Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is the CISA Known Exploited Vulnerabilities (KEV) catalog?
Updated
CISA's KEV catalog lists CVEs with reliable evidence of active exploitation. As of last verification, CISA Binding Operational Directive 26-04 (issued 10 June 2026) is current, having revoked BOD 22-01's flat 14-day rule for risk-tiered FCEB timelines. For everyone else, KEV is guidance, not a mandate.
What-is-KEV guide, last verified 10 September 2026 against CISA Binding Operational Directive 26-04 (issued 10 June 2026) and its published Implementation Guidance, the KEV catalog's own criteria page, and the now-revoked BOD 22-01 text for historical contrast. This page is not legal advice, does not determine that any directive applies to YOU, and does not start a clock.
This is the current directive, not YOUR mandate
Audience: a security lead, engineering manager, or compliance owner who has heard 'KEV' used as shorthand for 'CISA says patch this in 14 days' and needs to know whether that is still true. This page is not legal advice. It does not start a clock. Reading it does not start a clock. This product does not patch YOUR estate — a named human still owns remediation timing and any exception.
As of last verification on 10 September 2026, the flat 14-day-from-KEV-listing rule is not current law. CISA Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, issued 10 June 2026, states in its own background section: 'This Directive supersedes and hereby revokes BOD 19-02: Vulnerability Remediation Requirements for Internet-Accessible Systems (April 29, 2019), and BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities (Nov. 3, 2021).' Both older directives were revoked the same day BOD 26-04 was issued. Some third-party materials written before or shortly after that date, including some public writing this site itself has not yet updated everywhere, may still describe BOD 22-01's flat 14-day rule as current — it is not, as of this verification.
The KEV catalog itself was not eliminated. BOD 26-04 explicitly says it 'evolves upon CISA's KEV Catalog' — the catalog CISA established in 2021 under the now-revoked BOD 22-01 continues, maintained at the same address, under the new directive's remediation framework.
- Kind of text: BOD 26-04 is a legal requirement, but only for US federal civilian executive branch (FCEB) agencies — it is issued under 44 U.S.C. § 3553 and binds federal agencies under § 3554(a)(1)(B)(ii). It does not, by its own scope section, apply to contractors unless a procurement contract says otherwise, and it does not bind state, local, tribal, territorial governments, critical infrastructure operators, or private-sector organizations at all. For everyone outside that scope, KEV listing is CISA guidance and best practice.
- A dedicated what-is-vulnerability-management pillar is not on this site yet. Naming it is not a link. The how-to-prioritize guide and the vulnerability-vs-exploit-vs-risk guide on this site are live siblings.
The KEV catalog itself, unchanged in purpose
The KEV catalog is CISA's authoritative, continuously updated list of CVEs with reliable evidence of active exploitation in the wild — not every serious vulnerability, only ones CISA has verified are actually being exploited. That purpose has not changed across the BOD 22-01-to-BOD 26-04 transition. Last verified 10 September 2026. Not legal advice.
| Attribute | What CISA states |
|---|---|
| What it lists | CVE IDs with reliable evidence of active exploitation in the wild, maintained by CISA at cisa.gov/known-exploited-vulnerabilities-catalog. |
| Formats | HTML, CSV, and JSON feeds, plus a JSON schema; CISA also provides vulnerability metadata (KEV status, exploit automatability, technical impact) to the CVE database via its Vulnrichment Program. |
| How CISA describes intended use | As an input to an organization's own vulnerability-management prioritization framework — not a complete vulnerability inventory and not, by itself, a full risk assessment. |
| Known limitation | It is a lagging indicator by construction: a CVE is added once exploitation has been observed and verified, so a vulnerability under fresh active exploitation may not be listed yet. Absence from KEV is weak evidence of safety, not proof. |
BOD 22-01 (revoked) versus BOD 26-04 (current) — what actually changed
BOD 22-01, issued 3 November 2021, established the KEV catalog and required FCEB agencies to remediate every KEV-listed vulnerability by a due date CISA set per-entry, with a default outer cap the directive described as 14 calendar days for vulnerabilities with a due date CISA did not otherwise specify. BOD 26-04 replaced that flat structure. This page does not reproduce BOD 26-04's Table 1 cell-by-cell — that table is published as a graphic in the primary source, not as extractable text, and this page will not invent numbers for cells it cannot quote. Last verified 10 September 2026. Not legal advice.
