Glossary
What Is a Known Exploited Vulnerability?
How KEV Intelligence defines known exploited vulnerabilities, what evidence counts, and how this differs from severity-only prioritisation.
Definition
Known Exploited Vulnerability
A known exploited vulnerability (KEV) is a Common Vulnerabilities and Exposures (CVE) identifier with credible evidence of exploitation in the wild.
Severity scores such as CVSS describe how bad a flaw could be; KEV status answers a different question: are attackers actually exploiting it?
Only a small fraction of published CVEs are ever exploited. Security teams use KEV intelligence to cut through vulnerability noise and prioritise remediation, detection, and temporary controls on the CVEs that matter operationally.
Prioritisation
KEV vs High Severity
A high CVSS score does not mean a vulnerability is exploited. Conversely, some actively exploited flaws may not dominate scanner severity rankings.
Exploitation-led prioritisation complements (and often overrides) severity-only queues.
Evidence
What Evidence Counts?
KEV Intelligence treats a CVE as a known exploited vulnerability when attestation sources document known exploitation. Valid sources can include:
- KEV Intelligence honeypot and sensor evidence of exploitation attempts mapped to a CVE
- Vendor advisories that explicitly state active exploitation or observed attacks
- Official known exploited vulnerability catalogs
- High-trust exploitation reporting and threat intelligence
- Credible public reporting that documents exploitation in the wild
A generic patch advisory, public PoC, scanner template, or exploitability claim alone is not enough. Full rules are in the KEV Intelligence methodology.
Catalogs
CISA KEV and Beyond
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) maintains an official Known Exploited Vulnerabilities catalog. It is authoritative and valuable — and KEV Intelligence includes it.
KEV Intelligence also tracks additional exploited vulnerabilities not yet in CISA KEV, with confidence scoring, enrichment, RSS delivery, and proprietary sensor telemetry. See KEV Intelligence vs CISA KEV.
Next step
Browse the Live Catalog
The live list of known exploited vulnerabilities tracked by KEV Intelligence — with confidence, CISA status, and sensor flags — is on the KEV feed.