What Is a Known Exploited Vulnerability?
How KEVIntel defines known exploited vulnerabilities, what evidence counts, and how this differs from severity-only prioritisation.
A known exploited vulnerability (KEV) is a Common Vulnerabilities and Exposures (CVE) identifier with credible evidence of exploitation in the wild. Severity scores such as CVSS describe how bad a flaw could be; KEV status answers a different question: are attackers actually exploiting it?
Only a small fraction of published CVEs are ever exploited. Security teams use KEV intelligence to cut through vulnerability noise and prioritise remediation, detection, and temporary controls on the CVEs that matter operationally.
KEV vs High Severity
A high CVSS score does not mean a vulnerability is exploited. Conversely, some actively exploited flaws may not dominate scanner severity rankings. Exploitation-led prioritisation complements (and often overrides) severity-only queues.
What Evidence Counts?
KEVIntel treats a CVE as a known exploited vulnerability when attestation sources document known exploitation. Valid sources can include:
- KEVIntel honeypot and sensor evidence of exploitation attempts mapped to a CVE
- Vendor advisories that explicitly state active exploitation or observed attacks
- Official known exploited vulnerability catalogs
- High-trust exploitation reporting and threat intelligence
- Credible public reporting that documents exploitation in the wild
A generic patch advisory, public PoC, scanner template, or exploitability claim alone is not enough. Full rules are in the KEVIntel methodology.
CISA KEV and Beyond
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) maintains an official Known Exploited Vulnerabilities catalog. It is authoritative and valuable — and KEVIntel includes it.
KEVIntel also tracks additional exploited vulnerabilities not yet in CISA KEV, with confidence scoring, enrichment, RSS delivery, and proprietary sensor telemetry. See KEVIntel vs CISA KEV.
Browse the Live Catalog
The live list of known exploited vulnerabilities tracked by KEVIntel — with confidence, CISA status, and sensor flags — is on the KEV feed.