---
title: "CISA's Known Exploited Vulnerabilities Catalog: A Crucial Tool for Cybersecurity Defense"
description: Learn how CISA's Known Exploited Vulnerabilities (KEV) catalog helps organizations prioritize and address actively exploited security risks for robust cyber defense.
image: https://codenotary.com/hubfs/CISA-KEV.png
---

**$ protect --distro linux --machines 25 --free**

[Start now](https://apps.codenotary.com/linux)

[![cn-logo-black-nobg](https://codenotary.com/hubfs/cn-logo-black-nobg.svg)](https://codenotary.com/)

- Product
  
  #### [![AgentMon Start](https://codenotary.com/hubfs/AgentMon%20Start.svg) **AgentMon Start** Organization-wide AI agent spend, security and device fleet TRY NOW →](https://apps.codenotary.com/agentmon-start)
  
  #### [![AgentMon for Enterprise](https://codenotary.com/hubfs/AgentMon%20for%20Enterprise.svg) **AgentMon** Currently monitors more \> 7 million agent interactions/day. TRY NOW →](https://codenotary.com/agentmon)
  
  #### [![AgentX](https://codenotary.com/hubfs/AgentX.svg) **AgentX** Agentic network control middleware. TRY NOW →](https://codenotary.com/agent-network-control)
  
  #### [![Autonomous Security](https://codenotary.com/hubfs/Autonomous%20Security.svg) **Autonomous Security** AI Agents keep your servers secure. TRY NOW →](https://codenotary.com/trust)
- Use Cases
  
  #### [**AI Agent Risk Monitoring** Continuous oversight of autonomous agents across every environment.](https://codenotary.com/use-cases#risk)
  
  #### [**Autonomous Security Operations** Self-healing defenses that detect, contain, and remediate threats.](https://codenotary.com/use-cases#agentops)
  
  #### [**AI Coding Governance & Performance Monitoring** AI-generated code reviewed, tracked, and held to quality standards.](https://codenotary.com/use-cases#performance)
  
  #### [**AI Tool Cost & Usage Optimization** Spend and consumption optimized across every AI service in use.](https://codenotary.com/use-cases#cost)
  
  #### [**AI Tool Security & Policy Enforcement** Approved AI usage enforced with guardrails and policy controls.](https://codenotary.com/use-cases#security#security)
  
  #### [**Shadow AI Governance** Unsanctioned AI tools discovered, surfaced, and brought under control.](https://codenotary.com/use-cases#shadowit)
- [Blog](https://codenotary.com/blog)
- [Press](https://codenotary.com/press)
- Resources
  
  #### [**Integrations** Connect with your favorite tools and platforms. LEARN MORE →](https://codenotary.com/integrations)
  
  #### [**Support** Get help from our dedicated support team. GET HELP →](https://support.codenotary.com)
  
  #### [**Success Stories** Read how customers achieve their goals. READ MORE →](https://codenotary.com/success)
  
  #### [**Learn** Access documentation and learning resources. EXPLORE →](https://codenotary.com/learn)

[Login](https://apps.codenotary.com/auth/login)

[All posts](https://codenotary.com/blog/all)

 Apr 07, 2025

# CISA's Known Exploited Vulnerabilities Catalog: A Crucial Tool for Cybersecurity Defense

 By  [blog](https://codenotary.com/blog/author/blog)  ·   3 minute read

The cybersecurity landscape is constantly evolving, with new threats emerging daily. To help organizations stay ahead of potential attacks, the Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerabilities (KEV) catalog—an authoritative source of vulnerabilities that have been actively exploited in the wild.

![CISA-KEV](https://codenotary.com/hs-fs/hubfs/CISA-KEV.png?width=800&height=400&name=CISA-KEV.png)

 

## What is the KEV Catalog?

The KEV catalog serves as a critical resource for organizations to prioritize their vulnerability management efforts. Unlike other vulnerability listings that may focus on severity scores alone, the KEV catalog specifically highlights vulnerabilities that are actively being exploited by threat actors, making them immediate security concerns.

For example, a recent addition to the catalog is the Qlik Sense HTTP Tunneling Vulnerability. This vulnerability allows attackers to escalate privileges and execute HTTP requests on backend servers hosting the software. It's associated with CWE-444 and is known to be used in ransomware campaigns. CISA recommends that organizations apply vendor-provided mitigations or discontinue use of the product if mitigations are unavailable, with a compliance due date of February 3, 2025, for federal agencies.

## Why the KEV Catalog Matters

The KEV catalog isn't just another vulnerability database—it represents vulnerabilities that pose immediate risk because:

1. They have confirmed exploitation in real-world attacks
2. They have assigned CVE IDs
3. They have clear remediation actions available

For federal civilian executive branch (FCEB) agencies, addressing vulnerabilities listed in the KEV catalog isn't optional—it's required under Binding Operational Directive (BOD) 22-01. While other organizations aren't bound by this directive, CISA strongly recommends all entities prioritize remediation of KEV-listed vulnerabilities to strengthen their security posture.

 

## How Vulnerabilities Qualify for the KEV Catalog

For a vulnerability to be included in the KEV catalog, it must meet three specific criteria:

### 1. Assigned CVE ID

The vulnerability must have a Common Vulnerabilities and Exposures (CVE) identifier assigned by an authorized CVE Numbering Authority (CNA). This ensures the vulnerability has been properly documented and publicly disclosed.

