Glossary
Known Exploited Vulnerabilities (KEV)
What Are Known Exploited Vulnerabilities (KEV)?
The Known Exploited Vulnerabilities (KEV) catalog, maintained by CISA, is a list of CVEs that are known to be actively exploited in the wild — treated as the highest-priority subset of vulnerabilities for remediation in U.S. federal agencies and increasingly in private sector programs.
A KEV-listed vulnerability is no longer theoretical: someone, somewhere, is using it against real targets. KEV status is one of the most reliable signals for prioritizing remediation, and is built into modern vulnerability management workflows. NetRise Turbine enriches CVE findings with KEV status so teams focus on exploited, not just exploitable.
Related Terms
CVE · Exploit Prediction Scoring System · Vulnerability Management · Execution-Aware Reachability


