What are Known Exploited Vulnerabilities (KEV)?
Known Exploited Vulnerabilities (KEV) are vulnerabilities with a CVE identifier for which there is reliable evidence that attackers are exploiting them in the wild; the best-known list is the KEV catalog maintained by the US agency CISA. The catalog was launched on 3 November 2021 and held more than 1,700 entries in early October 2026. Where a severity score tells you how bad a flaw could be, KEV tells you that it is being used right now. That makes KEV one of the most powerful filters in vulnerability management, especially in OT, where not everything can be patched straight away.
🎯 Why does the KEV catalog exist?
Tens of thousands of CVEs are published every year, yet only a small fraction is ever exploited. Organisations that try to patch everything by severity drown in work and miss the flaws that actually matter. CISA therefore launched the catalog together with Binding Operational Directive BOD 22-01, which required US federal civilian agencies to remediate KEV entries within fixed deadlines.
The list is public, free and machine-readable (CSV and JSON). CISA explicitly urges businesses, local governments and organisations in other countries to prioritise KEV entries as well. As a result, the catalog has become a de facto standard built into vulnerability scanners, SIEM platforms and patch tools worldwide.
🧠 How does a vulnerability get into the KEV catalog?
CISA applies three criteria, and all three must be met:
| Criterion | Meaning |
|---|---|
| CVE identifier | The vulnerability has an assigned CVE ID |
| Active exploitation | There is reliable evidence that an actor executed malicious code on a system without the owner’s permission; failed attempts count too, but scanning, security research and proofs of concept do not |
| Clear remediation | There is a clear action to take: usually a vendor update, otherwise a mitigation or removal of the product |
The third criterion matters for OT: an actively exploited zero-day only enters the catalog once such guidance exists. For end-of-life products with no patch, the required action is often simply to remove the product from the network. Each entry records, among other things, the vendor, product, date added, required action, a due date and a knownRansomwareCampaignUse flag. Of the 1,733 entries on 2 October 2026, 361 were known to have been used in ransomware campaigns.
🗓️ What deadlines apply to US federal agencies?
For federal agencies KEV is an obligation, not advice. On 10 June 2026 CISA replaced BOD 22-01, together with the older BOD 19-02, with the risk-based directive BOD 26-04.
| Directive | Period | Deadline |
|---|---|---|
| BOD 22-01 | Nov 2021 – June 2026 | Fixed: 2 weeks for CVEs from 2021 onwards, 6 months for older CVEs |
| BOD 26-04 | Issued 10 June 2026; deadlines apply within 180 days | Tiered: 3 days plus forensic triage for the riskiest combinations, such as an internet-facing system with a KEV flaw that gives total control; otherwise 14 days, 60 days or “at the next major system upgrade” |
BOD 26-04 weighs four variables: public exposure, KEV status, whether exploitation can be automated, and technical impact (partial or total control). KEV therefore remains the pivot, but combined with context. That fits the reality of patch management in OT well.
🏭 Which OT vulnerabilities appear in the KEV catalog?
The vast majority of the catalog concerns IT: Microsoft alone accounts for 389 entries, Cisco for 100. Even so, recognisable ICS products are listed:
- Unitronics Vision PLC/HMI (CVE-2023-6448) — a default password exploited against water utilities in late 2023; added with a deadline of just one week
- Rockwell Logix controllers (CVE-2021-22681) — an authentication bypass, added in March 2026
- Siemens SIMATIC CP, Schneider Electric U.motion Builder, Trihedral VTScada and Delta DOPSoft — older flaws added in 2022
- Sierra Wireless AirLink and OpenPLC ScadaBR — added in 2025
More important than this handful of direct OT entries are the IT components inside the OT environment: VPN gateways for remote access, firewalls, Windows engineering workstations and virtualisation platforms. Those appear in KEV in large numbers and are often the attacker’s route to the PLC.
🌍 What is the European counterpart to KEV?
On 13 May 2025 ENISA launched the European Vulnerability Database (EUVD), as mandated by Article 12 of NIS2. The EUVD aggregates information from national CSIRTs, vendors and existing sources such as the CVE Programme and the KEV catalog. It offers three dashboards: critical vulnerabilities, exploited vulnerabilities, and vulnerabilities coordinated by European CSIRTs. EUVD identifiers are mapped to CVE IDs, and ENISA has itself been a CVE Numbering Authority since January 2024.
The EUVD does not replace KEV, but it gives European organisations a source of their own that is less dependent on US funding. For Dutch organisations under the Dutch Cybersecurity Act, the NCSC is another regular source of advisories.
