THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by the Cybersecurity & Infrastructure Security Agency (CISA) to help organizations manage vulnerabilities that have been exploited in real-world scenarios. It serves as a crucial resource for vulnerability management prioritization. Users can report new vulnerabilities not listed in the catalog.
The catalog includes detailed entries such as the Gitea Code Injection Vulnerability (CVE-2026-60004), which allows repository access to execute harmful commands. Organizations are guided to follow specific mitigation steps, including compliance with CISA directives. The catalog is available in multiple formats including CSV and JSON.