KNOWLEDGE CENTER

What is the CISA KEV Catalog?

The CISA Known Exploited Vulnerabilities (KEV) Catalog is a publicly available catalog of software and hardware vulnerabilities that have been confirmed as actively exploited in real-world attacks.

What is the CISA KEV Catalog?

The CISA Known Exploited Vulnerabilities (KEV) Catalog Explained

Maintained by the Cybersecurity and Infrastructure Security Agency (CISA), the catalog serves as an authoritative source of vulnerability intelligence, helping organizations identify which vulnerabilities are currently being leveraged by threat actors and should therefore be prioritized for remediation. CISA explicitly recommends that organizations use the KEV Catalog as an input to their vulnerability management prioritization strategy. 

Unlike the broader Common Vulnerabilities and Exposures (CVE) database, which contains hundreds of thousands of reported vulnerabilities, the KEV Catalog focuses only on vulnerabilities for which CISA has reliable evidence of exploitation in the wild. This distinction makes the catalog one of the most valuable resources available for risk-based vulnerability management. 

What Does KEV Stand For? 

KEV stands for Known Exploited Vulnerabilities. 

A vulnerability is added to the CISA KEV Catalog only after there is evidence that attackers are actively exploiting it against public or private organizations. Rather than trying to predict which vulnerabilities might be dangerous, the KEV Catalog highlights vulnerabilities that have already crossed an important threshold: they have been weaponized and used by real threat actors. 

This makes KEV listings especially useful for security teams that need to prioritize limited remediation resources. 

Why Was the CISA KEV Catalog Created? 

The catalog was created to help organizations focus on vulnerabilities that present an immediate and proven threat. 

Historically, vulnerability management programs relied heavily on severity scores like CVSS to determine remediation priorities. While severity remains useful, many highly rated vulnerabilities are never exploited, while some lower-scoring vulnerabilities become major attack vectors. 

To address this gap, CISA launched the KEV Catalog as part of Binding Operational Directive (BOD) 22-01, an initiative requiring U.S. Federal Civilian Executive Branch agencies to remediate known exploited vulnerabilities within defined deadlines. The directive established both the catalog itself and the operational framework for using exploit intelligence to drive remediation decisions. 

The result was a standardized, publicly accessible source of verified exploitation data that both government agencies and private-sector organizations could use to prioritize security efforts. 

CISA BOD 22-01 was superseded by CISA BOD 26-04 in June 2026. Under BOD 26-04, the KEV Catalog has become one of four factors that government agencies must consider when prioritizing vulnerability remediation activities. 

How the CISA KEV Catalog Works 

When CISA determines there is reliable evidence that a vulnerability is being actively exploited, it may add that vulnerability to the KEV Catalog. Each entry typically includes: 

  • CVE identifier
  • Vendor and product information
  • Vulnerability description
  • Date added to the catalog
  • Remediation guidance
  • Required remediation deadlines for federal agencies
  • Information regarding ransomware usage when available 

The catalog is continuously updated as new exploitation activity is identified. CISA also makes the dataset available in machine-readable formats, making it easy to integrate into vulnerability management and security operations workflows. 

Why the KEV Catalog Matters for Vulnerability Management 

Most organizations face an impossible challenge: there are far more vulnerabilities than can reasonably be remediated. 

A modern enterprise environment may contain thousands or even tens of thousands of detected vulnerabilities. While vulnerability scanners can identify everything that is technically vulnerable, they cannot always determine which issues pose the greatest real-world risk. 

The KEV Catalog helps solve this prioritization problem by answering a critical question: Which vulnerabilities are attackers actually exploiting today? 

Because KEV entries represent confirmed exploitation, they are often considered among the highest-confidence indicators available when deciding how to allocate remediation resources. 

Many vulnerability management programs use KEV status alongside factors such as: 

  • CVSS severity
  • Asset criticality
  • Internet exposure
  • Exploit availability
  • Threat intelligence
  • Business impact 

Together, these factors provide a more realistic view of organizational risk than severity ratings alone. 

CISA KEV vs CVE: What’s the Difference? 

One of the most common sources of confusion is the relationship between CVE and KEV. 

Think of the KEV Catalog as a curated list of the vulnerabilities that security teams should pay attention to first.

CVEKEV
A catalog of publicly disclosed vulnerabilitiesA catalog of vulnerabilities confirmed to be actively exploited
Managed by the CVE ProgramManaged by CISA
Contains hundreds of thousands of vulnerabilitiesContains a much smaller subset of exploited vulnerabilities
Indicates a vulnerability existsIndicates a vulnerability is being exploited in the wild
Not all CVEs are exploitedEvery KEV entry is associated with a CVE

Are Organizations Required to Remediate KEV Vulnerabilities? 

For U.S. federal civilian agencies, compliance requirements originate from CISA’s Binding Operational Directives, which establish remediation timelines for vulnerabilities added to the catalog. 

Private-sector organizations are generally not required to follow these directives. However, many security teams use KEV status as a critical prioritization signal because it represents verified attacker activity rather than theoretical risk. 

As a result, KEV has become one of the most widely adopted sources of vulnerability intelligence across both public and private sectors. 

Limitations of the CISA KEV Catalog 

While the KEV Catalog is one of the most valuable vulnerability intelligence resources available, it is not designed to predict future attacks. 

A vulnerability must first be exploited, observed, and validated before it can be added to the catalog. This means exploitation may begin days or weeks before a vulnerability appears in KEV. As Nucleus research has noted, KEV should be viewed as a confirmation signal of active exploitation rather than an early warning system. 

For this reason, mature security programs often combine KEV data with additional threat intelligence sources, exploitability analysis, and business context to make faster risk decisions. 

How Organizations Use CISA KEV Data Today 

Security teams commonly use the KEV Catalog to: 

  • Prioritize remediation efforts
  • Identify actively exploited vulnerabilities in their environment
  • Support risk-based vulnerability management programs
  • Drive patching and mitigation workflows
  • Monitor newly exploited CVEs
  • Meet regulatory or contractual security requirements 

Many vulnerability management platforms enrich findings with KEV status to make identification and prioritization easier at scale.  

Bringing CISA KEV Into Your Vulnerability Management Program 

The CISA Known Exploited Vulnerabilities Catalog is one of the most widely used sources of vulnerability intelligence available today. By focusing on vulnerabilities with confirmed exploitation activity, it helps organizations move beyond severity-based prioritization and concentrate on the risks most likely to lead to compromise. 

Organizations that integrate KEV intelligence into their vulnerability management workflows can reduce noise, focus remediation efforts, and respond more effectively to evolving threat activity. 

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.