KEV (CISA Known Exploited Vulnerabilities)
The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.
KEV is the shortest list in vulnerability management and the most important. CISA adds a CVE when it has reliable evidence of exploitation in the wild, the vulnerability has a CVE identifier, and there is clear remediation guidance. Each entry carries a date added and a due date by which US federal agencies must act.
The catalog is small by design, in the low thousands against a quarter of a million CVEs, which is what lets a team work through it. If a vulnerability is in KEV, someone is already using it against real targets; the debate about whether it will be exploited is over. Many organisations outside the US federal government treat the KEV due dates as their own.
CVSS, EPSS and KEV answer three different questions. CVSS asks how bad the vulnerability would be if exploited, and gives a severity from 0 to 10 that never changes once published. EPSS asks how likely it is to be exploited in the next 30 days, and gives a probability that is recomputed daily as exploitation evidence arrives. KEV asks whether it is already being exploited, and gives a yes or no from CISA. A CVSS 9.8 with an EPSS of 0.4 % and no KEV entry is a theoretical emergency; a CVSS 6.5 in the KEV catalog is a practical one. Prioritisation that uses only the first number patches the wrong things first.
Example
A CVE sits at CVSS 7.2 and EPSS 3 % for a year, then appears in KEV with a three-week due date. Nothing about the bug changed; what changed is that it is now being used. The KEV entry is the trigger to move it to the top of the queue.
In isMalicious
CVE pages on isMalicious flag KEV membership with the date added and the due date, and CVE Watch raises a finding when a product in a monitored environment matches a CVE that enters the catalog.
Frequently Asked Questions
What is KEV (CISA Known Exploited Vulnerabilities)?
The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.
How is KEV (CISA Known Exploited Vulnerabilities) related to CVE (Common Vulnerabilities and Exposures)?
KEV (CISA Known Exploited Vulnerabilities) and CVE (Common Vulnerabilities and Exposures) are both key concepts in threat intelligence. CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.
Related Terms
CVE (Common Vulnerabilities and Exposures)
CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.
EPSS (Exploit Prediction Scoring System)
EPSS is a data-driven model from FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Scores range from 0 to 1 (0%–100%). EPSS helps prioritize patching by combining NVD data with real-world exploitation observations.
CVSS (Common Vulnerability Scoring System)
CVSS is an open framework for communicating the severity of software vulnerabilities. A CVSS v3 base score from 0 to 10 reflects factors like attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. Scores ≥ 9.0 are Critical; ≥ 7.0 are High.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.