GlossaryAttack surface and pentesting

KEV catalogue

Short answer

The KEV catalogue (Known Exploited Vulnerabilities) is a public list maintained by the US agency CISA of vulnerabilities with reliable evidence of active exploitation. It has become a widely used reference for deciding which vulnerabilities to patch first. It is free to consult and download.

What gets a vulnerability on the list

CISA adds a vulnerability when it has a CVE identifier, there is reliable evidence that it is being exploited in real attacks, and there is clear guidance to fix it, such as a vendor patch or mitigation. Each entry includes the affected product, a short description, the required action and a due date.

Origin and scope

CISA created the catalogue in 2021, together with a directive that requires US federal civilian agencies to remediate listed vulnerabilities within set deadlines. Outside the US government it has no legal force, but security teams around the world, including in Europe, use it as a strong prioritisation signal. It is free to consult and download on the CISA website.

How to use it

Treat any listed vulnerability on your systems as a priority, especially on internet facing systems such as VPN gateways, firewalls and file transfer tools, which appear frequently. Many scanners flag KEV entries automatically. Combine it with EPSS for vulnerabilities that are not yet on the list.

Limits

The catalogue only includes vulnerabilities for which CISA has evidence of exploitation, so absence from the list is not proof of safety. It is one input to vulnerability management, not a replacement for it.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub