Skip to main content
VulnerabilitiesUpdated September 3, 2026

KEV (CISA Known Exploited Vulnerabilities)

The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.

KEV is the shortest list in vulnerability management and the most important. CISA adds a CVE when it has reliable evidence of exploitation in the wild, the vulnerability has a CVE identifier, and there is clear remediation guidance. Each entry carries a date added and a due date by which US federal agencies must act.

The catalog is small by design, in the low thousands against a quarter of a million CVEs, which is what lets a team work through it. If a vulnerability is in KEV, someone is already using it against real targets; the debate about whether it will be exploited is over. Many organisations outside the US federal government treat the KEV due dates as their own.

CVSS, EPSS and KEV answer three different questions. CVSS asks how bad the vulnerability would be if exploited, and gives a severity from 0 to 10 that never changes once published. EPSS asks how likely it is to be exploited in the next 30 days, and gives a probability that is recomputed daily as exploitation evidence arrives. KEV asks whether it is already being exploited, and gives a yes or no from CISA. A CVSS 9.8 with an EPSS of 0.4 % and no KEV entry is a theoretical emergency; a CVSS 6.5 in the KEV catalog is a practical one. Prioritisation that uses only the first number patches the wrong things first.

Example

A CVE sits at CVSS 7.2 and EPSS 3 % for a year, then appears in KEV with a three-week due date. Nothing about the bug changed; what changed is that it is now being used. The KEV entry is the trigger to move it to the top of the queue.

In isMalicious

CVE pages on isMalicious flag KEV membership with the date added and the due date, and CVE Watch raises a finding when a product in a monitored environment matches a CVE that enters the catalog.

Frequently Asked Questions

What is KEV (CISA Known Exploited Vulnerabilities)?

The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.

How is KEV (CISA Known Exploited Vulnerabilities) related to CVE (Common Vulnerabilities and Exposures)?

KEV (CISA Known Exploited Vulnerabilities) and CVE (Common Vulnerabilities and Exposures) are both key concepts in threat intelligence. CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary