CISA KEV
Using CISA's Known Exploited Vulnerabilities catalog to turn confirmed exploitation into accountable, time-bound remediation changes.
A CISA KEV entry changes the character of a vulnerability discussion. It is no longer only a score, scanner finding, or item waiting for the next maintenance cycle; it is evidence that exploitation has been observed and that exposure needs an operational response. Vulnerability management identifies affected assets, security leaders establish urgency, and change owners must decide how to contain, patch, validate, and communicate the work. For federal agencies, CISA BOD 26-04 adds deadline pressure. For everyone else, the catalog is still a useful forcing function because it tests whether asset inventory, ownership, maintenance windows, and compensating controls can support a rapid decision.
The material here follows that conversion from advisory to change queue. It covers reading a KEV entry accurately, assigning parallel owners, weighing available patches against incomplete fixes, and documenting a justified exception when remediation cannot finish on the preferred timetable. It also distinguishes a real deadline plan from a ticket with an urgent label: affected service scope, change authority, implementation sequence, verification, and a credible fallback all need to be visible. CABs can use these pieces to make KEV intake repeatable without pretending that every exploited vulnerability has the same operational answer. The objective is a short, accountable path from confirmed risk to a recorded reduction in exposure.
Start here
-
How to Read a CISA KEV Entry and What to Do Next
Builds the interpretation discipline needed before teams translate a catalog entry into a remediation plan.
-
KEV Batch Triage: Three Owners, Two Deadlines, One Update
Illustrates how ownership and timing must be separated when several urgent items arrive together.
More on CISA KEV
-
This Week in Change Risk — Week of Aug 31, 2026
AI infrastructure hit the CISA KEV catalog hard this week: LiteLLM, Kestra, and JFrog joined nine new exploited CVEs. Plus SonicWall, PaperCut, and DORA.
-
This Week in Change Risk — Week of Aug 24, 2026
A CVSS-10.0 Oracle flaw with CISA's tightest three-day deadline, six more KEV entries, GitHub's outage pledge, and PagerDuty's SRE-agent drop.
-
This Week in Change Risk — Week of Aug 17, 2026
Eight new CISA KEV entries led by a critical VMware vCenter flaw, GitHub's near-8-hour outage post-mortem, and NIS2's October deadline closing in.
-
This Week in Change Risk — Week of Aug 10, 2026
A CVSS 10 Metabase SQL injection in KEV with named victims, Microsoft's ~400-CVE August Patch Tuesday, and NIS2's October deadline closing in.
-
This Week in Change Risk — Week of Aug 3, 2026
A CVSS 9.8 JetBrains TeamCity RCE in KEV, two GitHub Actions outages in two days, Microsoft's Aug 11 Patch Tuesday, and NIS2 pressure this week.
-
N-able N-central KEV: When the Emergency Patch Is Incomplete
CISA added N-able N-central to KEV after an incomplete fix left every build before 2026.3.1.7 exploitable. A CAB playbook for the re-remediation.
-
This Week in Change Risk — Week of Jul 27, 2026
A CVSS 10.0 Arista SD-WAN flaw in KEV, a GitHub Copilot incident, Datadog's DASH launches, and the ECB's AI deadline — the week's change-risk signals.
-
This Week in Change Risk — Week of Jul 20, 2026
KEV batch of 6, a GitHub Actions outage, Datadog's AI incident tooling, and the NIS2 deadline confusion — the week's change-risk signals for CABs.
-
CISA's July 21 KEV Batch: How a CAB Should Triage 4 CVEs
CISA added four exploited CVEs on July 21, 2026 — WordPress, Langflow, and DD-WRT. A change manager's triage playbook under the new BOD 26-04 rules.