← All Terms

Known Exploited Vulnerabilities

KEV

CISA's public catalogue of software flaws with reliable evidence of active exploitation, used as a priority list for patching.

Governance & Risk

The Known Exploited Vulnerabilities catalogue is a list maintained by the US Cybersecurity and Infrastructure Security Agency of flaws that attackers are confirmed to be using. A flaw joins the list when there is reliable evidence of exploitation in the wild and a clear remediation, such as a patch or a vendor workaround.

Its value is focus. Tens of thousands of CVEs are published each year, and most are never exploited. KEV narrows the list to the ones that are, and US federal agencies are required to fix them by set deadlines. Under BOD 26-04, issued in June 2026, those deadlines fall to as little as three days for exposed systems where the flaw gives an attacker total control.

For organisations outside the US government, KEV is still the most defensible trigger for reopening an accepted risk. Once a deferred flaw appears on the list, the argument that nobody is exploiting it no longer holds.