- This page states the shape of the change qualitatively and quotes what CISA's own directive text says about the fastest tier (three days plus forensic triage). For the complete Table 1 matrix — every combination of the four variables mapped to its exact remediation timeline — CISA publishes that as Table 1 in the directive itself; this page does not quote it cell-by-cell and does not invent numbers for combinations it has not verified.
- CISA's four variables — asset exposure, KEV status, exploit automatability, technical impact — are published per-CVE through CISA's Vulnrichment Program for KEV status, automatability, and technical impact; asset exposure is an organization's own determination, guided by CISA's Internet Exposure Reduction Guidance.
| Aspect | BOD 22-01 (issued 3 Nov 2021 — revoked 10 June 2026) | BOD 26-04 (issued 10 June 2026 — current) |
|---|---|---|
| Status | Revoked. BOD 26-04's own text states it 'supersedes and hereby revokes' BOD 22-01. | Current directive for FCEB agencies as of last verification. |
| Core structure | Every KEV-listed CVE gets a due date CISA sets per catalog entry, historically described as defaulting to a 14-day outer cap absent a different CISA-set date. | A four-variable risk model: asset exposure (publicly exposed or not), KEV status, exploit automatability, and technical impact (partial or total control) together determine which of several remediation tiers a finding falls into. CISA states this is informed by the SSVC methodology. |
| Fastest tier | The shortest due dates under BOD 22-01 were still measured in days from KEV listing, without a separate forensic-triage step named in the directive. | The most urgent tier requires remediation or mitigation within a short window (CISA states three calendar days in the directive's own text) plus a forensic-triage investigation into whether the asset was already compromised — described in CISA's separately published Implementation Guidance. |
| Lowest-risk tier | BOD 22-01 did not define a deferred, 'wait for the next upgrade' tier; every KEV entry carried a due date. | A vulnerability that is not publicly exposed, not KEV-listed, and not automatable can be deferred to the asset's next scheduled system upgrade rather than patched off-cycle. |
| Primary reference scheme | CVSS base severity was one common input organizations layered on top of the flat due-date structure. | CISA states BOD 26-04 does not require CVSS as the primary prioritization mechanism; the four-variable, SSVC-informed model replaces that role for FCEB timeline purposes. |
Phased rollout — Phase I, II, and III, not one date
BOD 26-04 rolls out in three phases from its 10 June 2026 issuance date. Public CISA and FedRAMP materials describe agencies updating policy immediately, refining processes within roughly 60 days (placing that milestone in early-to-mid August 2026), and meeting the new remediation timelines in full within roughly 180 days (placing that milestone around early December 2026). This page states those windows approximately, from the directive's own phase structure, rather than asserting an exact calendar date this page has not independently confirmed against the primary text for every phase boundary. Last verified 10 September 2026. Not legal advice.
