CISA
CISA Known Exploited Vulnerabilities
CISA's catalog of vulnerabilities with confirmed evidence of active, in-the-wild exploitation. This is an educational overview of how the catalog works and what listing on it means — not a live mirror of catalog entries, which change continuously and are out of scope for a static reference page.
Entries
CISA Known Exploited Vulnerabilities Reference Entries
2 of 2 entries
KEV
What the CISA KEV Catalog Is
A CISA-maintained catalog of CVEs with confirmed evidence of active, in-the-wild exploitation — not a predictive or theoretical list.
KEV
BOD 22-01 and the Federal Remediation Mandate
The CISA Binding Operational Directive that requires federal civilian agencies to remediate KEV-listed vulnerabilities by an assigned due date.