### 2. Active Exploitation

There must be reliable evidence that the vulnerability has been actively exploited "in the wild." This means:

- An actor has executed malicious code on a system without permission
- The attack occurred in real-time environments (not just in research settings)
- The intent was to succeed in exploitation

 Importantly, security research, proof of concept development, or vulnerability scanning alone don't qualify as active exploitation for KEV inclusion.

### 3. Clear Remediation Guidance

The vulnerability must have a clear remediation path available, such as:

- Vendor-provided updates that can be applied
- Specific mitigations to prevent exploitation
- Workarounds to protect vulnerable systems

 

## How Codenotary Guardian Enhances KEV Protection

Codenotary Guardian is a software solution that provides enhanced protection against vulnerabilities in the KEV catalog. This solution actively scans your systems to identify components affected by high-priority vulnerabilities and monitors for three key categories of exploits:

### 1. KEV Catalog Exploits

These are the vulnerabilities documented in CISA's KEV catalog that have confirmed exploitation in the wild. Codenotary Guardian integrates with the KEV catalog to ensure your organization is protected against these known exploited vulnerabilities.

### 2. GitHub Exploits

"GitHub exploits" refer to vulnerabilities that have publicly available exploit code repositories on GitHub. When exploit code is published on platforms like GitHub, the risk of exploitation increases dramatically as attackers can easily find, copy, and modify these exploits to target vulnerable systems. Codenotary Guardian identifies vulnerabilities in your environment that have corresponding exploit code published on GitHub.

### 3. In-the-Wild Exploits

These are vulnerabilities with confirmed instances of exploitation in real-world environments. Unlike theoretical vulnerabilities, these have already been weaponized and used successfully against actual targets. Codenotary Guardian prioritizes these vulnerabilities as they represent immediate threats with proven impact.

### 4. Offensive Security Exploits

Offensive security exploits are vulnerabilities that have been weaponized and included in popular penetration testing frameworks like Metasploit. The inclusion in these frameworks makes them particularly dangerous as they're packaged in an easy-to-use format that requires minimal technical expertise to deploy. Codenotary Guardian identifies components in your environment that are vulnerable to these ready-to-use exploits.

 

## Building a Robust Vulnerability Management Program

To effectively use the KEV catalog in your security program:

1. **Regularly monitor the KEV catalog**: Create a process to review new additions to the catalog as they're published.
2. **Prioritize KEV vulnerabilities**: Incorporate KEV status into your vulnerability management prioritization framework.
3. **Implement automated solutions**: Deploy solutions like Codenotary Guardian that integrate with the KEV catalog to automatically identify and prioritize these vulnerabilities in your environment.
4. **Establish clear remediation timeline**: Define strict remediation timelines for KEV vulnerabilities, similar to the requirements placed on federal agencies.
5. **Document exceptions carefully**: If a KEV vulnerability cannot be immediately addressed, implement compensating controls and document the exception process.
   
    

## Conclusion

The CISA KEV catalog represents a shift in vulnerability management from theoretical risk to actual, observed threats. By focusing remediation efforts on vulnerabilities with confirmed exploitation, organizations can significantly improve their security posture and reduce the likelihood of compromise.

Whether you're required to comply with BOD 22-01 or simply looking to enhance your security program, making the KEV catalog a cornerstone of your vulnerability management strategy—supported by solutions like Codenotary Guardian—is a crucial step toward building collective resilience across the cybersecurity community.

Remember, when it comes to cybersecurity, addressing known exploited vulnerabilities isn't just about compliance—it's about staying ahead of the adversaries who are actively using these vulnerabilities against organizations right now.

[![Share on twitter](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/twitter-color.png?width=35&height=35&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=twitter&url=https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on facebook](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/facebook-color.png?width=35&height=35&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=facebook) [![Share on linkedin](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/linkedin-color.png?width=35&height=35&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=linkedin) [![Share on pinterest](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/pinterest.jpg?width=35&height=35&name=pinterest.jpg)](http://pinterest.com/pin/create/button/?url=https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=pinterest&media=) [![Share on email](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/email-color.png?width=35&height=35&name=email-color.png)](mailto:?subject=Check%20out%20https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=email%20&body=Check%20out%20https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense&utm_medium=social&utm_source=email)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "blog",
    "url" : "https://codenotary.com/blog/author/blog"
  },
  "dateModified" : "2025-04-11T07:32:27.576Z",
  "datePublished" : "2025-04-07T13:00:00.000Z",
  "headline" : "CISA's Known Exploited Vulnerabilities Catalog: A Crucial Tool for Cybersecurity Defense",
  "image" : [ "https://codenotary.com/hubfs/CISA-KEV.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://codenotary.com/hubfs/logo-light.svg"
    },
    "name" : "Codenotary, Inc."
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : [ "blog" ],
    "url" : "https://codenotary.com/blog/author/blog"
  },
  "datePublished" : "2025-04-07T13:00:00+0000",
  "description" : "Learn how CISA's Known Exploited Vulnerabilities (KEV) catalog helps organizations prioritize and address actively exploited security risks for robust cyber defense.",
  "headline" : "CISA's Known Exploited Vulnerabilities Catalog: A Crucial Tool for Cybersecurity Defense",
  "image" : "https://23873599.fs1.hubspotusercontent-na1.net/hubfs/23873599/CISA-KEV.png",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn2.hubspot.net/hubfs/23873599/logo-light.svg"
    },
    "name" : ""
  },
  "url" : "https://codenotary.com/blog/cisas-known-exploited-vulnerabilities-catalog-a-crucial-tool-for-cybersecurity-defense"
}
```