Back to glossary

CISA KEV

1 min read

The CISA KEV catalogue is a public list, maintained by the United States Cybersecurity and Infrastructure Security Agency, of vulnerabilities with reliable evidence of exploitation in the wild. In vulnerability management it is used as a factual signal that something is being exploited now, rather than as a prediction that it might be.

July 29, 2026
Compartir:

An entry is added when there is evidence of active exploitation, an assigned CVE identifier, and clear remediation guidance. It carries a due date, which is binding on United States federal civilian agencies under the directive that created the catalogue and carries no legal weight anywhere else. For a Spanish organisation the value is therefore not compliance but confirmation: inclusion means the question of whether an issue is theoretical has already been answered.

It complements rather than replaces the two scores it sits next to. CVSS describes how bad an issue would be if exploited and says nothing about whether anyone is exploiting it; EPSS estimates the probability that someone will. The catalogue records what has been observed, and it is deliberately conservative, so absence from it is not evidence that something is safe.

In practice the useful thing to do with it is to intersect it with your own inventory and treat the overlap as a queue with a fixed clock, separate from the general backlog. When a remediation deadline is disputed in a report, this is the reference that ends the conversation quickest, because it is a third party statement of fact rather than our opinion about severity.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.