Patch Guidance
CISA KEV entries sorted by federal remediation deadline. Overdue and urgent patches listed first. Required actions and mitigation steps for each vulnerability.
Emergency (≤72 h)
KEV + CVSS 9.0+ + public exploit
Critical (≤7 d)
KEV-listed, actively exploited
Urgent (≤30 d)
High severity, KEV pending
Planned (≤90 d)
Medium/low, no active exploit
Remediation deadlines apply to FCEB agencies (BOD 22-01). Treat as guidance for all organisations — KEV-listed vulnerabilities are confirmed actively exploited.
Related Vulnerability Research
Search 250,000+ CVEs from the NIST National Vulnerability Database. Live CVSS scores, CWE mappings and vendor references.
CVSS 3.1 base score calculator. Compute scores from attack vector, complexity, privileges, scope and impact metrics.
Security advisory schedules and patch cadence for Cisco, Fortinet, Microsoft, Palo Alto, Juniper and 20+ vendors.
Exploit methodology reference: vulnerability classes, weaponisation lifecycle, PoC-to-exploit pipeline and detection opportunities.
Layered mitigation playbooks for RCE, SQLi, SSRF, Deserialization, Auth Bypass and XXE. WAF rules and compensating controls when patches can't deploy immediately.
Frequently Asked Questions
What determines patch priority in this framework?
A combination of CVSS base score, CISA KEV status (confirmed active exploitation), public exploit availability, and environmental context — internet-facing, business-critical, existing compensating controls.
What are the CISA BOD 22-01 remediation deadlines?
Under Binding Operational Directive 22-01, US federal civilian agencies must remediate KEV-listed vulnerabilities within deadlines CISA sets per vulnerability — commonly around 2 weeks, though it varies by entry.
Should a low-CVSS vulnerability ever be patched before a high-CVSS one?
Yes — a lower-CVSS vulnerability that's in CISA KEV (confirmed actively exploited) is generally higher real-world priority than a higher-CVSS vulnerability with no known exploitation.
What happens if a vendor hasn't released a patch yet?
Track it as an unpatched risk, apply mitigation guidance and compensating controls in the meantime, and monitor vendor advisories for the fix.