Glossary
KEV (CISA Known Exploited Vulnerabilities catalog)
A catalog maintained by the U.S. CISA listing vulnerabilities that are being actively exploited in the wild (Known Exploited Vulnerabilities). Adding a CVE to the KEV means the threat is no longer theoretical: real attacks are underway. The KEV serves as a de facto patch-priority list, including for organizations outside the United States.