← Cybersecurity Alphabet Soup

KEV

Known Exploited Vulnerabilities

operationsmedium

Fewer than 5 percent of CVEs are ever exploited in the wild; the KEV catalog, maintained by CISA, is the list of the ones that have been. Vulnerability management teams use it to prioritize patching, since a flaw on the KEV list is a proven risk, not a theoretical one. US federal civilian agencies must patch KEV entries on a deadline under Binding Operational Directive 22-01.

Sources

More in operations

Go deeper

Tools worth considering