Definition ยท Known Vulnerabilities (CVEs)
What is KEV Catalogue?
The Known Exploited Vulnerabilities (KEV) catalogue is published by CISA, the US Cybersecurity and Infrastructure Security Agency. It lists CVE identifiers for which CISA has reliable evidence that the vulnerability has been actively exploited, together with the affected vendor and product, a required action, and a due date. It was established by Binding Operational Directive 22-01 in November 2021.
Inclusion criteria
A vulnerability is added when it meets three conditions:
- It has an assigned CVE ID
- There is reliable evidence of active exploitation in the wild
- There is a clear remediation action available, such as a vendor patch or a supported mitigation
This makes KEV deliberately conservative. Absence from the catalogue means CISA has not confirmed exploitation, not that a vulnerability is safe.
Why it matters outside US government
The due dates are enforceable only against federal civilian executive branch agencies, but the underlying signal is useful to anyone: these are the flaws attackers are demonstrably using. Many organisations adopt KEV as a hard prioritisation rule โ anything on the list that is internet-facing goes to the front of the queue regardless of its CVSS score.
Combining KEV with other signals
KEV is a binary, retrospective signal. EPSS complements it with a forward-looking probability for vulnerabilities not yet known to be exploited, and CVSS still describes what an attacker would gain. A practical ordering is KEV first, then high-EPSS items on exposed assets, then everything else by severity.
Related concepts
KEV entries are drawn from the NVD and CVE record set, describe flaws with working exploits โ often former zero-days โ and drive patch management deadlines as part of vulnerability management.