What is the KEV catalog?
CISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.
A CVE is added only when three conditions hold: it has a CVE ID, there is reliable evidence it has been actively exploited, and there is clear remediation guidance (such as a vendor update). That makes the catalog a short, high-signal list compared with the hundreds of thousands of CVEs overall.
Each entry has the fields cveID, vendorProject, product, vulnerabilityName, dateAdded, shortDescription, requiredAction, dueDate, knownRansomwareCampaignUse and notes. The catalog is published as CSV and JSON and updated whenever CISA adds entries, often several times a week.
Federal civilian agencies must act on it under CISA's binding directives; for everyone else it is the most widely used free signal of what attackers are using right now.
Sources
Related terms
- KEV due dateThe dueDate field on a KEV catalog entry: the deadline by which US federal civilian agencies must apply the required action for that CVE.
- BOD 26-04CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.
- Known ransomware campaign useA KEV catalog field (knownRansomwareCampaignUse) set to "Known" when CISA has evidence the CVE was used in a ransomware campaign, otherwise "Unknown".
- EPSSExploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.