CISA KEV Catalog — Updated Hourly
Known Exploited Vulnerabilities
CISA's Known Exploited Vulnerabilities (KEV) catalog lists CVEs actively exploited in the wild. Federal agencies (FISMA) must patch KEV vulnerabilities within 15 days for critical, 25 days for others. These are the vulnerabilities attackers are using right now.
KEV CVEs
0
Critical (CVSS ≥9)
0
+ Ransomware
0
Feed temporarily unavailable — please check back shortly.
What is the CISA KEV catalog?
The CISA Known Exploited Vulnerabilities (KEV) catalog is a curated list of CVEs that CISA has confirmed are being actively exploited in real attacks. Unlike CVSS scores — which measure theoretical severity — KEV flags mean the vulnerability is actively being weaponized by threat actors right now.
Under CISA's Binding Operational Directive 22-01, all U.S. federal civilian agencies must remediate KEV vulnerabilities within defined deadlines: 15 calendar days for critical vulnerabilities, 25 for others. Non-federal organizations should treat KEV as a priority patching signal regardless of their CVSS score.
A CVSS 5.3 (medium) vulnerability on the KEV list is more dangerous in practice than a CVSS 9.8 (critical) vulnerability that remains theoretical. Attackers vote with their toolkits — KEV is that vote.
Data via Shodan CVEDB. KEV flags sourced from CISA. Updated hourly.