Skip to content
Private Beta ·invite-only access. Reach out to get in.
Back to blog
Threat Intel5 min read·

KEV Catalog Explained: CISA's Known Exploited Vulnerabilities

The KEV catalog is one of the most actionable threat intelligence sources available. Here's how to use it in your vulnerability management workflow.

What Is the KEV Catalog?

CISA's Known Exploited Vulnerabilities (KEV) catalog is a curated list of CVEs that have been confirmed exploited in the wild. Not theoretically exploitable. Not "a proof-of-concept exists." Actually used by attackers against real targets.

As of early 2026, the catalog contains over 1,200 entries. It's updated multiple times per week as new exploitation is confirmed.

Why KEV Matters More Than You Think

Most vulnerability intelligence is probabilistic. CVSS estimates severity. EPSS predicts exploitation likelihood. Threat feeds report indicators of compromise.

KEV is different: it's a confirmed fact. When a CVE appears on the KEV list, it means:

  1. An attacker has used this vulnerability to compromise a real system
  2. CISA has verified the exploitation through reliable sources
  3. The vulnerability has a known remediation (patch or mitigation)

This makes KEV one of the highest-signal, lowest-noise threat intelligence feeds available, and it's completely free.

The BOD 22-01 Mandate

For U.S. federal agencies, KEV isn't optional. Binding Operational Directive 22-01 requires federal civilian agencies to remediate KEV-listed vulnerabilities within specific timeframes:

  • Typically 14 days for newly added vulnerabilities, though CISA can set shorter deadlines based on severity and active exploitation

While this mandate only applies to federal agencies, many private sector organizations have adopted KEV as a prioritization benchmark because the logic is sound: if it's being exploited, patch it.

How to Integrate KEV Into Your Workflow

Priority Override: Any vulnerability on your stack that appears in KEV should jump to the top of your remediation queue, regardless of its CVSS score. A KEV entry with CVSS 6.0 is more urgent than a non-KEV entry with CVSS 9.8.

Gap Analysis: Cross-reference the KEV catalog against your technology inventory. If you find KEV entries affecting technologies you run, you may already have an exposure that needs immediate attention.

Metrics and Reporting: Track your "KEV remediation time" as a security KPI. It's a clear, defensible metric: "We patch known-exploited vulnerabilities within X days."

Supply Chain Awareness: KEV entries often affect widely-used software, Apache, Microsoft, Google, Citrix. If your vendors' products appear on KEV, that's a conversation to have with them about their patch timelines.

Common KEV Patterns

Looking at the catalog's history, several patterns emerge:

  • VPN and edge devices are heavily represented (Fortinet, Palo Alto, Cisco, Ivanti)
  • Web server and CMS vulnerabilities appear frequently (Apache, WordPress, Drupal)
  • Serialization and injection flaws are the most common vulnerability types
  • Time-to-exploitation is shrinking, many CVEs land on KEV within days of disclosure

How We Use KEV

On our platform, KEV status is a first-class signal. When a CVE lands on the KEV catalog and it affects your declared stack, you get an immediate priority alert, regardless of CVSS or EPSS scores. We also monitor the catalog for additions and cross-reference them against all user profiles automatically.

The Bottom Line

If you do nothing else for vulnerability management, monitor the KEV catalog against your stack. It's free, it's authoritative, and it tells you exactly which vulnerabilities are being used by attackers right now.

Stay ahead of threats

Get AI-filtered CVE alerts for your specific tech stack. Free to start.

Start for free