The Known Exploited Vulnerabilities (KEV) Catalog is a list maintained by the Cybersecurity and Infrastructure Security Agency (CISA) that identifies vulnerabilities that are known to be actively exploited in the wild. It helps organizations prioritize vulnerabilities based on evidence of real world exploitation rather than relying only on severity scores.
The catalog is particularly useful for vulnerability management teams that need to determine which vulnerabilities should receive immediate attention.
What is the CISA Known Exploited Vulnerabilities Catalog?
The CISA Known Exploited Vulnerabilities Catalog is a continuously updated list of vulnerabilities that CISA has determined are being actively exploited or meet its criteria for known exploitation.
Each catalog entry generally provides information such as:
- CVE identifier
- Vulnerability description
- Product or vendor affected
- Date the vulnerability was added
- Remediation or required action
- Due date for federal civilian agencies under CISA’s Binding Operational Directive
The catalog is intended to help organizations focus remediation efforts on vulnerabilities that attackers are actually exploiting.
Being listed in the KEV Catalog does not mean that every organization is currently compromised. It means there is evidence that the vulnerability has been exploited and therefore warrants increased attention.
How should teams use the KEV Catalog for prioritization?
Security teams can use the KEV Catalog as an important prioritization signal within their broader vulnerability management process.
A practical approach is to:
- Identify KEV vulnerabilities: Compare the organization’s vulnerability inventory against the current catalog.
- Confirm affected assets: Determine which systems, applications, and versions are actually affected.
- Assess exposure: Prioritize vulnerabilities on internet facing, externally accessible, or otherwise exposed assets.
- Consider asset criticality: Give additional priority to vulnerabilities affecting critical systems, sensitive data, or important business services.
- Check available remediation: Determine whether a vendor patch, mitigation, or workaround is available.
- Prioritize remediation: Address actively exploited vulnerabilities according to organizational risk and response requirements.
- Verify remediation: Rescan or otherwise validate that the vulnerability has been successfully addressed.
- Monitor continuously: Recheck the catalog and vulnerability inventory as new KEV entries are added.
KEV status should generally be treated as a high priority risk signal, but teams should still consider factors such as asset exposure, exploitability, business criticality, and existing compensating controls.
For example, a KEV vulnerability affecting an internet facing production server would typically warrant more urgent attention than the same vulnerability on an isolated system that cannot be reached by the relevant attack path.
Why is the KEV Catalog important?
Traditional vulnerability prioritization often relies heavily on severity scores such as CVSS. While severity is useful, it does not necessarily indicate whether attackers are actively exploiting a vulnerability.
The KEV Catalog adds evidence of real world exploitation to the prioritization process.
It can help teams:
- Identify vulnerabilities being actively exploited
- Prioritize remediation based on observed attacker activity
- Focus limited security resources
- Reduce exposure to known attacks
- Improve vulnerability management workflows
- Support risk based remediation decisions
- Strengthen vulnerability reporting and governance
KEV vs. CVSS
KEV status and CVSS scores provide different types of information.
CVSS evaluates the technical severity of a vulnerability based on defined characteristics.
KEV indicates that there is known evidence of exploitation associated with the vulnerability.
A vulnerability can therefore have a high CVSS score without appearing in the KEV Catalog, while a vulnerability with a lower severity score may deserve urgent attention if it is actively exploited.
Using both signals can provide better prioritization than relying on severity alone.
Common KEV Catalog Use Cases
Vulnerability Prioritization
Teams can use KEV status to identify vulnerabilities that deserve accelerated remediation.
Patch Management
KEV entries can help patch management teams determine which vulnerabilities should be addressed first.
Exposure Management
Organizations can combine KEV status with asset exposure, criticality, and attack path information to identify vulnerabilities that create particularly significant risk.
Risk Reporting
Security leaders can track the number of KEV vulnerabilities present in the environment and monitor remediation progress.
Incident Response
When an organization discovers that an actively exploited vulnerability exists on an exposed asset, the KEV Catalog can provide useful context for determining whether further investigation is necessary.
Challenges of Using the KEV Catalog
The KEV Catalog is a valuable prioritization resource, but it should not be treated as a complete vulnerability management strategy.
Common challenges include:
- Not every exploited vulnerability is listed: Absence from KEV does not mean a vulnerability is safe.
- Large remediation workloads: Organizations may have many affected systems.
- Asset visibility gaps: Teams cannot remediate vulnerabilities they do not know exist.
- Complex dependencies: Patching one system may affect applications or business services.
- Different risk levels: The same KEV vulnerability can create very different risks depending on asset exposure and criticality.
- Rapid changes: New vulnerabilities can become actively exploited quickly.
The Future of KEV Based Prioritization
Vulnerability prioritization is increasingly moving beyond static severity scores toward approaches that combine multiple risk signals.
Future approaches are likely to combine KEV status with:
- Asset criticality
- Internet exposure
- Exploit availability
- Threat intelligence
- Active attack activity
- Attack path analysis
- Compensating controls
- Business impact
This can help security teams determine not only whether a vulnerability is known to be exploited, but where it creates the greatest practical risk within their environment.
Frequently Asked Questions
What are known exploited vulnerabilities?
Why is the KEV list important?
Who maintains the KEV catalog?
How should teams use the KEV list?
How is a KEV flaw different from a high severity flaw?
How does KEV connect to vulnerability management?
Conclusion
The CISA Known Exploited Vulnerabilities Catalog provides organizations with a valuable list of vulnerabilities that are known to be exploited in real world attacks. Teams can use KEV status as a high priority signal alongside asset exposure, criticality, exploitability, and other risk factors. By incorporating the catalog into vulnerability and exposure management workflows, organizations can focus remediation efforts on vulnerabilities with demonstrated exploitation risk.