What is the CISA KEV catalog?
The CISA Known Exploited Vulnerabilities catalog is a public list of CVEs with confirmed evidence of exploitation in the wild. It was established by US Binding Operational Directive 22-01 and sets remediation deadlines that federal civilian agencies must meet. Because entries require observed exploitation rather than theoretical severity, KEV is one of the strongest available signals that a vulnerability needs attention now.
KEV is deliberately conservative. A CVE only appears once there is reliable evidence it has actually been used against real targets, which makes inclusion a much stronger signal than a high severity score.
The catalog is binding for US federal civilian agencies, but its practical use is far wider: any organisation can treat "is it in KEV?" as a first-pass filter that turns an unmanageable vulnerability backlog into a short, ranked list.
The obvious limitation is coverage. KEV lists what has been observed and reported, so absence from it is not evidence of safety — only that exploitation has not been confirmed publicly.
Related coverage
CVE & Vulnerabilitiesdispatches →Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
More on prioritisation