Known Exploited Vulnerabilities Catalog
In effectCISA · CISA guidance · November 3, 2021
Summary
CISA's list of vulnerabilities known to be exploited in real attacks, launched with Binding Operational Directive 22-01; agencies must fix listed vulnerabilities on the deadlines CISA's directives set.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- CISA guidance
- Issued
- November 3, 2021
- Status
- In effect
Still in force, possibly with amendments.
BOD 26-04 replaced BOD 22-01 on June 10, 2026, and KEV listing remains one of the risk factors that sets agency remediation deadlines.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.