The Known Exploited Vulnerabilities catalog is the list CISA uses to tell US federal agencies what to fix first. It started in November 2021 with Binding Operational Directive 22-01 and has grown by a few entries almost every week since. Each entry has a vendor, a product, a short description, the action required, the date it was added and a due date.
Why it is the first sort key here
An entry in KEV is an observation, not a prediction: someone was attacked through that vulnerability and CISA could verify it. Studies by FIRST and others show that only a small share of published CVEs is ever exploited, so knowing which ones are is worth more than any severity score.
Reading an entry
- Date added is when CISA listed it, which can be years after the CVE was published. Old vulnerabilities enter the catalog when exploitation is noticed.
- Due date is mandatory only for US federal civilian agencies. Recent entries often give a few days; older ones typically gave two or three weeks.
- Ransomware use: known marks entries CISA has tied to ransomware campaigns.
- Required action, shown on each CVE page, is CISA’s text: usually to apply the vendor’s mitigation or stop using the product.
Its limits
The catalog is not a list of everything exploited in the world. It needs a CVE ID, verifiable evidence and an available remediation, and it reflects what matters to the networks CISA protects. Treat presence in KEV as a strong reason to act and absence as no information.