Vulnerability management glossary
The identifiers, scores and federal deadlines behind "which CVE do we patch first": CVE and NVD records, CVSS and EPSS scores, CISA's Known Exploited Vulnerabilities catalog and the binding directives that set its due dates. Each entry links CISA, NIST, FIRST or the CVE Program.
- CVECommon Vulnerabilities and Exposures: the public ID system for disclosed security flaws, written as CVE-YEAR-NUMBER, for example CVE-2021-44228.
- CNA (CVE Numbering Authority)An organisation authorised by the CVE Program to assign CVE IDs and publish CVE records for vulnerabilities in its scope.
- KEV catalogCISA's Known Exploited Vulnerabilities catalog: the list of CVEs with reliable evidence of exploitation in the wild, each with a required action and a due date.
- KEV due dateThe dueDate field on a KEV catalog entry: the deadline by which US federal civilian agencies must apply the required action for that CVE.
- BOD 22-01CISA Binding Operational Directive 22-01 (November 2021), which created the KEV catalog and required federal agencies to fix listed CVEs by set deadlines. It was revoked on 10 June 2026 by BOD 26-04.
- BOD 26-04CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.
- Known ransomware campaign useA KEV catalog field (knownRansomwareCampaignUse) set to "Known" when CISA has evidence the CVE was used in a ransomware campaign, otherwise "Unknown".
- CVSSCommon Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.
- EPSSExploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.
- NVDThe National Vulnerability Database run by NIST, which republishes CVE records and adds analysis such as CVSS scores, CWE types and CPE product names.
- CPECommon Platform Enumeration: a structured name for a product and version, used to match CVEs to the software you run.
- CWECommon Weakness Enumeration: the catalogue of software and hardware weakness types, such as CWE-79 (cross-site scripting) or CWE-787 (out-of-bounds write).
- SSVCStakeholder-Specific Vulnerability Categorization: a decision-tree method that turns a few facts about a vulnerability into an action, such as Track, Attend or Act.