KEV

Known Exploited Vulnerabilities Catalog

Katalog bekannter ausgenutzter Schwachstellen

The KEV catalogue is a list maintained by the US authority CISA of vulnerabilities for which active exploitation in the wild has been confirmed. It answers not the question „how severe?“ but „is it already being attacked?“ — thereby sharply prioritising patching. A vulnerability in the KEV is no longer a theoretical risk.

History & facts. CISA introduced the KEV catalogue in 2021 to counter the flood of known vulnerabilities with action-guiding prioritisation. The inclusion criterion is not a high severity but the proof of actual exploitation. For US federal agencies, closing KEV entries within set deadlines is mandatory; beyond that, the catalogue has established itself as a de-facto standard for urgency assessment and is linked, for instance, with EPSS and in aggregators such as the EUVD. Outlook & recommendation. KEV complements the severity rating (CVSS) and the probability estimate (EPSS) with the hardest factor: proven exploitation. Anyone prioritising vulnerabilities should treat KEV as the top escalation level — what is listed here generally belongs fixed or mitigated immediately. The greatest benefit arises when the catalogue is matched automatically against one's own inventory rather than reviewed by hand.
KEV — Known Exploited Vulnerabilities Catalog