Zennoxa Shield
Application Security Glossary

CISA KEV (Known Exploited Vulnerabilities Catalog)

CISA KEV (Known Exploited Vulnerabilities Catalog) is an authoritative, regularly updated list maintained by the U.S. cybersecurity agency CISA of CVEs that have confirmed evidence of active exploitation in the wild.

The CISA KEV catalog is a curated list of vulnerabilities for which there is reliable evidence of real-world exploitation. Unlike a predictive score, KEV is a binary, evidence-based signal: a CVE is either on the list (confirmed exploited) or it is not. Each entry includes the CVE ID, a short description, the date it was added, and a required remediation due date for U.S. federal agencies.

CISA adds a vulnerability only when there is trustworthy evidence of active exploitation and a clear remediation action exists. Because inclusion requires observed attacks, KEV membership is one of the strongest single indicators that a flaw demands immediate attention.

For developers and security teams, KEV acts as a high-confidence 'fix this now' flag. A vulnerability that is present in your dependencies and appears on the KEV list has moved from theoretical to actively weaponized, which is why prioritization models weight KEV status heavily alongside severity and exploit probability.

Frequently asked questions

What is the CISA KEV catalog?
It is a list published by CISA of CVEs with confirmed evidence of active exploitation in the wild. Being on the KEV list is a strong signal that a vulnerability is being attacked now and should be remediated urgently.
How does a vulnerability get added to CISA KEV?
CISA adds a CVE when there is reliable evidence of active exploitation and a defined remediation action is available. Each entry carries an added date and a remediation due date for federal agencies.
CISA KEV vs EPSS — how are they different?
KEV is a binary, evidence-based flag confirming exploitation has been observed, while EPSS is a probabilistic prediction of future exploitation. KEV says 'it is happening'; EPSS says 'how likely it is to happen.'

Related terms

CISA KEV (Known Exploited Vulnerabilities Catalog) — Zennoxa Glossary — Zennoxa Shield