Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Government

CISA's KEV Catalog: What It Is and Why It Matters

CISA's Known Exploited Vulnerabilities (KEV) catalog is the US government's definitive list of security flaws being actively used in real-world attacks.

By · Published · 11 min read

A single server rack in a modern, dark data center is brightly illuminated, highlighting it as a critical asset among rows of other servers.

CISA's Known Exploited Vulnerabilities (KEV) catalog is a curated list of security flaws that have been confirmed as being actively exploited by attackers in the wild. Maintained by the US Cybersecurity and Infrastructure Security Agency, it serves as a mandatory directive for federal agencies to remediate these specific, high-priority vulnerabilities within a given timeframe, but it has become an essential resource for all organizations seeking to prioritize their patching efforts.

What Exactly Is the KEV Catalog?

The KEV catalog was established under Binding Operational Directive (BOD) 22-01, issued in November 2021. This directive requires Federal Civilian Executive Branch (FCEB) agencies to patch all vulnerabilities listed in the catalog by their assigned due dates. It represents a fundamental shift in the government's approach to vulnerability management, moving from a model based purely on potential severity to one based on confirmed, real-world threats.

The core principle of the KEV is prioritization through evidence. The security landscape is flooded with thousands of new vulnerabilities discovered each month. It's impossible for any organization, no matter its size, to patch everything immediately. The KEV cuts through this noise by providing a focused, actionable list. If a vulnerability is on this list, it means CISA or its partners have credible proof that malicious actors are already using it to compromise systems.

For FCEB agencies, compliance is not optional. They must regularly scan their networks for KEV vulnerabilities and remediate them by the deadline, which is typically a few weeks from the date the vulnerability is added. While the directive does not apply to private companies, the KEV catalog is publicly available and serves as a powerful, free source of threat intelligence for the entire cybersecurity community.

How a Vulnerability Gets on the KEV List

CISA has a clear and straightforward set of criteria for adding a vulnerability to the KEV catalog. A flaw must meet two conditions:

  1. It must have a Common Vulnerabilities and Exposures (CVE) identifier. The CVE system provides a unique, standardized name for each publicly known vulnerability, allowing everyone to talk about the same issue using a common reference (e.g., CVE-2023-12345).
  1. There must be reliable evidence of active exploitation. This is the key differentiator. CISA must have seen or received credible reports that attackers are actively using the vulnerability. This evidence can come from a variety of sources, including CISA's own incident response activities, security vendors, threat intelligence firms, academic researchers, and open-source reporting from trusted international partners.

What's notably absent from this list is a minimum severity score. A vulnerability does not need a high or critical Common Vulnerability Scoring System (CVSS) score to be included. While high-impact flaws are common on the list, CISA will also add lower-rated vulnerabilities if they are being exploited at scale. For example, a medium-severity flaw that is extremely easy to exploit and allows an attacker to gain an initial foothold might be added to the KEV long before a complex, critical-severity flaw that has no known public exploit. This focus on real-world exploitation is what makes the KEV so practical. To learn more about how these ratings work, see our guide on CVSS scores explained.

KEV vs. CVE vs. CVSS: Understanding the Difference

It's easy to get lost in the alphabet soup of cybersecurity terminology. Understanding the distinct roles of CVE, CVSS, and KEV is crucial for building a mature vulnerability management program.

TermWhat It IsPurposeAnalogy
CVEA unique ID for a vulnerabilityTo create a standard dictionary of all known vulnerabilities, preventing confusion.A unique serial number for a faulty car part.
CVSSA score from 0.0 to 10.0To measure the potential technical severity of a vulnerability if it were exploited.The mechanic's rating of how dangerous the faulty part could be (e.g., 'engine failure').
KEVA curated catalog of vulnerabilitiesTo identify which vulnerabilities are actually being exploited by attackers right now.A government recall notice for car parts that are confirmed to be failing on the road.

Think of it this way: The CVE database is a massive dictionary of every potential problem. The CVSS score tells you how bad each problem *could* be in theory. The KEV catalog is the short, urgent list of problems that are *actually happening* right now and causing crashes.

Why the KEV Catalog Matters to Everyone

The KEV catalog may be a directive for federal agencies, but its influence and utility extend far beyond the government. For private sector organizations, from small businesses to large enterprises, it's one of the most valuable free tools available for cyber defense.

