CISA KEV Catalog

Browse CISA's catalog of actively exploited vulnerabilities. Filter by vendor, view ransomware associations, and track remediation due dates.

Loading KEV catalog...

Don't leave your security to chance

Get a free security assessment from our experts. We'll identify vulnerabilities and create a protection plan tailored to your business.

Frequently Asked Questions

Common questions about the CISA KEV Catalog

What is the CISA KEV Catalog?+

The CISA Known Exploited Vulnerabilities (KEV) Catalog is an authoritative list of vulnerabilities that have been actively exploited in the wild. CISA requires federal agencies to remediate these vulnerabilities within specified timeframes.

How often is the KEV catalog updated?+

CISA updates the KEV catalog regularly as new exploited vulnerabilities are discovered. New entries can be added at any time when CISA confirms active exploitation.

What do the due dates mean?+

Due dates indicate when federal agencies are required to remediate the vulnerability. While only mandatory for federal agencies, all organizations should treat these deadlines as guidance for prioritization.

⚠️ Security Notice

This tool is provided for educational and authorized security testing purposes only. Always ensure you have proper authorization before testing any systems or networks you do not own. All processing happens client-side in your browser — no data is sent to our servers.