Glossary / practitioner vulnerability frameworks hardening

CISA KEV

Known Exploited Vulnerabilities catalogue plus BOD 26-04 deadlines. If it is on KEV and you are internet-facing, treat exposure as an incident trigger, not a backlog item.

CISA KEV / known exploitedCVEhas an idEvidencein the wildFix existspatch / mitigateIf it is on KEV and you are exposed, it is near the front of the queue.

CISA's Known Exploited Vulnerabilities (KEV) catalogue lists CVEs with evidence of real-world exploitation and a clear mitigation. US federal civilian agencies get binding due dates. Australian operators are not bound by those dates, but KEV is still one of the strongest public signals that a patch is being raced in the wild.

BOD 26-04 (Prioritizing Security Updates Based on Risk) is how CISA turns KEV into a clock for federal systems: apply the vendor mitigation by the due date, and for many edge appliances run the forensic triage steps in the BOD implementation guidance before you declare the box clean. When this desk cites a KEV due date (for example NetScaler CVE-2026-19490 due 12 September 2026), read it as a prioritisation hint for internet-facing gear you actually run — not as an AU legal deadline.

Practical intake: internet-facing or identity-plane product + KEV entry = same-day owner, change record, and either patch, compensate, or isolate. Pair KEV with vendor PSIRT and ASD/ACSC product alerts. KEV is not a complete threat model and it lags fresh zero-days; it is the exploited-class queue jumper.

Live catalogue: cisa.gov/known-exploited-vulnerabilities-catalog. This desk seeds curated cards ahead of the live KEV upsert so duplicate CVE rows stay off the river.

Fact source: CISA Known Exploited Vulnerabilities Catalog.