A Powerful Tool for Prioritization For most security teams, the primary challenge is not a lack of information, but an overwhelming abundance of it. A typical vulnerability scanner might flag thousands of issues, many with high or critical CVSS scores. The KEV provides an immediate, data-driven way to prioritize. Instead of asking "What's the most severe?" teams can ask "What's being exploited?" This focuses limited resources on the threats most likely to cause a breach.

Free, High-Fidelity Threat Intelligence Threat intelligence feeds can be expensive. The KEV is a free, constantly updated feed of validated intelligence from one of the world's leading cybersecurity agencies. When a new vulnerability appears on the list, such as the recent [exploited Citrix NetScaler zero-days](/posts/citrix-netscaler-zero-days-cisa-alert), it's a clear signal that attackers have developed a working exploit and are actively deploying it. This insight allows defenders to react quickly to emerging campaigns.

A Benchmark for 'Good Enough' While federal agencies must comply, private companies can use the KEV deadlines as a benchmark for their own performance. If your organization's patching cadence is significantly slower than the two or three weeks mandated for federal agencies, it may be a sign that your processes are not agile enough to keep pace with modern threats. Striving to meet the KEV deadlines is a good goal for any mature security program.

Justification for Action Security professionals often struggle to get buy-in from IT operations or business leaders for emergency, out-of-band patching, which can be disruptive. Pointing to a vulnerability's inclusion in the KEV catalog provides powerful justification. It's no longer just the security team's opinion; it's a formal warning from the US government about a clear and present danger.

Integrating KEV into Your Security Operations

Adopting the KEV catalog is not just about reading the list; it's about integrating it into your daily security operations. A well-designed patch management process is the foundation for this integration.

Here’s how organizations can operationalize the KEV:

  • Subscribe and Monitor: CISA provides multiple ways to stay informed about KEV updates, including email alerts and a machine-readable JSON feed. Ensure your team is subscribed and has a process for reviewing new additions daily.
  • Automate Ingestion: Most modern vulnerability management platforms (e.g., Tenable, Qualys, Rapid7) can automatically ingest the KEV feed. They can then tag or flag assets in your environment that are affected by a known exploited vulnerability, making them instantly visible on dashboards.
  • Establish a KEV-Specific SLA: Create a dedicated Service Level Agreement (SLA) for remediating KEV vulnerabilities. This SLA should be much more aggressive than your standard patching timelines. While the federal deadline is a good starting point, aim to patch even faster if possible.
  • Drive Emergency Patching: When a new KEV vulnerability is discovered on your network, it should trigger an emergency patching workflow. This process bypasses normal testing and deployment cycles to get the fix applied as quickly as possible.
  • Enhance Incident Response: Your incident response plan should treat the presence of an unpatched KEV vulnerability as a potential indicator of compromise. If a system has been vulnerable for a period of time, it should be prioritized for forensic analysis to search for signs of malicious activity. After all, unpatched software is one of the primary ways how data breaches happen.

Building a KEV-Informed Defense

Ultimately, CISA's KEV catalog is more than just a list—it's a strategic tool that empowers defenders to work smarter, not just harder. By focusing on confirmed threats, organizations can break free from the overwhelming cycle of chasing every new CVE and allocate their most valuable resources—time and people—to fixing the problems that matter most. Building a program around this data-driven approach is a significant step toward a more resilient and proactive security posture.

To effectively leverage the KEV, follow these steps:

  1. Know Your Assets: Maintain a comprehensive and continuously updated inventory of all hardware and software assets in your environment. You cannot protect what you do not know you have.
  1. Scan Continuously: Implement an authenticated vulnerability scanning program that runs frequently. Your ability to detect a new KEV vulnerability is limited by how often you scan for it.
  1. Define a Process: Create a formal, documented process for what happens when a KEV vulnerability is found. Who is notified? Who is responsible for patching? What is the escalation path if the deadline is missed?
  1. Verify and Report: After a patch is deployed, run a verification scan to confirm that the vulnerability has been successfully remediated. Use dashboards to track your organization's compliance with KEV deadlines and report the status to leadership.

By embracing the KEV catalog, organizations of all sizes can align their defensive efforts with the real-world tactics of attackers, transforming their vulnerability management from a reactive chore into a proactive, intelligence-led discipline.

Read next