Skip to content

CISA KEV (Known Exploited Vulnerabilities)

Definition

The CISA KEV catalogue is a list maintained by the US agency CISA of vulnerabilities proven to be exploited in real attacks, each with a remediation due date.

Also known asKEVKnown Exploited Vulnerabilities CatalogCISA catalogue

Updated:

Fix firstsorted by risk
1CVE-2024-21762vpn.beispiel-gmbh.atKEV
2CVE-2024-21410mail.beispiel-gmbh.atKEV
3TLS 1.0 enabledshop.beispiel-gmbh.atMedium

Visuals show sample data.

How blacklens.io covers this

The CISA KEV catalogue (Known Exploited Vulnerabilities) is a list maintained by the US Cybersecurity and Infrastructure Security Agency (CISA) of vulnerabilities for which exploitation in real attacks has been confirmed. Each entry contains the CVE number, vendor, product, a short description, the date added, a remediation due date for US federal agencies and, since 2023, an indication of whether the vulnerability is used in ransomware campaigns.

Why CISA KEV matters

The catalogue is deliberately small: it covers only a fraction of all CVEs, but exactly the ones attackers actually use. For prioritisation this is the most reliable statement available, because unlike a prediction (EPSS), KEV describes an observed fact. If a vulnerability is in the catalogue and affects a system reachable from the internet, there is no good reason to wait. Even though the due dates formally apply only to US agencies, auditors, insurers and regulators in Europe use the catalogue as the benchmark for what "state of the art" means in vulnerability management.

How the KEV catalogue works

CISA adds a vulnerability when three criteria are met: a CVE number exists, there is reliable evidence of active exploitation, and there is clear remediation guidance (patch, workaround or decommissioning). The basis is Binding Operational Directive 22-01 of November 2021, which obliges US federal agencies to remediate KEV entries within the set deadline. The catalogue is extended continuously, often several times a week, and is freely available as JSON and CSV. The field "known ransomware campaign use" shows whether the entry is associated with ransomware.

How blacklens.io uses CISA KEV

blacklens.io flags every finding with a CVE that is listed in the KEV catalogue, including the date added, remediation due date and ransomware flag. The KEV status feeds into prioritisation together with EPSS, exploit availability and CVSS and can be used as a filter in every list and in BQL queries. Because new CVEs are matched in real time against your technology inventory, a vulnerability newly added to the catalogue that affects one of your products appears shortly afterwards as a threat in the Threat Center and is verified there automatically.

Does CISA KEV apply to companies in Austria and Germany?

Legally the catalogue is binding only for US federal agencies. Technically it is relevant worldwide, because attackers know no borders. Many European companies use the KEV due dates as an internal SLA for remediation.

How does KEV differ from EPSS?

KEV is a binary, evidenced statement: this vulnerability is being exploited. EPSS is a probability for all CVEs, including those where no exploitation has been observed yet. KEV is more precise, EPSS earlier. Together they cover both cases.

What should you do when a KEV vulnerability appears in your inventory?

Identify affected systems, check reachability from the internet, apply the vendor's patch or workaround and then check for compromise. Since KEV entries are by definition already being exploited, a retest alone is not enough; logs and systems should be examined for traces.

See which of these apply to your company.

The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings