A list of holes in software that, beyond doubt, have already hit someone. Not a forecast, but a proven fact from the US cybersecurity agency.
A technical detail that explains everything: every known software hole gets a unique number, a CVE, issued by an international cataloging system. There are thousands of holes, most never touched by anyone outside a research lab. CISA takes from that mass only the ones with hard confirmation that a real attacker has already used them, and puts them in KEV. The difference isn't a nuance. The difference is a chasm: one is 'theoretically possible', the other is 'already happened'.
In practice it works like this. A new hole comes out, someone reports seeing an attack through it, CISA verifies it and adds it with a mandatory deadline, usually two to three weeks, for every US federal agency to patch it. In July 2026 alone, new entries were added within days. This isn't a bureaucratic slip of paper. It's a timer, started the moment it's added.
The catalog launched in 2021 and today holds over 1,300 entries. It exists because companies and institutions are drowning in warnings about thousands of potential holes and don't have the resources to patch everything at once. KEV tells them what's on fire right now, and what's only on paper. The priority shifts from 'how dangerous is it theoretically' to 'how dangerous is it in practice, because it's already been used'.
It's used by far more people than it sounds. US federal agencies are required to by law, but private companies around the world, including here, feed the KEV list directly into their security software, so it lights up red automatically when something in their systems matches an entry in the catalog. This is the list a real security team builds its workday around.
Watching the staging
The most honest part of this list is exactly what makes it valuable: the delay. You only make it onto it after the harm has already been done somewhere. That's why I don't look at KEV as an alarm system. I look at it as an autopsy protocol - one that happens to update fast enough to save the next victim.
For me, as someone who builds software systems, this is the simplest possible filter against noise: thousands of warnings, one dimension that actually matters, whether it's already hit someone. Everything else is theory, and theory doesn't hurt.