Vulnerability intelligence

CISA KEV catalog

Track CISA’s Known Exploited Vulnerabilities against your program, synced from the live federal feed.

Start free See pricing
Keel KEV catalog listing known exploited vulnerabilities from the CISA feed

Not all vulnerabilities are equal. The ones attackers are actively exploiting are. Keel syncs CISA’s Known Exploited Vulnerabilities (KEV) catalog from the live federal feed, so the CVEs that matter most are in front of your team instead of buried in a scanner report.

What cisa kev catalog does

Synced from the live CISA feed

The KEV catalog is kept current from CISA’s official feed, so you’re looking at the same authoritative list of actively-exploited vulnerabilities the federal government tracks.

Prioritise what’s exploited

Focus on vulnerabilities with confirmed, in-the-wild exploitation, the ones that warrant urgent attention over a long tail of theoretical CVEs.

In your compliance context

KEV lives alongside your controls, risks, and evidence, so vulnerability intelligence isn’t a separate silo from your program.

Why it matters

  • See the vulnerabilities attackers are actually using
  • Prioritise remediation by real-world exploitation, not just CVSS
  • Stay current automatically from the authoritative CISA feed

Get audit-ready, and prove it

CISA KEV catalog is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

Where does the KEV data come from?

CISA’s official Known Exploited Vulnerabilities catalog, synced from the live feed so it stays current.

What is the KEV catalog?

A US government list of vulnerabilities with confirmed active exploitation, the ones prioritised for urgent remediation across federal agencies and, increasingly, private industry.

Related features: Risk register · Controls & crosswalk