🔄 How do KEV, CVSS and EPSS relate to each other?
| Feature | CVSS | EPSS | KEV |
|---|---|---|---|
| Maintained by | FIRST | FIRST | CISA |
| Question answered | How severe is the flaw? | How likely is exploitation? | Is it already being exploited? |
| Output | Score 0.0–10.0 | Probability 0–1 over the next 30 days | Yes or no, with a deadline |
| Basis | Technical characteristics | Statistical model, updated daily | Proven exploitation |
| Current version | 4.0 (2023) | 4 (March 2025) | Continuously updated |
| Weakness | Says nothing about threat | A prediction, not evidence | Lags behind, limited to known cases |
The three complement each other: KEV as the hard trigger, EPSS to sort the long tail, and CVSS to understand the impact.
🔐 Why is ‘actively exploited’ the trigger in the CRA?
The Cyber Resilience Act defines an actively exploited vulnerability in Article 3(42) in almost the same terms as KEV: reliable evidence that a malicious actor has exploited it in a system without the owner’s permission. Since 11 September 2026 manufacturers must report such a vulnerability in their product through ENISA’s single reporting platform: an early warning within 24 hours, a notification within 72 hours and a final report no later than 14 days after a corrective measure becomes available. See CRA Reporting Obligations for the details. For OT vendors, ‘active exploitation’ thus becomes a legal concept, not merely a prioritisation label.
🛠️ How do you use KEV in an OT environment?
A practical workflow for an asset owner:
- Know your installation — a current asset inventory with vendor, model, firmware and software versions, ideally supplemented by an SBOM
- Match CVEs — compare the inventory against vendor advisories, CISA ICS advisories and the EUVD
- Filter on KEV — every hit in KEV or the EUVD exploited dashboard goes to the top of the list
- Rank the rest with EPSS and exposure — a high EPSS score on a system reachable from the internet or the office network comes next
- Patch or mitigate — patch during the next maintenance shutdown; if that is not possible, apply compensating measures immediately
- Record and review — document decisions and residual risks, and check daily whether the catalog contains new matches
Typical compensating measures when a PLC or HMI cannot be patched right away:
- Remove exposure — no direct internet connection, network segmentation and strict firewall rules
- Restrict access — change default passwords, allow remote access only through a managed gateway with MFA
- Detect — network monitoring for known exploit patterns and unusual engineering commands
- Layer your defences — defence in depth, so that a single flaw does not reach the process directly
❓ Frequently asked questions
Is the KEV catalog mandatory for European companies?
No, the KEV catalog is only binding for US federal civilian agencies. European organisations use KEV voluntarily, but it fits well with the vulnerability-handling duty of care under NIS2 and national laws such as the Dutch Cybersecurity Act. A demonstrable KEV process is strong evidence of risk-based vulnerability management.
How many vulnerabilities are in the KEV catalog?
On 2 October 2026 the KEV catalog contained 1,733 vulnerabilities. CISA adds a few entries a week on average; in 2025 it added 245. That is only a small fraction of all published CVEs.
What is the difference between KEV and EPSS?
KEV states that a vulnerability is demonstrably being exploited, whereas EPSS predicts the probability of exploitation over the next 30 days. KEV is therefore evidence after the fact, EPSS a statistical expectation in advance. Together they prioritise far better than CVSS alone.
How often is the KEV catalog updated?
The KEV catalog is updated continuously, often several times a week. Each addition is published as an alert on the CISA website and in the CSV and JSON feeds. Vulnerability scanners and patch tools usually ingest those feeds automatically.
What should you do if an OT system with a KEV vulnerability cannot be patched?
Apply compensating measures straight away: remove internet exposure, segment the network, change default passwords and monitor for exploitation. Schedule the patch for the next maintenance shutdown and record the residual risk. A KEV vulnerability without any mitigation is a risk that attackers are already actively using.
Does the EUVD also have a list of exploited vulnerabilities?
Yes, ENISA’s European Vulnerability Database has a separate dashboard for actively exploited vulnerabilities. It is the European equivalent of the KEV catalog and draws on information from European CSIRTs and vendors in addition to KEV itself.
📌 In summary
Known Exploited Vulnerabilities are flaws that are demonstrably already being exploited; CISA’s KEV catalog and ENISA’s EUVD dashboard show you which weaknesses in your OT environment need a patch or compensating measure first. Combine KEV with EPSS, CVSS and a sound asset inventory, and bear in mind that under the CRA ‘active exploitation’ is also a legal reporting trigger.
