Future TechnologyFuture Technology
Security

How to Check the CISA KEV Catalog and Find Out What Is Being Exploited Today

· 2 min read · By Future Technology

Key takeaways

  • CISA maintains a free public catalog of vulnerabilities that attackers are provably exploiting, updated continuously
  • Two new CVEs went into KEV on 1 September, and a critical JFrog Artifactory flaw at CVSS 9.8 was exploited within days of disclosure
  • Working through the catalog against your own internet-facing devices takes about twenty minutes and needs no security background
  • KEV entries carry federal remediation deadlines that work as a reasonable benchmark for everyone else

There is a free public list of the software flaws that criminals are provably using today, and almost nobody outside a security team ever opens it. It is the CISA Known Exploited Vulnerabilities catalog, usually shortened to KEV, and it is the difference between patching everything and patching the things that are currently on fire.

This week alone CISA added CVE-2026-82078 and CVE-2026-81578 on 1 September. Separately, attackers began exploiting a critical JFrog Artifactory flaw, CVE-2026-82329 at CVSS 9.8, within days of public disclosure. That one is an authentication bypass leading to admin access. Six more flaws went into the catalog in late August covering NetScaler, Linux and SQL Server, plus an actively exploited N-able N-central bug that was added after customers were compromised.

What KEV actually is

Most vulnerability databases list everything that has ever been reported, which runs to hundreds of thousands of entries and is useless as a to-do list. KEV only contains flaws with confirmed evidence of exploitation in the wild. That makes it short enough to be actionable.

Each entry carries a remediation deadline that US federal agencies are legally required to meet. You are almost certainly not a federal agency, but those dates are a decent benchmark for how urgent the wider security community thinks a given flaw is.

The twenty minute version

  1. Write down every internet-facing thing you actually run. The router counts. So does the NAS, the security camera, the home server, and the old VPN appliance nobody has logged into since 2023.
  2. Search each vendor and product against the catalog at cisa.gov. It is searchable and does not require an account.
  3. Check the due date column on anything that matches. A date that has already passed means the flaw has been under active exploitation for a while.
  4. Subscribe to the KEV RSS feed instead of remembering to check manually.
  5. For anything on the list you cannot patch today, take it off the public internet. A device behind a firewall with no port forward is a much smaller problem than the same device with an open port.
  6. Repeat monthly, and again after any headline breach involving software you use.

If you are not sure what of yours is currently reachable from outside, start with our guide on how to check whether your server is exposed to the internet. The Zimbra CVE-2026-73570 exploitation case is a good example of how quickly a KEV entry turns into real compromises.

The part people skip

Patching is only half of it. Most of the KEV entries that matter to individuals rather than enterprises get exploited after credentials leak, not before. Hardware-backed two factor closes that gap on the accounts that matter most, and a YubiKey 5 NFC is the standard option that works across a phone and a laptop without an app in the middle. Our Android security checklist covers the free steps first if you would rather not spend anything.

Checking KEV costs nothing and turns a vague background fear into a task with an end. The catalog is public precisely so that people outside government use it.

Some links in this article are affiliate links. We may earn a small commission at no extra cost to you.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.