CISA KEV (Known Exploited Vulnerabilities)
The CISA Known Exploited Vulnerabilities (KEV) catalogue is a curated list of CVEs that CISA has confirmed are being actively exploited in the wild. It is a high-signal patch-first list, but it is not exhaustive. Many mass-exploited CVEs are never added.
KEV is one of the strongest prioritisation signals available: if a CVE is in KEV, it is confirmed exploited, and US federal agencies are bound to remediate it on a deadline.
But KEV has a coverage gap. Shadowserver honeypot telemetry shows hundreds of CVEs under active mass-exploitation that are not in CISA KEV, which is why leading teams use both lists.
The KEV catalogue is maintained by the US Cybersecurity and Infrastructure Security Agency and lists vulnerabilities for which reliable evidence of active exploitation exists. Unlike a severity score, which is an estimate of potential impact, KEV is a statement of fact: these specific vulnerabilities are being used in real attacks. That certainty makes it one of the most valuable prioritisation signals available.
For US federal agencies, KEV is more than advisory. A binding operational directive requires them to remediate listed vulnerabilities within set deadlines, which has made the catalogue a de facto standard that many private organisations also adopt. Treating KEV entries as must-fix, regardless of their CVSS score, is a simple and effective prioritisation rule.
KEV is powerful precisely because it is narrow. Of the tens of thousands of published CVEs, only a small fraction ever appear in the catalogue, which is what makes it useful: it separates the vulnerabilities that attackers genuinely use from the vast majority that they ignore. A high CVSS score with no KEV listing and a low EPSS probability is often a lower priority than a moderate-severity flaw that is actively exploited.
The catalogue is most effective as one input among several. Combined with EPSS probability and CVSS severity, it lets a team build a prioritisation model that reflects confirmed exploitation, predicted likelihood and potential impact together, which is the basis of risk-based vulnerability management and continuous exposure management programmes.
A vulnerability is added to the KEV catalogue when CISA has reliable evidence that it is being actively exploited, along with an assigned CVE identifier and a clear remediation path. This evidence-based threshold is deliberately high, which is why the catalogue stays small and trustworthy: an entry is not a prediction or an estimate but a confirmation that attacks are happening, which is exactly what makes it such a strong prioritisation signal.
Although the binding remediation deadlines apply only to US federal agencies, the catalogue has been widely adopted well beyond government. Private organisations of all kinds use it as a straightforward, authoritative must-fix list, and many vulnerability tools now flag KEV status automatically. Treating every KEV entry present in your environment as a priority, regardless of its CVSS score, is one of the simplest high-value rules in vulnerability management.
Precursor’s Known Exploited Vulnerabilities view unifies CISA KEV with Shadowserver honeypot-observed exploitation, surfacing the CVEs exploited in the wild that CISA KEV misses.