Data source resources

CISA KEV

CISA KEV is an external confirmed-exploitation signal used by DevSecure Intelligence to help vendors and security teams understand which CVEs have real-world attack evidence.

What is CISA KEV?

The CISA Known Exploited Vulnerabilities catalog lists vulnerabilities that CISA has identified as exploited in the wild. It is an external authoritative source maintained by CISA.

Why confirmed exploitation matters

Confirmed exploitation is stronger than theoretical severity alone. It shows that attackers have used the vulnerability outside a lab or scoring model.

How DevSecure Intelligence uses KEV

DevSecure Intelligence treats KEV membership as a confirmed exploitation signal alongside CVSS, EPSS, exploit evidence, source coverage, and patch intelligence.

How KEV affects prioritisation

A KEV-listed CVE is ranked with elevated external-risk context because known exploitation changes the urgency of review and exposure validation.

DevSecure does not own or publish the CISA KEV catalog. For the authoritative catalog, use CISA's official source.

Official CISA KEV catalog