How this tracker is built
Twice a day a scheduled job fetches the official CISA JSON feed, normalises the field names, and compares every record against the copy we already hold. Anything that differs is written to the change log in the sidebar. Nothing on this page is edited by hand.
If a fetch fails, we keep the previous data and its original verified date. You will see the timestamp go stale rather than see fresh-looking data that is actually old. After three consecutive failures the page carries a warning banner and we get an email.
What the labels mean
- Ransomware — CISA has confirmed the vulnerability was used in a ransomware campaign. That is their field, not our judgement.
- Critical / High / Medium — the NVD CVSS v3.1 base score. KEV entries carry no severity of their own.
- Patched — a fix is available and we have seen no exploitation reported in 90 days. The entry stays in the catalog regardless.
Why the due dates matter to you
The due date is the deadline by which US federal civilian agencies must remediate, under Binding Operational Directive 22-01. It is not a deadline for anyone else.
It is still the most useful urgency signal available, because CISA sets it based on how actively the flaw is being used rather than on CVSS. A two-week due date means something is on fire right now.
Known limitations
KEV is not a complete list of exploited vulnerabilities. It is the list CISA has confirmed and chosen to publish. Absence from this catalog is not evidence that something is safe.
Vendors also occasionally revise affected version ranges after publication. Where that happens, the revision appears in the change log rather than silently replacing what was there before.