101% more reported CVEs per day in 2026 than last year.

Vulnerabilities

CISA KEV: the Known Exploited Vulnerabilities catalog

Of the hundreds of thousands of published CVEs, a small fraction have ever been exploited in the wild. CISA's Known Exploited Vulnerabilities catalog lists them. If one is in software you ship, it goes to the top of the list.

Updated

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities (KEV) catalog is maintained by the US Cybersecurity and Infrastructure Security Agency (CISA). CISA calls it the authoritative source of vulnerabilities that have been exploited in the wild, and strongly encourages all organizations to prioritize remediating them.

CISA set up the catalog in November 2021 alongside Binding Operational Directive 22-01. As of the catalog version of September 24, 2026, it holds 1,723 vulnerabilities. That is a tiny share of all published CVEs, which is exactly why it is useful: a KEV entry is not a prediction or a severity rating, it is a record of exploitation.

How a vulnerability gets added

CISA adds a vulnerability when it meets three criteria:

  1. It has a CVE ID.
  2. It is actively exploited, with reliable evidence that it has been or is being exploited.
  3. There is clear remediation guidance, a clear action for affected organizations, such as a vendor update.

The third criterion matters in practice: a vulnerability can be exploited for a while before it appears in KEV, because there was no fix to point to. Anyone can nominate a vulnerability through a form linked from CISA's KEV page.

What each KEV entry contains

Field What it holds
cveID The CVE identifier
vendorProject, product Who makes the affected software, and which product
vulnerabilityName, shortDescription A name and a short description
dateAdded, dueDate When CISA added it, and the remediation due date for US federal agencies
requiredAction What to do, usually apply the vendor's updates or mitigations, or discontinue use
knownRansomwareCampaignUse "Known" if it has been used in a ransomware campaign, otherwise "Unknown"
forensicTriage "Yes" if BOD 26-04 requires forensic triage for it
notes, cwes References and the weakness types

361 entries are currently marked as used in ransomware campaigns. If you have to rank within KEV, those come first.

BOD 26-04: KEV deadlines for federal agencies

For US federal civilian executive branch agencies, KEV is not advice. Binding Operational Directive 26-04, issued June 10, 2026, sets how fast they must remediate. It revoked BOD 22-01, which had given two weeks for most KEV entries and six months for CVEs assigned before 2021, and BOD 19-02. The criteria for adding a vulnerability to KEV did not change.

BOD 26-04 sets each deadline from four questions, informed by CISA's SSVC decision model:

  • Publicly exposed: can the asset be reached from public networks?
  • KEV status: is the vulnerability in the catalog?
  • Exploit automation: can an attacker automate exploitation?
  • Technical impact: does exploitation give partial or total control?

The answers give deadlines from 3 days, with forensic triage to check whether the system was already compromised, to fixing on the next system upgrade. The directive does not apply to companies outside the federal government, unless a contract says so. Even so, it is a useful benchmark for your own policy.

How to use KEV if you build software

Most KEV entries are in products from large vendors: Microsoft alone accounts for 388, followed by Cisco, Apple, Adobe and Google. Open source appears too, and when it does, it is inside other people's products. Log4Shell (CVE-2021-44228) is the example everyone remembers.

Build pipelines are not exempt. The compromised GitHub Actions tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup (CVE-2025-30154) are both in the catalog: a known exploited vulnerability can sit in the workflow that builds your product, not only in the product.

  1. Match KEV against what you ship, not against what your repositories declare. A vulnerable library pulled in transitively, or downloaded by a build script, is still in the product.
  2. Treat a match as an incident, not a backlog item. Fix it, or mitigate it and record why.
  3. Check your exposure period. Which releases shipped the vulnerable version, and since when? That is what customers ask.
  4. Watch the reporting clock. Under the EU Cyber Resilience Act, an actively exploited vulnerability in a product starts a 24-hour early warning obligation for the manufacturer.
  5. Rank everything else with EPSS and CVSS. Vulnerability prioritization covers the method.

How to get the KEV data

  • CISA: the catalog page, plus CSV, JSON and a JSON schema.
  • GitHub: cisagov/kev-data mirrors the data files and updates when the catalog does.
  • Email: CISA offers a subscription for catalog updates.
  • Your tools: many scanners and vulnerability management platforms flag KEV entries, among them Grype, Tenable, Qualys and Rapid7.

How CRACI helps

KEV tells you which vulnerabilities are exploited. CRACI tells you where they are. It runs your GitHub Actions jobs and records the packages each job actually fetched, including transitive dependencies, cached packages and hidden dependencies no lockfile lists, and re-evaluates monitored SBOMs continuously.

  • Which builds are affected. Build history shows which past builds contained the vulnerable dependency, direct or transitive, so you know the exposure period.
  • Who fixes it. Security teams triage findings and route each one to the team that owns the fix.
  • Stop it shipping again. Policy gates can block a build that contains a specific CVE.
  • Report it. For actively exploited vulnerabilities under the CRA, CRACI submits the notifications to the authorities on the manufacturer's behalf.

CISA KEV: frequently asked questions

What is CISA KEV?

The Known Exploited Vulnerabilities (KEV) catalog is CISA's list of vulnerabilities that have been exploited in the wild. CISA calls it the authoritative source of exploited vulnerabilities and encourages every organization to prioritize remediating them.

How many vulnerabilities are in the KEV catalog?

1,723 as of the catalog version of September 24, 2026, out of the hundreds of thousands of published CVEs. 361 of them are marked as known to have been used in ransomware campaigns.

What gets a vulnerability added to KEV?

Three criteria: it has a CVE ID, there is reliable evidence that it has been or is being exploited, and there is clear remediation guidance, such as a vendor update.

Do private companies have to follow KEV due dates?

No. The due dates bind US federal civilian executive branch agencies under Binding Operational Directive 26-04. Everyone else can use the catalog as a prioritization signal, and many customers and auditors expect it.

What replaced BOD 22-01?

BOD 26-04, issued June 10, 2026, revoked BOD 22-01 and BOD 19-02. Instead of a fixed two weeks for KEV entries, it sets deadlines from 3 days to the next system upgrade, based on KEV status, public exposure, whether exploitation can be automated and the technical impact.

What is the difference between KEV and EPSS?

KEV records vulnerabilities that are already exploited. EPSS estimates the probability that any published CVE will be exploited in the next 30 days. Use KEV first and EPSS to rank everything else.

Find known exploited vulnerabilities in what you ship

Book a demo and run one of your GitHub Actions workflows on CRACI. See every vulnerable package the build pulled in, and which builds shipped it.

Book a demo