---
title: "KEV Definition &amp; Meaning | MedTech Terms"
description: "CISA's authoritative list of CVEs with confirmed in-the-wild exploitation, with mandatory federal remediation deadlines."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/kev#term",
        "name": "CISA Known Exploited Vulnerabilities Catalog",
        "alternateName": [
          "KEV",
          "CISA KEV",
          "Known Exploited Vulnerabilities"
        ],
        "description": "The Known Exploited Vulnerabilities (KEV) Catalog is a continuously updated list maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) of Common Vulnerabilities and Exposures (CVEs) that are being actively exploited in the wild. Each entry includes the CVE ID, vendor/product, vulnerability name, the date added, a required-action date (typically 21 days for federal civilian agencies under Binding Operational Directive 22-01), and notes on whether the vulnerability is known to be used in ransomware campaigns. KEV is widely adopted outside the federal sector as a high-confidence prioritization signal: a vulnerability on KEV is, by definition, no longer theoretical.",
        "url": "https://medtechterms.com/terms/kev",
        "termCode": "kev",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/kev#article",
        "headline": "KEV, CISA Known Exploited Vulnerabilities Catalog",
        "description": "CISA's authoritative list of CVEs with confirmed in-the-wild exploitation, with mandatory federal remediation deadlines.",
        "url": "https://medtechterms.com/terms/kev",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/kev"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/kev#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "CISA Known Exploited Vulnerabilities Catalog, KEV, CISA KEV, Known Exploited Vulnerabilities, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "Known Exploited Vulnerabilities Catalog",
            "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
            "publisher": {
              "@type": "Organization",
              "name": "CISA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "Binding Operational Directive 22-01",
            "url": "https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities",
            "publisher": {
              "@type": "Organization",
              "name": "CISA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "KEV JSON feed",
            "url": "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json",
            "publisher": {
              "@type": "Organization",
              "name": "CISA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/cve#term",
            "name": "Common Vulnerabilities and Exposures",
            "alternateName": "CVE",
            "url": "https://medtechterms.com/terms/cve"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/cvss#term",
            "name": "Common Vulnerability Scoring System",
            "alternateName": "CVSS",
            "url": "https://medtechterms.com/terms/cvss"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/sbom#term",
            "name": "Software Bill of Materials",
            "alternateName": "SBOM",
            "url": "https://medtechterms.com/terms/sbom"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/vex#term",
            "name": "Vulnerability Exploitability eXchange",
            "alternateName": "VEX",
            "url": "https://medtechterms.com/terms/vex"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/ics-medical-advisory#term",
            "name": "ICS Medical Advisory",
            "alternateName": "ICSMA",
            "url": "https://medtechterms.com/terms/ics-medical-advisory"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/section-524b#term",
            "name": "Section 524B of the FD&C Act",
            "alternateName": "524B",
            "url": "https://medtechterms.com/terms/section-524b"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "CISA Known Exploited Vulnerabilities Catalog",
            "item": "https://medtechterms.com/terms/kev"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/kev#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "How does CISA decide what goes on KEV?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Three criteria must all be met: the vulnerability has a CVE ID, there is reliable evidence of active exploitation in the wild, and there is clear remediation guidance (usually a vendor patch)."
            }
          },
          {
            "@type": "Question",
            "name": "Is KEV machine-readable?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes, CISA publishes the catalog as a JSON feed and a CSV at cisa.gov/kev. Most SBOM tooling can subscribe to it directly."
            }
          },
          {
            "@type": "Question",
            "name": "Does FDA require KEV monitoring?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Not by name. But FDA's premarket cybersecurity guidance and Section 524B post-market authority require manufacturers to monitor for exploited vulnerabilities, KEV is the most authoritative public source for that."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  CISA Known Exploited Vulnerabilities Catalog

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)KEV 

# CISA Known Exploited Vulnerabilities Catalog

CISA's authoritative list of CVEs with confirmed in-the-wild exploitation, with mandatory federal remediation deadlines.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

The Known Exploited Vulnerabilities (KEV) Catalog is a continuously updated list maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) of  [Common Vulnerabilities and Exposures](/terms/cve) (CVEs) that are being actively exploited in the wild. Each entry includes the CVE ID, vendor/product, vulnerability name, the date added, a required-action date (typically 21 days for federal civilian agencies under Binding Operational Directive 22-01), and notes on whether the vulnerability is known to be used in ransomware campaigns. KEV is widely adopted outside the federal sector as a high-confidence prioritization signal: a vulnerability on KEV is, by definition, no longer theoretical. 

