Cisa Kev
| Name | CISA Known Exploited Vulnerabilities (KEV) Catalog |
|---|---|
| First created | 2021 |
| Maintained by | Cybersecurity and Infrastructure Security Agency (CISA) |
| Purpose | Catalog of vulnerabilities with known, active exploitation |
| Scope | Primarily software vulnerabilities affecting U.S. federal civilian agencies |
| Update frequency | Regularly, as new exploited vulnerabilities are identified |
| Mandatory action | Binding Operational Directive (BOD) 22-01 requires federal agencies to patch listed vulnerabilities on defined timelines |
Origin and history
CISA KEV originates from the United States and was first formally launched and documented in the early 2020s. It was created by the Cybersecurity and Infrastructure Security Agency (CISA), a federal agency established in 2018. The framework was developed in direct response to the escalating frequency and impact of cyber attacks against critical infrastructure and major enterprises. Its creation was informed by ongoing analysis of real-world exploitation data gathered from government and industry partners. The initial list was built upon foundational concepts of vulnerability prioritization that had been discussed within the cybersecurity community for the preceding decade. The publication of the KEV catalog represents a significant shift towards a more authoritative and actionable form of vulnerability management guidance.
What it is for
CISA KEV is a public catalog of Known Exploited Vulnerabilities that carry significant risk to federal civilian agencies. Its primary purpose is to mandate and standardize the patching timeline for these specific vulnerabilities within the U.S. federal government. The framework serves as a definitive filter, separating vulnerabilities that are merely theoretically severe from those that are actively being used in attacks. It provides organizations with a prioritized to-do list for remediation, directly addressing the common problem of vulnerability overload. By focusing on proven exploitation, it aims to force defensive resources toward the most immediate and tangible threats. The catalog is also designed as a resource for all organizations worldwide to improve their defensive posture by aligning their patching efforts with observed adversary behavior.
Pros and cons
A major pro of the CISA KEV framework is its clarity and actionability, removing subjective debate about which vulnerabilities to patch first for covered entities. It is based on empirical evidence of exploitation, making it a highly reliable indicator of genuine threat, unlike tools that rely solely on theoretical severity scores. The framework's binding nature for federal agencies creates a powerful forcing function that has raised the baseline security posture across a large ecosystem. A significant con is that it is inherently reactive, as a vulnerability only enters the catalog after exploitation is confirmed, leaving a window where organizations relying solely on KEV are unprotected from zero-days. Organizations outside the U.S. federal mandate often mistakenly treat KEV as a comprehensive list, potentially neglecting critical vulnerabilities that are being exploited but have not yet been formally cataloged by CISA. Another common regret comes from organizations that implement the KEV patches but then consider their job complete, failing to integrate it with a broader, proactive vulnerability management program that addresses other risk factors.
Who it suits
The CISA KEV framework is specifically suited for U.S. federal civilian executive branch agencies, for whom it is a binding directive. It is highly effective for any resource-constrained security team that needs a clear, authoritative prioritization schema to cut through the noise of thousands of reported vulnerabilities. Large enterprises and critical infrastructure operators find it invaluable as a baseline for aligning their patching schedules with the most pressing threats. The framework also suits managed security service providers and auditors who require a standardized, evidence-based benchmark for assessing client security postures. It is less suited for highly advanced, intelligence-driven security teams that require predictive threat hunting, as KEV is a trailing indicator. Organizations operating in highly targeted sectors may need to use KEV as a floor, not a ceiling, supplementing it with additional threat intelligence to address threats specific to their industry.
Latest Cisa Kev news
Latest reporting

CISA Releases 2026 Election Infrastructure Security Plan
CISA has published a 13-page Election Infrastructure Security Plan 40 days before the November 2026 midterms, offering guidance against cyber and...

CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The U.S. Cybersecurity agency CISA has mandated patching for three actively exploited Linux kernel vulnerabilities, including a critical flaw with a...

CISA Issues Guidance on Deploying Cyber Decoy Systems
The U.S. Cybersecurity and Infrastructure Security Agency has released new guidance for critical infrastructure operators on deploying decoy systems...

CISA Updates Insider Threat Mitigation Guide
CISA has revised its Insider Threat Mitigation Guide with new case studies and guidance addressing hybrid work, AI deception, and employee...

CISA Director Warns of Critical Vulnerabilities, Urges Rapid
Acting CISA Director Nick Andersen warns that decades of bad decisions and overwhelming technical debt have left the U.S.

Mars Security automates threat intelligence
Mars Security has launched a real-time detection capability that automatically converts threat advisories from sources like CISA and Mandiant into...