CISA Known Exploited Vulnerabilities (KEV) Catalog
CISA Known Exploited Vulnerabilities (KEV) Catalog 是什么?
CISA Known Exploited Vulnerabilities (KEV) CatalogA U.S. CISA-maintained list of CVEs with credible evidence of in-the-wild exploitation, paired with mandatory remediation deadlines for U.S. federal civilian agencies and widely used by enterprises as a priority signal.
The CISA Known Exploited Vulnerabilities (KEV) Catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency of vulnerabilities for which CISA has credible evidence of active in-the-wild exploitation. KEV launched in November 2021 under Binding Operational Directive 22-01, which makes remediation of listed CVEs mandatory for U.S. Federal Civilian Executive Branch (FCEB) agencies within a stated deadline (typically two to three weeks). Each entry includes the CVE, product, short description, required action, due date, and the date added. By 2025 the catalog held over 1,300 CVEs across operating systems, network appliances, VPNs, RMM, productivity software, and ICS. Despite its formal scope being U.S. federal, KEV has become the de facto cross-industry prioritization signal — many enterprise vulnerability-management programs and cyber insurers treat KEV inclusion as a 'patch immediately' marker, and many ASPM/CSPM platforms surface KEV status alongside EPSS, CVSS, and reachability data. KEV is widely paired with the EPSS score (Exploit Prediction Scoring System) for risk-based vulnerability management.
● 示例
- 01
A FortiManager 'FortiJump' CVE-2024-47575 is added to KEV the day Mandiant publishes the post; FCEB agencies have a strict deadline to patch.
- 02
An enterprise patch prioritization policy mandates remediation of any KEV-listed CVE within seven days, regardless of CVSS, EPSS, or asset criticality.
● 常见问题
CISA Known Exploited Vulnerabilities (KEV) Catalog 是什么?
A U.S. CISA-maintained list of CVEs with credible evidence of in-the-wild exploitation, paired with mandatory remediation deadlines for U.S. federal civilian agencies and widely used by enterprises as a priority signal. 它属于网络安全的 漏洞 分类。
CISA Known Exploited Vulnerabilities (KEV) Catalog 是什么意思?
A U.S. CISA-maintained list of CVEs with credible evidence of in-the-wild exploitation, paired with mandatory remediation deadlines for U.S. federal civilian agencies and widely used by enterprises as a priority signal.
CISA Known Exploited Vulnerabilities (KEV) Catalog 是如何工作的?
The CISA Known Exploited Vulnerabilities (KEV) Catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency of vulnerabilities for which CISA has credible evidence of active in-the-wild exploitation. KEV launched in November 2021 under Binding Operational Directive 22-01, which makes remediation of listed CVEs mandatory for U.S. Federal Civilian Executive Branch (FCEB) agencies within a stated deadline (typically two to three weeks). Each entry includes the CVE, product, short description, required action, due date, and the date added. By 2025 the catalog held over 1,300 CVEs across operating systems, network appliances, VPNs, RMM, productivity software, and ICS. Despite its formal scope being U.S. federal, KEV has become the de facto cross-industry prioritization signal — many enterprise vulnerability-management programs and cyber insurers treat KEV inclusion as a 'patch immediately' marker, and many ASPM/CSPM platforms surface KEV status alongside EPSS, CVSS, and reachability data. KEV is widely paired with the EPSS score (Exploit Prediction Scoring System) for risk-based vulnerability management.
如何防御 CISA Known Exploited Vulnerabilities (KEV) Catalog?
针对 CISA Known Exploited Vulnerabilities (KEV) Catalog 的防御通常结合技术控制与运营实践,详见上方完整定义。
CISA Known Exploited Vulnerabilities (KEV) Catalog 还有哪些其他名称?
常见的别称包括: KEV, Known Exploited Vulnerabilities。
● 相关术语
- vulnerabilities№ 663
已知被利用漏洞(KEV)
由美国 CISA 确认正在被实际利用并加入公开 KEV 目录的 CVE,会触发美国联邦机构的修复时限。
- vulnerabilities№ 285
CVE(通用漏洞披露)
为每个已披露的软件或硬件漏洞分配唯一标识符的公共目录,使其能在全行业被明确引用。
- vulnerabilities№ 287
CVSS(通用漏洞评分系统)
由 FIRST 维护的开放框架,根据漏洞的利用特征和影响,为其打出 0–10 的严重性评分。
- vulnerabilities№ 428
EPSS(漏洞利用预测评分系统)
由 FIRST 维护、基于数据驱动的模型,用于估计某个 CVE 在未来 30 天内被实际利用的概率。
- vulnerabilities№ 1343
漏洞
系统、应用或流程中可被攻击者利用以破坏机密性、完整性或可用性的弱点。
- defense-ops№ 1345
漏洞扫描
自动化对系统、应用或容器进行探测,根据已知漏洞特征生成潜在弱点清单的过程。