Known Exploited Vulnerabilities (KEV) Catalog: Prioritizing Cyber Risk Reduction

Cybersecurity and Infrastructure Security Agency (CISA)

An operational cybersecurity reference helping organizations prioritize remediation of vulnerabilities actively exploited by threat actors.
Executive summary
The Known Exploited Vulnerabilities (KEV) Catalog is one of CISA's most widely used cybersecurity resources. It provides an authoritative, continuously updated list of software and hardware vulnerabilities that are actively exploited in real-world attacks.
The catalog enables organizations to prioritize patch management, vulnerability remediation, and risk reduction efforts based on active threat intelligence rather than theoretical exposure.
Integrating the KEV Catalog into vulnerability management programs helps improve operational resilience and reduce the likelihood of successful cyberattacks.