| Phase | Timing from 10 June 2026 issuance | What CISA's directive text requires |
|---|---|---|
| Phase I | Effective immediately. | Review and, as appropriate, update agency vulnerability-management policies; monitor KEV catalog updates and aggressively mitigate per KEV remediation timelines; continue automated status reporting via the CDM Dashboard; continue Cyber Hygiene scanning. |
| Phase II | Within 60 days of issuance — approximately early-to-mid August 2026. | Update agency vulnerability-management processes and procedures to support ongoing remediation based on the CVE database (or an equivalent service) and the KEV catalog. |
| Phase III | Within 180 days of issuance — approximately early December 2026. | Remediate each vulnerability no later than the timelines in Table 1; continuously identify and tag all internet-reachable agency-owned assets; ensure all CDM-reported assets include full associated IP addressing. |
Who this binds — FCEB agencies only
BOD 26-04's own scope section is explicit: it applies to agency assets in a 'federal information system' as OMB Circular A-130 defines that term, and it names the agencies it binds as 'Federal Civilian Executive Branch' (FCEB) agencies. It does not, by its own text, apply to contractors unless the governing procurement contract says otherwise, and national-security systems and certain Department of War / Intelligence Community systems are excluded by the underlying statute. Last verified 10 September 2026. Not legal advice.
| Entity | Bound by BOD 26-04? | What KEV is for that entity instead |
|---|---|---|
| US federal civilian executive branch (FCEB) agencies | Yes. Legal requirement under 44 U.S.C. §§ 3552–3554, implemented through this directive. | Not applicable — BOD 26-04 is the binding text itself. |
| Federal contractors | Only if the governing procurement contract incorporates the requirement; agencies are directed to review contracts and determine what modifications are necessary. | Absent that contractual flow-down, KEV listing is a strong prioritization signal, not a directive obligation. |
| State, local, tribal, and territorial (SLTT) governments | No. BOD 26-04 binds FCEB agencies, not SLTT governments. | CISA guidance and best practice; CISA explicitly encourages SLTT and critical-infrastructure entities to use SSVC and KEV voluntarily. |
| Private-sector organizations generally | No. | CISA guidance and best-practice signal, alongside FIRST EPSS and CVSS. Treat a KEV listing as one of the strongest available fix-first signals, not as a law that applies to you. |
Legal requirement versus CISA guidance versus best practice
The table below labels each text. Do not treat CISA guidance as binding you if you are not an FCEB agency, and do not treat KEV listing itself as optional evidence just because it does not bind you legally. Last verified 10 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| 44 U.S.C. §§ 3552–3554 (FISMA authorities) | Legal requirement — statutory authority for DHS/CISA to issue binding operational directives to FCEB agencies. | Does not determine that YOU are an FCEB agency or contractor covered by a flow-down clause. |
| CISA BOD 26-04 (issued 10 June 2026, current) | Legal requirement — binds FCEB agencies only. Revokes and supersedes BOD 22-01 and BOD 19-02. | Does not bind non-FCEB organizations. Does not start a remediation clock for YOU unless you are an FCEB agency. |
| CISA BOD 22-01 (issued 3 Nov 2021) | Revoked, effective 10 June 2026. No longer current law for any agency. | This page does not restate its flat 14-day rule as current. Some older third-party writing may still do so in error. |
| CISA KEV catalog criteria and Vulnrichment Program | CISA guidance describing how CVEs are added to KEV and how exploit-automatability/technical-impact metadata is published. | Does not itself bind non-FCEB organizations; it is the data BOD 26-04's FCEB timelines are built on. |
| CISA SSVC methodology and guide | CISA guidance, offered for voluntary adoption by any organization. Also the methodology BOD 26-04 states it draws on for FCEB timelines. | Does not require YOU to adopt SSVC. The how-to-prioritize guide on this site covers SSVC as one of several prioritization approaches. |
What to do now
As of last verification on 10 September 2026, BOD 26-04 is current, BOD 22-01 and BOD 19-02 are revoked, and Phase III's full-timeline deadline is approaching (roughly early December 2026 from the directive's own phase structure). The list below is operational, not a determination that BOD 26-04 or any other directive applies to YOU.
- If you are an FCEB agency, or a contractor whose contract may flow BOD 26-04 down, read the directive and its Implementation Guidance directly — including the full Table 1 — rather than relying on this page's qualitative summary.
- If you are not FCEB-bound, treat KEV listing as a strong, evidence-based prioritization signal, not a legal deadline. Combine it with FIRST EPSS and CVSS, as the how-to-prioritize guide on this site walks through.
