Definition
The US cybersecurity agency's list of vulnerabilities confirmed to be actively exploited in the real world, with deadlines for federal agencies to patch them. It doubles as an operational alert feed for all organisations, and its entries are treated as urgent because attackers are already using them.
Why it matters
When a vulnerability appears on the KEV list — especially one chained by autonomous agents — it signals immediate, in-the-wild risk that boards should expect security teams to prioritise ahead of routine patching.