CISA KEV catalog
Track CISA’s Known Exploited Vulnerabilities against your program, synced from the live federal feed.
Not all vulnerabilities are equal. The ones attackers are actively exploiting are. Keel syncs CISA’s Known Exploited Vulnerabilities (KEV) catalog from the live federal feed, so the CVEs that matter most are in front of your team instead of buried in a scanner report.
What cisa kev catalog does
Synced from the live CISA feed
The KEV catalog is kept current from CISA’s official feed, so you’re looking at the same authoritative list of actively-exploited vulnerabilities the federal government tracks.
Prioritise what’s exploited
Focus on vulnerabilities with confirmed, in-the-wild exploitation, the ones that warrant urgent attention over a long tail of theoretical CVEs.
In your compliance context
KEV lives alongside your controls, risks, and evidence, so vulnerability intelligence isn’t a separate silo from your program.
Why it matters
- See the vulnerabilities attackers are actually using
- Prioritise remediation by real-world exploitation, not just CVSS
- Stay current automatically from the authoritative CISA feed
Get audit-ready, and prove it
CISA KEV catalog is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
Where does the KEV data come from?
CISA’s official Known Exploited Vulnerabilities catalog, synced from the live feed so it stays current.
What is the KEV catalog?
A US government list of vulnerabilities with confirmed active exploitation, the ones prioritised for urgent remediation across federal agencies and, increasingly, private industry.
Related features: Risk register · Controls & crosswalk