we_are_coded.by CODE · The world, decoded
БГ
Concept

KEV catalog

The BasicsUpdated on 16 August 2026we are coded

A list of holes in software that, beyond doubt, have already hit someone. Not a forecast, but a proven fact from the US cybersecurity agency.

Checked on16 August 2026
In short: KEV (Known Exploited Vulnerabilities) is a catalogue that CISA (the US Cybersecurity and Infrastructure Security Agency, part of the Department of Homeland Security) has kept since November 2021: a public list of software holes with proof that they're already being used in real attacks, not in theory. The list is called the KEV catalog, and it's something like a list of confirmed cases, not suspected ones. If a hole is on it, it's already hurt someone before it made the list. US government institutions have a deadline to close it, or they count as violators.

A technical detail that explains everything: every known software hole gets a unique number, a CVE, issued by an international cataloging system. There are thousands of holes, most never touched by anyone outside a research lab. CISA takes from that mass only the ones with hard confirmation that a real attacker has already used them, and puts them in KEV. The difference isn't a nuance. The difference is a chasm: one is 'theoretically possible', the other is 'already happened'.

In practice it works like this. A new hole comes out, someone reports seeing an attack through it, CISA verifies it and adds it with a mandatory deadline, usually two to three weeks, for every US federal agency to patch it. In July 2026 alone, new entries were added within days. This isn't a bureaucratic slip of paper. It's a timer, started the moment it's added.

The catalog launched in 2021 and today holds over 1,300 entries. It exists because companies and institutions are drowning in warnings about thousands of potential holes and don't have the resources to patch everything at once. KEV tells them what's on fire right now, and what's only on paper. The priority shifts from 'how dangerous is it theoretically' to 'how dangerous is it in practice, because it's already been used'.

It's used by far more people than it sounds. US federal agencies are required to by law, but private companies around the world, including here, feed the KEV list directly into their security software, so it lights up red automatically when something in their systems matches an entry in the catalog. This is the list a real security team builds its workday around.

KEV doesn't look forward. It looks back - a protocol for the past: every entry on the list means someone was already a victim, before it ever reached the catalog.

Watching the staging

The most honest part of this list is exactly what makes it valuable: the delay. You only make it onto it after the harm has already been done somewhere. That's why I don't look at KEV as an alarm system. I look at it as an autopsy protocol - one that happens to update fast enough to save the next victim.

For me, as someone who builds software systems, this is the simplest possible filter against noise: thousands of warnings, one dimension that actually matters, whether it's already hit someone. Everything else is theory, and theory doesn't hurt.

The visual is generated code art. No third-party images.
Official primary sources
→CISA: the KEV catalog (Known Exploited Vulnerabilities)→CISA: why KEV is the patching priority