CyberMax
Home › Glossary › Vulnerability management

What is the KEV catalog?

Vulnerability management glossary · 1 primary source

CISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.

A CVE is added only when three conditions hold: it has a CVE ID, there is reliable evidence it has been actively exploited, and there is clear remediation guidance (such as a vendor update). That makes the catalog a short, high-signal list compared with the hundreds of thousands of CVEs overall.

Each entry has the fields cveID, vendorProject, product, vulnerabilityName, dateAdded, shortDescription, requiredAction, dueDate, knownRansomwareCampaignUse and notes. The catalog is published as CSV and JSON and updated whenever CISA adds entries, often several times a week.

Federal civilian agencies must act on it under CISA's binding directives; for everyone else it is the most widely used free signal of what attackers are using right now.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary