CISA KEV
Known Exploited Vulnerabilities catalogue. If it is here, someone is using it. Treat exposure as urgent.
CISA's KEV list records CVEs with evidence of exploitation in the wild and a clear mitigation. US federal agencies have binding deadlines. Everyone else should still read it.
Use KEV as a prioritisation input: internet-facing plus KEV is the front of the queue. It is not a complete threat model.
The live catalogue is at cisa.gov. This desk pulls from that feed when the network allows.
