CISA Known Exploited Vulnerabilities (KEV)
An authoritative catalog maintained by the U.S. CISA listing CVEs that have confirmed active exploitation in the wild.
The CISA KEV catalog is the gold standard for prioritizing vulnerability remediation. Under Binding Operational Directive (BOD) 22-01, federal agencies and leading enterprises must patch KEV vulnerabilities within strict 14-day deadlines to prevent imminent ransomware and cyber espionage intrusions.