What does "known ransomware campaign use" mean in KEV?
A KEV catalog field (knownRansomwareCampaignUse) set to "Known" when CISA has evidence the CVE was used in a ransomware campaign, otherwise "Unknown".
"Unknown" does not mean the CVE is safe from ransomware, only that CISA has not confirmed such use. Teams often patch "Known" entries first among their KEV backlog, because ransomware operators turn access into outages quickly.
Sources
Related terms
- KEV catalogCISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.
- EPSSExploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.