LiveIn use by CVE Triage
CISA Known Exploited Vulnerabilities (KEV) catalogue
What it is
CISA's list of vulnerabilities with evidence of exploitation in the wild, with required actions and due dates for US federal agencies.
Publisher and URL
Cybersecurity and Infrastructure Security Agency (CISA).
Licence
CC0 1.0, which places the data in the public domain. Use does not permit the CISA logo or imply endorsement.
Update cadence
Updated whenever CISA adds entries, usually on weekdays in US Eastern business hours. We fetch every night and apply the changes.
Fields we use
cveID, vendorProject, product, vulnerabilityName, dateAdded, requiredAction, dueDate, knownRansomwareCampaignUse.
Known gaps
- An entry needs CISA's evidence of exploitation, so the catalogue can lag other exploitation reports, and it leans towards products used by US agencies.
- In 2026 CISA revoked BOD 22-01, the directive that created the catalogue, and issued BOD 26-04 in its place. The catalogue is still published and updated.
How Stackbyte uses it
The stackbyte.kev.* fields in CVE Triage. A KEV listing makes a CVE priority P1. The recently-exploited endpoint lists new KEV entries.
Field by field details are in the CVE Triage docs.