Kai Ole Hartwig

name of the term: CISA KEV
descriptions of the term:

Definition

Definition. The KEV catalogue (Known Exploited Vulnerabilities) is maintained by the US agency CISA. It lists CVEs with documented attacks in the wild. Each entry names the product, the date it was added and the required action. The catalogue is public and available as machine-readable JSON.

Why it matters. The CVSS score says how severe a flaw would be. KEV says whether it is being exploited right now. For operators of TYPO3, PHP and Kubernetes stacks that is the better basis for priorities. Not every critical CVE is on fire, but every KEV entry is.

Example. An image scan finds forty CVEs in the base image. The pipeline matches them against the KEV feed. Two hits block the deploy, the rest goes into the regular patch cycle.

Related. CVE, CVSS, RCE, SBOM

Synonyms: KEV, CISA-KEV, Known Exploited Vulnerabilities
Type of term: acronym
Language of the term (2 char ISO code): en
Back