CISA Known Exploited Vulnerabilities Catalog
CISA's authoritative list of CVEs with confirmed in-the-wild exploitation, with mandatory federal remediation deadlines.
Definition
The Known Exploited Vulnerabilities (KEV) Catalog is a continuously updated list maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) of Common Vulnerabilities and Exposures (CVEs) that are being actively exploited in the wild. Each entry includes the CVE ID, vendor/product, vulnerability name, the date added, a required-action date (typically 21 days for federal civilian agencies under Binding Operational Directive 22-01), and notes on whether the vulnerability is known to be used in ransomware campaigns. KEV is widely adopted outside the federal sector as a high-confidence prioritization signal: a vulnerability on KEV is, by definition, no longer theoretical.What this means in practice
For medical device manufacturers, KEV is the single most actionable input to vulnerability prioritization. A CVE on KEV that affects a component listed in your SBOM should trigger immediate triage, well ahead of generic CVSS scoring. KEV inclusion also frequently appears in CISA ICS Medical Advisories and informs FDA's expectations under Section 524B for a 'plan to monitor, identify, and address' post-market vulnerabilities.- •Treating CVSS score as a substitute for KEV status, many critical-CVSS bugs are never exploited; many medium-CVSS bugs on KEV are devastating.
- •Polling KEV manually instead of automating ingestion of the official JSON feed and cross-referencing it with your SBOM.
- •Assuming the 21-day federal timeline doesn't apply to private hospitals, many health systems contractually require vendor remediation on the KEV cadence.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsA globally unique identifier for a publicly disclosed cybersecurity vulnerability.
An industry-standard 0–10 score that quantifies the severity of a software vulnerability.
CISA's official vulnerability advisories for medical devices, the public record of disclosed device cybersecurity issues, indexed as ICSMA-YY-DDD-NN.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.
A machine-readable statement that explains whether a known vulnerability is actually exploitable in a specific product.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
Primary references
3 sources- 1
Known Exploited Vulnerabilities CatalogVerifiedCISAcisa.gov
- 2
Binding Operational Directive 22-01VerifiedCISAcisa.gov
- 3
KEV JSON feedVerifiedCISAcisa.gov
Inline markers like [1] jump to the matching reference above.