What is CISA KEV?
The CISA Known Exploited Vulnerabilities catalog lists vulnerabilities that CISA has identified as exploited in the wild. It is an external authoritative source maintained by CISA.
CISA KEV is an external confirmed-exploitation signal used by DevSecure Intelligence to help vendors and security teams understand which CVEs have real-world attack evidence.
The CISA Known Exploited Vulnerabilities catalog lists vulnerabilities that CISA has identified as exploited in the wild. It is an external authoritative source maintained by CISA.
Confirmed exploitation is stronger than theoretical severity alone. It shows that attackers have used the vulnerability outside a lab or scoring model.
DevSecure Intelligence treats KEV membership as a confirmed exploitation signal alongside CVSS, EPSS, exploit evidence, source coverage, and patch intelligence.
A KEV-listed CVE is ranked with elevated external-risk context because known exploitation changes the urgency of review and exposure validation.
DevSecure does not own or publish the CISA KEV catalog. For the authoritative catalog, use CISA's official source.
Official CISA KEV catalog