What the regulation says

CISA Binding Operational Directive 22-01 makes KEV remediation mandatory for federal civilian executive branch agencies. FDA's premarket cybersecurity guidance and Section  [524B](/terms/section-524b) post-market expectations cite KEV-style exploited-in-the-wild status as the highest tier of vulnerability that manufacturers' post-market plans must address quickly. 

## What this means in practice

For medical device manufacturers, KEV is the single most actionable input to vulnerability prioritization. A  [CVE](/terms/cve) on KEV that affects a component listed in your  [SBOM](/terms/sbom) should trigger immediate triage, well ahead of generic  [CVSS](/terms/cvss) scoring. KEV inclusion also frequently appears in CISA ICS Medical Advisories and informs FDA's expectations under Section  [524B](/terms/section-524b) for a 'plan to monitor, identify, and address' post-market vulnerabilities. 

Common pitfalls

-   • Treating CVSS score as a substitute for KEV status, many critical-CVSS bugs are never exploited; many medium-CVSS bugs on KEV are devastating. 
-   • Polling KEV manually instead of automating ingestion of the official JSON feed and cross-referencing it with your SBOM. 
-   • Assuming the 21-day federal timeline doesn't apply to private hospitals, many health systems contractually require vendor remediation on the KEV cadence. 

## Frequently asked questions

How does CISA decide what goes on KEV? 

Three criteria must all be met: the vulnerability has a  [CVE](/terms/cve) ID, there is reliable evidence of active exploitation in the wild, and there is clear remediation guidance (usually a vendor patch). 

Is KEV machine-readable? 

Does FDA require KEV monitoring? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Common Vulnerabilities and Exposures(CVE) 

A globally unique identifier for a publicly disclosed cybersecurity vulnerability.





](/terms/cve)[

Cybersecurity

Common Vulnerability Scoring System(CVSS) 

An industry-standard 0–10 score that quantifies the severity of a software vulnerability.





](/terms/cvss)[

Cybersecurity

ICS Medical Advisory(ICSMA) 

CISA's official vulnerability advisories for medical devices, the public record of disclosed device cybersecurity issues, indexed as ICSMA-YY-DDD-NN.





](/terms/ics-medical-advisory)[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)

### More in Cybersecurity

· Same category 

[

Cybersecurity

Section 524B of the FD&C Act(524B) 

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.





](/terms/section-524b)[

Cybersecurity

Software Bill of Materials(SBOM) 

A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.





](/terms/sbom)[

Cybersecurity

Vulnerability Exploitability eXchange(VEX) 

A machine-readable statement that explains whether a known vulnerability is actually exploitable in a specific product.





](/terms/vex)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

1.  [1 
    
    Known Exploited Vulnerabilities Catalog
    
    Verified 
    
    CISA · cisa.gov 
    
    
    
    ](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
2.  [2 
    
    Binding Operational Directive 22-01
    
    Verified 
    
    CISA · cisa.gov 
    
    
    
    ](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities)
3.  [3 
    
    KEV JSON feed
    
    Verified 
    
    CISA · cisa.gov 
    
    
    
    ](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

KEV

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=kev)

Learn in 60 seconds

Card Lesson Quiz

CISA's authoritative list of CVEs with confirmed in-the-wild exploitation, with mandatory federal remediation deadlines.

-   · For medical device manufacturers, KEV is the single most actionable input to vulnerability prioritization. 
-   · A CVE on KEV that affects a component listed in your SBOM should trigger immediate triage, well ahead of generic CVSS scoring. 
-   · KEV inclusion also frequently appears in CISA ICS Medical Advisories and informs FDA's expectations under Section 524B for a 'plan to monitor, identify, and address' post-market vulnerabilities. 

Remember this

Watch out: Treating CVSS score as a substitute for KEV status, many critical-CVSS bugs are never exploited; many medium-CVSS bugs on KEV are devastating.

Related terms

-   [Common Vulnerabilities and Exposures(CVE) ](/terms/cve)
-   [Common Vulnerability Scoring System(CVSS) ](/terms/cvss)
-   [Software Bill of Materials(SBOM) ](/terms/sbom)
-   [Vulnerability Exploitability eXchange(VEX) ](/terms/vex)
-   [ICS Medical Advisory(ICSMA) ](/terms/ics-medical-advisory)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Section 524B of the FD&C Act(524B) ](/terms/section-524b)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [Common Weakness Enumeration(CWE) ](/terms/cwe)
-   [Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) ](/terms/hph-cpg)
-   [MITRE ATT&CK(ATT&CK) ](/terms/mitre-attack)
-   [HITRUST CSF(HITRUST) ](/terms/hitrust)
-   [Coordinated Vulnerability Disclosure(CVD) ](/terms/cvd)
-   [FedRAMP(FedRAMP) ](/terms/fedramp)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)