CISA Known Exploited Vulnerabilities Catalog Exceeds 1,200 Entries
The CISA KEV catalog surpassed 1,200 actively exploited vulnerabilities in early 2025 and had grown to more than 1,650 entries as of August 2026. Federal civilian agencies must remediate KEV-listed vulnerabilities within timelines mandated by Binding Operational Directive 22-01, and private sector organizations are strongly urged to prioritize these vulnerabilities in their vulnerability management and testing programs.
Key Analytics
Impact Analysis
The expanding KEV catalog underscores the importance of regular penetration testing that goes beyond automated scanning. Many KEV entries involve chained exploits and business logic flaws that only manual testing can identify. Organizations relying solely on vulnerability scanners miss the exploitation context that pentests provide.
Recommended Actions
- Cross-reference KEV catalog with your asset inventory
- Include KEV-listed vulnerabilities in penetration test scoping
- Verify remediation of all applicable KEV entries
- Implement continuous monitoring for newly added KEV entries
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Cross-reference KEV entries against the current asset inventory
- ›Add KEV-listed vulnerabilities to pentest scope and retest coverage
- ›Alerting on newly published KEV entries
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 45 to 95 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.