Skip to content

Known Exploited Vulnerabilities Catalog

In effectCISA · CISA guidance · November 3, 2021

Summary

CISA's list of vulnerabilities known to be exploited in real attacks, launched with Binding Operational Directive 22-01; agencies must fix listed vulnerabilities on the deadlines CISA's directives set.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
CISA guidance
Issued
November 3, 2021
Status
In effect

Still in force, possibly with amendments.

BOD 26-04 replaced BOD 22-01 on June 10, 2026, and KEV listing remains one of the risk factors that sets agency remediation deadlines.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.