Definition
What is CISA KEV?
Also: CISA KEV
CISA's public list of CVEs with confirmed exploitation in the wild — strong evidence for the CRA's 'actively exploited' test.
A catalogue maintained by the US Cybersecurity and Infrastructure Security Agency listing vulnerabilities with reliable evidence of active exploitation, with dates and required remediation actions for US federal agencies. For CRA manufacturers a KEV listing of a shipped component is a strong signal that the 'actively exploited' threshold may be met for their product and should trigger an immediate reportability review; it is not by itself a legal determination.
Reference: CISA KEV catalogue
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.