- Correct any internal documentation, runbooks, or vendor materials that still cite BOD 22-01's flat 14-day rule as current federal policy — as of 10 June 2026 it is revoked.
- Do not treat this page, or any product surface, as tracking your organization's compliance with BOD 26-04. A named human still owns that assessment, and FCEB agencies should confirm directly with CISA where this page's summary and the primary source appear to diverge.
Where this shows up in ShipReady Metrics
Signed-in app → Security → Findings surfaces CISA KEV status as one ranking signal alongside FIRST EPSS and CVSS for vulnerabilities ingested from connected scanners (Dependabot, code scanning, secret scanning, DAST, and first-party SAST where configured), with cross-source deduplication and transitive-npm blast-radius analysis.
The product does not implement BOD 26-04's FCEB-specific remediation-tier logic, does not determine whether your organization is an FCEB agency or contractor bound by that directive, does not file agency reports to CISA or OMB, and does not patch YOUR estate. A named human still owns any BOD 26-04 compliance determination and any remediation SLA the organization sets.
This page does not document a public demo URL. There is no public vulnerability-management demo path.
Primary sources (last verified 10 September 2026)
Every directive claim on this page is taken from one of these. CISA Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk (issued 10 June 2026), including its own statement that it 'supersedes and hereby revokes BOD 19-02 ... and BOD 22-01.' CISA's Implementation Guidance for BOD 26-04. CISA's Known Exploited Vulnerabilities catalog page and its published inclusion criteria. CISA Binding Operational Directive 22-01 (issued 3 November 2021), read for historical contrast only — it is revoked, not current law. These are not a complete world list. Not legal advice.
The how-to-prioritize guide on this site is the decision-order page combining KEV, EPSS, and CVSS. The vulnerability-vs-exploit-vs-risk guide on this site covers what KEV listing does and does not tell you about a specific instance. A dedicated what-is-vulnerability-management pillar is not on this site yet. Naming it is not a link.
Frequently asked questions
Is the CISA KEV catalog still the '14-day rule'?
No, not as current federal policy. That flat 14-day default came from BOD 22-01 (2021), which CISA Binding Operational Directive 26-04, issued 10 June 2026, explicitly revoked the same day it took effect. BOD 26-04 replaced the flat rule with a four-variable, risk-tiered remediation structure for FCEB agencies. The KEV catalog itself continues; the remediation-timeline rule around it changed.
Does BOD 26-04 apply to our company?
Only if you are a US federal civilian executive branch agency, or a federal contractor whose procurement contract specifically flows the requirement down. It does not bind state, local, tribal, or territorial governments, critical-infrastructure operators generally, or private-sector organizations outside a federal contract. For everyone else, KEV is CISA guidance and a strong best-practice prioritization signal, not a legal mandate. This page does not determine your status.
What are the exact new remediation timelines under BOD 26-04?
CISA publishes those timelines in BOD 26-04's Table 1, built from four variables: asset exposure, KEV status, exploit automatability, and technical impact. The directive's own text states the most urgent tier requires action within three calendar days plus a forensic-triage investigation. This page does not reproduce Table 1 cell-by-cell — read the primary source for the complete matrix rather than relying on a secondhand table.
Is a CVE not being on the KEV catalog proof that it is safe?
No. KEV is a lagging indicator by construction — CISA adds a CVE once exploitation has been observed and verified, so exploitation that started this week may not be listed yet. Absence from KEV is weak evidence of safety, not proof. This holds whether or not BOD 26-04 binds your organization.
Does ShipReady track BOD 26-04 compliance for FCEB agencies?
No. Signed-in Security → Findings surfaces KEV status as a ranking signal alongside EPSS and CVSS, but it does not implement BOD 26-04's specific FCEB remediation-tier logic, does not determine FCEB status, and does not file agency reports. A named human at an FCEB agency still owns that compliance determination directly with CISA.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.