What gets a vulnerability on the list
CISA adds a vulnerability when it has a CVE identifier, there is reliable evidence that it is being exploited in real attacks, and there is clear guidance to fix it, such as a vendor patch or mitigation. Each entry includes the affected product, a short description, the required action and a due date.
Origin and scope
CISA created the catalogue in 2021, together with a directive that requires US federal civilian agencies to remediate listed vulnerabilities within set deadlines. Outside the US government it has no legal force, but security teams around the world, including in Europe, use it as a strong prioritisation signal. It is free to consult and download on the CISA website.
How to use it
Treat any listed vulnerability on your systems as a priority, especially on internet facing systems such as VPN gateways, firewalls and file transfer tools, which appear frequently. Many scanners flag KEV entries automatically. Combine it with EPSS for vulnerabilities that are not yet on the list.
Limits
The catalogue only includes vulnerabilities for which CISA has evidence of exploitation, so absence from the list is not proof of safety. It is one input to vulnerability management, not a replacement for it.




