Defense  ·  Glossary

CISA Known Exploited Vulnerabilities (KEV) Catalog

The US cybersecurity agency's list of vulnerabilities confirmed to be actively exploited in the real world, with deadlines for federal agencies to patch them. It doubles as an operational alert feed for all organisations, and its entries are treated as urgent because attackers are already using them.
When a vulnerability appears on the KEV list — especially one chained by autonomous agents — it signals immediate, in-the-wild risk that boards should expect security teams to prioritise ahead of routine patching.
CISA KEV Catalog
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →