Skip to content
BITBRIEF

Institutional research · AI · Cybersecurity · Digital assets

Vol. 01 · No. 13

KEV

Also: Known Exploited Vulnerabilities catalogue

A catalogue maintained by the United States Cybersecurity and Infrastructure Security Agency listing vulnerabilities confirmed to be exploited in the wild.

Most vulnerability feeds tell you what could be attacked. KEV tells you what is being attacked. Entry requires evidence of active exploitation, which makes the catalogue far shorter than the universe of published vulnerabilities and far more actionable.

Why the distinction changes priorities

A severity score describes how bad an exploit would be if it existed and were used. Presence in KEV describes something that is happening. A moderate-severity flaw under active exploitation deserves attention ahead of a critical one nobody has weaponised.

For United States federal civilian agencies, entries carry binding remediation deadlines. Everyone else is free to ignore them, and mostly should not.

How we use it

The catalogue feeds the live ribbon on our front page: total entries, and additions over the last seven and thirty days. Additions over a short window are a decent proxy for how busy the week has been.

All 30 terms