Skip to content
LIVE · CISA KEV

Vendor Advisories

Security advisories grouped by vendor from the CISA Known Exploited Vulnerabilities catalog. Filter by vendor, time window, or keyword.

Frequently Asked Questions

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities catalog maintained by CISA — a list of CVEs confirmed to have been actively exploited in the wild, used to prioritise patching.

How is CISA KEV different from the full NVD?

NVD lists all known CVEs regardless of exploitation status; KEV is a much smaller, curated subset CISA has confirmed is being actively exploited, with mandated remediation deadlines for US federal agencies.

Do CISA KEV deadlines apply to private companies?

The binding deadlines (BOD 22-01) apply to US federal civilian agencies, but KEV listing is widely used by private organisations as a de facto "patch this first" signal.

How often is the KEV catalog updated?

CISA adds new entries on a rolling basis whenever a vulnerability meets its active-exploitation criteria, sometimes multiple times per week.