What the KEV catalog adds
The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score.
The short version
The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score.
What happened
The KEV catalog is a standing subject on the Security desk. The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score. The page keeps that sentence so a trend headline does not have to. A reader who arrived from a wire line can use the sources instead of the headline. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names.Futureweb.
The record
The record for The KEV catalog is the CISA Known Exploited Vulnerabilities catalog and BOD 22-01's reliance on it. Treating every CVE as exploited, or treating a high score as proof of use, misreads both lists. Futureweb files the distinction here and leaves the source documents in the box, linked, rather than pasted. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names. The sources for The KEV catalog are listed below and are the place a quote should be verified.
The document
The document to open for The KEV catalog is the CISA Known Exploited Vulnerabilities catalog and BOD 22-01's reliance on it. The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score. A second page that repeats a vendor adjective without this document has not added a fact. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names.
Why it matters on this desk
On the Security desk, The KEV catalog matters because a reader has a check they can perform. A reader checks whether the identifier is in the catalog and what deadline the entry names. The desk files the check. It does not file a slogan in place of the check. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names. The sources for The KEV catalog are listed below and are the place a quote should be verified.Security.
What a reader can check
A reader checks whether the identifier is in the catalog and what deadline the entry names. That is the check for The KEV catalog. Treating every CVE as exploited, or treating a high score as proof of use, misreads both lists. If the check cannot be done from the documents, the page is ahead of the record and should say so. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names. The sources for The KEV catalog are listed below and are the place a quote should be verified.Software.
Where accounts differ
Accounts of The KEV catalog differ when one source states The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score. and another skips the condition. Treating every CVE as exploited, or treating a high score as proof of use, misreads both lists. This page does not average those accounts into a third claim neither document made. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names.
What to watch next
What to watch for The KEV catalog is a revision of the CISA Known Exploited Vulnerabilities catalog and BOD 22-01's reliance on it, or a shipping change that makes Treating every CVE as exploited, or treating a high score as proof of use, misreads both lists. either more common or impossible. The URL stays. The text changes when the document changes. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names. The sources for The KEV catalog are listed below and are the place a quote should be verified.memory safety in the release notes.
What would change this page
This page on The KEV catalog would change if the CISA Known Exploited Vulnerabilities catalog and BOD 22-01's reliance on it redefined the term, or if a measurement showed Treating every CVE as exploited, or treating a high score as proof of use, misreads both lists. was the wrong failure. Until then the definition above is the one the desk will quote. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names. The sources for The KEV catalog are listed below and are the place a quote should be verified.the key stays with the holder.
What is still specific
What stays specific to The KEV catalog is the pair of facts in the opening: The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score. A reader checks whether the identifier is in the catalog and what deadline the entry names. Neighboring pages on the Security desk answer a different question and should not be merged into this one. The KEV catalog is named again here so the check is hard to miss: A reader checks whether the identifier is in the catalog and what deadline the entry names.
Sources
The reports this brief is filing. Futureweb did not republish them.
Questions
What is The KEV catalog?
The Known Exploited Vulnerabilities catalog is CISA's list of flaws it says are being used, which is a different fact from a flaw that merely has a high score.
Which document defines The KEV catalog?
Start with the CISA Known Exploited Vulnerabilities catalog and BOD 22-01's reliance on it. The sources box has the link.
What fails if The KEV catalog is ignored?
Treating every CVE as exploited, or treating a high score as proof of use, misreads both lists.
What can a reader check about The KEV catalog?
A reader checks whether the identifier is in the catalog and what deadline the entry names.
Does a wire headline replace this page on The KEV catalog?
No. A wire line links to the outlet. This URL is Futureweb's definition.