DefinitionKEV (Known Exploited Vulnerabilities) is the public catalog from CISA, the United States cybersecurity agency, listing vulnerabilities with confirmed evidence of real-world exploitation. It is used as a top-urgency signal for remediation.
How it works
The catalog was created in 2021, along with Binding Operational Directive BOD 22-01, which requires US federal civilian agencies to fix listed flaws within set deadlines. To be added to KEV, a vulnerability must meet three criteria:
- It has an assigned CVE identifier.
- There is reliable evidence of active exploitation.
- There is clear remediation guidance, such as a vendor update.
Each entry lists the CVE, the affected product, the required action, the date added and the remediation deadline for agencies. The catalog also flags known use in ransomware campaigns.
KEV vs EPSS
EPSS is a prediction: it estimates the likelihood of exploitation in the next 30 days. KEV is an observation: it only includes flaws that have already been exploited. That is why KEV is smaller and more conservative, and EPSS helps anticipate what has not reached it yet. CVSS, in turn, measures technical severity, with no information about exploitation.
In practice
Companies outside the US government are not subject to BOD 22-01, but they can use KEV as a defensible urgency benchmark. The most common rule is simple: a flaw that is in KEV and exists in your environment goes to the top of the queue. Applying this rule requires an up-to-date inventory; without it, KEV is just a news feed.
Network Secure offers Vulnerability Management as a continuous service.
Frequently asked questions
Does KEV apply to companies outside the US?
It creates no obligation outside the US federal government, but it is public and widely used as a prioritization reference by companies in any country.
If a flaw is not in KEV, does that mean it is not exploited?
Not necessarily. KEV only lists confirmed exploitation that meets its criteria. Flaws outside it may be exploited without public evidence, so it is worth combining it with EPSS and threat intelligence.