KEV (Known Exploited Vulnerabilities catalog)

KEV is CISA's catalog of vulnerabilities with confirmed exploitation against real targets. It was created on 3 November 2021 by binding operational directive BOD 22-01, and it requires United States federal civilian agencies to remediate each entry by a published due date. Version 2026.09.16 held 1,713 entries, which is 0.46% of the CVEs carrying an EPSS score on that date.

Updated

What goes into the KEV catalog

KEV is the Known Exploited Vulnerabilities catalog, maintained by CISA, the United States government's cybersecurity agency, listing CVEs with confirmed exploitation against real targets.

Three conditions have to hold at once for a flaw to enter: an assigned CVE identifier, reliable evidence of active exploitation, and a remediation or mitigation action already available. A published proof of concept is not enough, and neither is a researcher demonstrating the attack in a lab.

That makes KEV the most conservative of the signals that order a vulnerability queue. It arrives after the others. In exchange, what sits in it needs no estimate.

Where KEV came from and who it binds

KEV was created on 3 November 2021 by binding operational directive BOD 22-01, and it opened with 287 entries on day one.

The legal obligation reaches United States federal civilian agencies, which have to remediate each item by the due date published alongside the entry. No company in Brazil, Spain or Mexico falls under it. The catalog became a market reference anyway, for two practical reasons: it is the cheapest public source to consult on confirmed exploitation, and the file is free, machine-readable and updated on almost every business day.

KEV in numbers, on 16 September 2026

At version 2026.09.16 KEV held 1,713 entries, 229 of them added since 1 January 2026. The median due date CISA assigns to a new entry is 21 days out.

Two readings of the set say more than the count.

The age of the flaws. Catalog CVEs run from 2002 to 2026, and only 150 of the 1,713 carry a 2026 identifier. Nine in ten items under confirmed exploitation today were published in some earlier year. The oldest entry is CVE-2002-0367, in Windows, added in March 2022. What takes a company down is usually well enough known to have become routine.

The ransomware flag. 360 entries, 21% of the catalog, are flagged for known use in ransomware campaigns. That subset maps most directly to an incident that stops operations, and it fits in a one-hour meeting.

Why KEV is too short to be the whole queue

1,713 entries against 374,847 CVEs carrying an EPSS score on the same date works out to 0.46%. The catalog covers under half a percent of the published universe.

The virtue and the limit are the same property. If an item in your estate appears in KEV, the argument about priority is over. In exchange, the catalog records what was observed and reported, with the lag of anyone who depends on somebody else's observation.

VulnCheck measured that lag on 21 January 2026: 884 vulnerabilities showed first evidence of exploitation during 2025, against 245 that CISA added to the catalog in the same year. The distance between the two numbers is the part of the problem the catalog does not see in time.

CISA's due date and the one your company meets

Every entry ships with a due date. Verizon's DBIR 2026 shows what happens to that deadline outside the US government: only 26% of catalog flaws were fully remediated, and median time to remediate rose from 32 to 43 days.

Three quarters of what is known to be under attack stays open, and the list is public, free and fits in a spreadsheet. The bottleneck sits between knowing and acting. Undefined asset owner, contested maintenance window, a system nobody wants to restart during business hours. The exposure window measures that distance in hours or days, per asset.

How to use KEV without turning it into a ceiling

As a floor. An item in your estate that shows up in the catalog goes to the top without a meeting. The common error runs the other way, treating everything off the list as optional.

Crossed with what answers from outside. A catalog entry in a component you do not expose weighs less than a medium-scored flaw on an open asset. The catalog says the flaw is used in the world. What says it is reachable in your environment is exploitability validation.

As a reordering trigger. When a CVE enters the catalog, an asset that was already parked in your queue changes position without having changed state. A program that only reorders on the next cycle loses that signal for weeks.

Added to the forecast. KEV is settled fact. EPSS estimates what is still going to happen. Teams that use both catch what is already in use and what is climbing; teams that use the catalog alone work facing backwards.

What KEV does not cover

It records observed exploitation, which leaves out by construction everything not yet observed or reported. An attack aimed at a single target, with an exploit that never circulated, enters the catalog when somebody tells the story, sometimes years later.

It also says nothing about your estate. None of the 1,713 entries knows whether you run that product, whether the service answers from the internet, or whether the flaw's precondition holds on your asset. That part is the work of vulnerability management plus a view of the external attack surface.

CSURFACE crosses CISA's catalog with the customer's external inventory, the EPSS score, the existence of a public exploit and the attack telemetry its sensors record, and orders the queue from that set. Endpoint, email and internal network fall outside what the platform observes, and no wording change alters that.

Veja isso na sua superfície

Análise preliminar gratuita