[{"data":1,"prerenderedAt":123},["ShallowReactive",2],{"wissen-en-cisa-kev":3,"wissen-related-en-cisa-kev":115},{"id":4,"title":5,"body":6,"description":95,"extension":96,"lang":97,"meta":98,"navigation":99,"path":100,"related":101,"seo":105,"short":106,"sitemap":107,"stem":108,"synonyms":109,"updated":113,"__hash__":114},"wissenEn\u002Fen\u002Fwissen\u002Fcisa-kev.md","CISA KEV (Known Exploited Vulnerabilities)",{"type":7,"value":8,"toc":83},"minimark",[9,13,18,21,25,28,32,35,39,42,46,49,53,56,60],[10,11,12],"p",{},"The CISA KEV catalogue (Known Exploited Vulnerabilities) is a list maintained by the US Cybersecurity and Infrastructure Security Agency (CISA) of vulnerabilities for which exploitation in real attacks has been confirmed. Each entry contains the CVE number, vendor, product, a short description, the date added, a remediation due date for US federal agencies and, since 2023, an indication of whether the vulnerability is used in ransomware campaigns.",[14,15,17],"h2",{"id":16},"why-cisa-kev-matters","Why CISA KEV matters",[10,19,20],{},"The catalogue is deliberately small: it covers only a fraction of all CVEs, but exactly the ones attackers actually use. For prioritisation this is the most reliable statement available, because unlike a prediction (EPSS), KEV describes an observed fact. If a vulnerability is in the catalogue and affects a system reachable from the internet, there is no good reason to wait. Even though the due dates formally apply only to US agencies, auditors, insurers and regulators in Europe use the catalogue as the benchmark for what \"state of the art\" means in vulnerability management.",[14,22,24],{"id":23},"how-the-kev-catalogue-works","How the KEV catalogue works",[10,26,27],{},"CISA adds a vulnerability when three criteria are met: a CVE number exists, there is reliable evidence of active exploitation, and there is clear remediation guidance (patch, workaround or decommissioning). The basis is Binding Operational Directive 22-01 of November 2021, which obliges US federal agencies to remediate KEV entries within the set deadline. The catalogue is extended continuously, often several times a week, and is freely available as JSON and CSV. The field \"known ransomware campaign use\" shows whether the entry is associated with ransomware.",[14,29,31],{"id":30},"how-blacklensio-uses-cisa-kev","How blacklens.io uses CISA KEV",[10,33,34],{},"blacklens.io flags every finding with a CVE that is listed in the KEV catalogue, including the date added, remediation due date and ransomware flag. The KEV status feeds into prioritisation together with EPSS, exploit availability and CVSS and can be used as a filter in every list and in BQL queries. Because new CVEs are matched in real time against your technology inventory, a vulnerability newly added to the catalogue that affects one of your products appears shortly afterwards as a threat in the Threat Center and is verified there automatically.",[14,36,38],{"id":37},"does-cisa-kev-apply-to-companies-in-austria-and-germany","Does CISA KEV apply to companies in Austria and Germany?",[10,40,41],{},"Legally the catalogue is binding only for US federal agencies. Technically it is relevant worldwide, because attackers know no borders. Many European companies use the KEV due dates as an internal SLA for remediation.",[14,43,45],{"id":44},"how-does-kev-differ-from-epss","How does KEV differ from EPSS?",[10,47,48],{},"KEV is a binary, evidenced statement: this vulnerability is being exploited. EPSS is a probability for all CVEs, including those where no exploitation has been observed yet. KEV is more precise, EPSS earlier. Together they cover both cases.",[14,50,52],{"id":51},"what-should-you-do-when-a-kev-vulnerability-appears-in-your-inventory","What should you do when a KEV vulnerability appears in your inventory?",[10,54,55],{},"Identify affected systems, check reachability from the internet, apply the vendor's patch or workaround and then check for compromise. Since KEV entries are by definition already being exploited, a retest alone is not enough; logs and systems should be examined for traces.",[14,57,59],{"id":58},"related-terms","Related terms",[61,62,63,71,77],"ul",{},[64,65,66],"li",{},[67,68,70],"a",{"href":69},"\u002Fen\u002Fwissen\u002Fepss","EPSS",[64,72,73],{},[67,74,76],{"href":75},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management",[64,78,79],{},[67,80,82],{"href":81},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)",{"title":84,"searchDepth":85,"depth":85,"links":86},"",3,[87,89,90,91,92,93,94],{"id":16,"depth":88,"text":17},2,{"id":23,"depth":88,"text":24},{"id":30,"depth":88,"text":31},{"id":37,"depth":88,"text":38},{"id":44,"depth":88,"text":45},{"id":51,"depth":88,"text":52},{"id":58,"depth":88,"text":59},"CISA KEV explained: what the catalogue of known exploited vulnerabilities contains, why it matters for European companies too and how blacklens.io flags KEV entries.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fcisa-kev",[102,103,104],"epss","vulnerability-management","continuous-threat-exposure-management",{"title":5,"description":95},"The CISA KEV catalogue is a list maintained by the US agency CISA of vulnerabilities proven to be exploited in real attacks, each with a remediation due date.",{"loc":100},"en\u002Fwissen\u002Fcisa-kev",[110,111,112],"KEV","Known Exploited Vulnerabilities Catalog","CISA catalogue","2026-09-14","q6P3sd4nfFMvHux9I0Wvd6BoaRNptYuwc2o_uwSiI0A",[116,118,121],{"path":81,"title":82,"short":117},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"path":69,"title":119,"short":120},"EPSS (Exploit Prediction Scoring System)","EPSS is a scoring system by FIRST that estimates for every CVE the probability that it will actually be exploited within the next 30 days, as a value between 0 and 1.",{"path":75,"title":76,"short":122},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1789638254590]