Nexus Void Research

CISA KEV, Known Exploited Vulnerabilities, Patch Management, BOD 22-01

What Is CISA KEV? Known Exploited Vulns Explained

What is CISA KEV? A clear guide to the Known Exploited Vulnerabilities catalog: what gets listed, why it drives patching, and what the catalog cannot tell you.

CISA KEV, the Known Exploited Vulnerabilities catalog, is the U.S. government's authoritative list of vulnerabilities that have been confirmed exploited in the wild, published by the Cybersecurity and Infrastructure Security Agency. If a CVE is in KEV, it is not a theoretical risk: someone has actually used it in a real attack. That single fact makes KEV the highest-signal free prioritization source available, because it removes the guesswork about whether a flaw matters.

A vulnerability earns a KEV entry only when CISA has reliable evidence of active exploitation, an assigned CVE ID, and clear remediation guidance. Each entry carries the CVE, vendor and product, the date added, a remediation due date, and a flag for whether the flaw is known to be used in ransomware campaigns. Under Binding Operational Directive 22-01, U.S. federal civilian agencies are required to remediate KEV entries by their due dates, which is why the catalog functions as a de facto patch-now list far beyond government.

Why does CISA KEV matter for patching?

Because it converts an unmanageable backlog into a short, defensible priority list. Tens of thousands of CVEs are published every year, and the vast majority are never exploited. KEV isolates the ones that are, so "patch everything in KEV that you run, on time" is a policy any team can defend to an auditor or a board. It is also increasingly used as a compliance and cyber-insurance benchmark, and it pairs naturally with EPSS: KEV tells you what is confirmed exploited today, EPSS estimates what is likely to be exploited next.

Attribute

What KEV gives you

Inclusion bar

Confirmed in-the-wild exploitation

Per-entry data

CVE, vendor/product, date added, due date, ransomware flag

Mandate

Federal remediation by due date (BOD 22-01)

Best paired with

CVSS (impact) + EPSS (probability)

What does the CISA KEV catalog not tell you?

KEV is a floor, not a ceiling. It only lists what CISA has confirmed, so a flaw being exploited quietly, or against non-U.S. or non-reported targets, may not appear for days or at all. There is a lag between first exploitation and the KEV listing, and coverage skews toward widely-deployed enterprise and edge products. So "not in KEV" does not mean "safe to defer," especially for a fresh CVE with a public exploit. Treat KEV as a definitive yes, never as a definitive no.

Our read

KEV is the closest thing defenders have to ground truth, and building your patch policy around it is one of the highest-leverage moves available. But the honest lesson from the data is about timing: our analysis of the 2025 KEV additions found the median gap from public disclosure to confirmed exploitation was 26 days, and 67% of that year's exploited vulnerabilities would never have been caught by an annual penetration test before attackers reached them. KEV tells you what to patch. Continuous verification is how you prove you actually did, in time.

Data per CISA and FIRST.org. Sources linked above.

Related: what CVSS misses for patch prioritization and the annual-pentest blind window.

DATA SOURCES

CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog ; CISA BOD 22-01 — https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities ; FIRST.org EPSS — https://www.first.org/epss/

Liked this post? Share it:

Related posts

Related posts appear on the live page

VIEW ALL RESEARCH ->

PAGE CONTENTS

Contents appear on the live page

// FROM THE LAB

Pentesting is easy and affordable now.

Continuous VAPT you can run every month, with a report built for AI-built apps.

RUN A VAPT ->

// CYBER NETWORK

Shape the next analysis.

A curated network of security practitioners who help set our research agenda. By application.

APPLY TO JOIN ->

Get new research first

We publish original analysis and experiments on how attackers actually move. Follow along: