CISA KEV (Known Exploited Vulnerabilities)
Also known as: Known Exploited Vulnerabilities catalog
The CISA KEV catalog is a U.S. government list of vulnerabilities that are confirmed to be actively exploited in the wild — making it one of the highest-signal sources for vulnerability prioritization.
Maintained by the Cybersecurity and Infrastructure Security Agency (CISA), the Known Exploited Vulnerabilities catalog flags CVEs that attackers are demonstrably using, often with a remediation due date for federal agencies. Because inclusion means real-world exploitation (not just theoretical risk), KEV entries should be triaged first.
Vigil ingests the KEV catalog continuously and matches each new entry against your specific technology stack, so you hear about an actively-exploited flaw in your firewall or VPN vendor immediately — not buried in a feed of thousands of CVEs.