Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s Known Exploited Vulnerabilities (KEV) Catalog launched in November 2021 with approximately 290 entries: about 200 vulnerabilities from 2017–2020 and 90 from 2021. It has continued to grow, but those launch figures and selected addition notices do not establish today’s total. The “must-patch” requirement is also narrower than the catalog’s audience: Binding Operational Directive 22-01 applies to federal civilian executive branch (FCEB) agencies, while CISA urges all organizations to prioritize KEV vulnerabilities.

How large was the KEV Catalog when it launched?

CISA’s November 2021 fact sheet describes an initial publication of approximately 200 vulnerabilities dated 2017–2020 and 90 from 2021—approximately 290 entries altogether. That is the launch baseline, not a current count. CISA’s catalog is maintained over time, and the dated notices below are examples rather than a complete record of every change. The catalog URL was not included in the cited source materials.

The catalog is not intended to be a census of every publicly disclosed software flaw. CISA describes it as a list of known exploited vulnerabilities that pose significant risk to the federal enterprise; additions are based on evidence of active exploitation. The focus is therefore on vulnerabilities with evidence of exploitation and consequential risk, rather than disclosure alone.

What additions show how the list expanded?

Selected CISA notices illustrate that the catalog continued to receive entries after launch. Their counts describe additions in those announcements, not the size of the catalog at the time or a complete annual total.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date What CISA announced
November 2021 Initial publication: approximately 200 vulnerabilities dated 2017–2020 and 90 from 2021, or approximately 290 entries. CISA, 2021 fact sheet
March 28, 2022 32 additions based on evidence of active exploitation. CISA, 2022 alert
July 9, 2024 Three additions based on evidence of active exploitation. CISA, 2024 alert
September 29, 2025 Five additions, affecting products including Adminer, Cisco IOS/IOS XE, Fortra GoAnywhere MFT, Libraesva Email Security Gateway, and sudo. CISA, 2025 alert

The examples also show that the affected technology is varied. Other CISA notices in 2025 named legacy Microsoft software, WinRAR, Citrix Session Recording, and Git; the catalog is not confined to one vendor or product category.

Additions alone cannot be used to calculate a reliable live total. CISA has also corrected the catalog: a 2024 notice records that it removed CVE-2021-4043 after a transcription error. A current count must come from the current catalog data, not by adding selected announcements to the launch figure. The 2024 correction notice URL was not included in the cited source materials.

Who is legally required to patch KEV vulnerabilities?

Binding Operational Directive 22-01 requires FCEB agencies to remediate catalog vulnerabilities by the due dates specified for those entries. CISA alerts identify that directive as applying to FCEB agencies. The word “must” in this context refers to that binding federal requirement, not a universal legal rule for every organization.

CISA’s recommendation is broader. In its September 29, 2025 alert, the agency says: “Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice.” CISA, September 29, 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That distinction matters for private companies, state and local governments, and other organizations: CISA’s encouragement to use KEV does not, by itself, make BOD 22-01 binding on them. Separate laws, contracts, or sector-specific rules may impose other obligations, but they are outside the scope of the directive described here.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should organizations outside the directive use the catalog?

For organizations not covered by BOD 22-01, KEV is a prioritization input, not a substitute for their own vulnerability-management process. CISA’s recommendation supports using the catalog to help identify affected assets, assess exposure, and plan remediation. Each organization still needs to determine which listed products and versions it operates and how to address them in its environment.

Do not treat a KEV listing as proof that every installation is exposed, or assume that the catalog supplies one deadline binding on every reader. The directive’s due dates apply to its covered federal agencies; other organizations should follow obligations that apply to them and use CISA’s prioritization guidance within their own risk and remediation processes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.