The United States Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog to 1,484 entries by the end of 2025, reflecting a significant 20% increase in actively exploited vulnerabilities compared to the previous year. This growth, which included the addition of 245 new vulnerabilities in 2025, marks a notable acceleration after a period of stabilization in 2024 and highlights the persistent and evolving threat landscape facing both public and private sector organizations. The KEV Catalog, established under Binding Operational Directive (BOD) 22-01, requires federal agencies to remediate listed vulnerabilities within specified timeframes, focusing on those with confirmed evidence of active exploitation rather than solely on CVSS severity scores.
Analysis of the 2025 KEV data revealed that not only did the number of newly discovered vulnerabilities rise, but the inclusion of older vulnerabilities also increased, with 94 vulnerabilities from previous years added—nearly a 45% jump from the 2023-2024 average. The catalog now includes vulnerabilities dating back to 2002, some of which have been exploited by ransomware groups. CISA also removed at least one vulnerability in 2025 due to insufficient evidence of exploitation. The KEV Catalog continues to serve as a critical resource for prioritizing remediation efforts and understanding the tactics of threat actors actively targeting known flaws across a wide range of software and hardware platforms.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
During 2025, ransomware remained a major driver of exploitation tracked in the KEV catalog, with 304 listed vulnerabilities linked to ransomware activity. Reporting highlighted continued abuse of both newly disclosed and older flaws by ransomware operators.
Across 2025, CISA added 245 new vulnerabilities to the KEV catalog, representing about 20% year-over-year growth. The increase outpaced the trend from the prior two years and included a notable number of older vulnerabilities from 2024 or earlier.
By December 2025, CISA's Known Exploited Vulnerabilities catalog had grown to 1,484 entries, reflecting vulnerabilities with confirmed active exploitation. The catalog continued to serve as a remediation priority list under Binding Operational Directive 22-01 for U.S. federal agencies.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.