CISA KEV (Known Exploited Vulnerabilities Catalog)
CISA KEV (Known Exploited Vulnerabilities Catalog) is an authoritative, regularly updated list maintained by the U.S. cybersecurity agency CISA of CVEs that have confirmed evidence of active exploitation in the wild.
The CISA KEV catalog is a curated list of vulnerabilities for which there is reliable evidence of real-world exploitation. Unlike a predictive score, KEV is a binary, evidence-based signal: a CVE is either on the list (confirmed exploited) or it is not. Each entry includes the CVE ID, a short description, the date it was added, and a required remediation due date for U.S. federal agencies.
CISA adds a vulnerability only when there is trustworthy evidence of active exploitation and a clear remediation action exists. Because inclusion requires observed attacks, KEV membership is one of the strongest single indicators that a flaw demands immediate attention.
For developers and security teams, KEV acts as a high-confidence 'fix this now' flag. A vulnerability that is present in your dependencies and appears on the KEV list has moved from theoretical to actively weaponized, which is why prioritization models weight KEV status heavily alongside severity and exploit probability.