabilities Catalog isΒ one of the mostΒ widely usedΒ sources of vulnerability intelligence available today. By focusing on vulnerabilities with confirmed exploitation activity, it helps organizations move beyond severity-based prioritization and concentrate on the risks most likely to lead to compromise.Β
Organizations that integrate KEV intelligence into their vulnerability management workflows can reduce noise, focus remediation efforts, and respond more effectively to evolving threat activity.Β
See Nucleus in Action
Discover how unified, risk-based automation can transform your vulnerability management.