CISA Expands KEV Catalog with 1,484 New Vulnerabilities as Active Exploitation Surges 20% in 2025
The United States Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog to include 1,484 vulnerabilities as of December 2025. This expansion represents a significant step in the federal…
The United States Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog to include 1,484 vulnerabilities as of December 2025. This expansion represents a significant step in the federal government's efforts to address actively exploited security flaws.
The KEV catalog, which began with 311 vulnerabilities in November 2021, now reflects the increasingly complex threat landscape. In 2025 alone, 245 new vulnerabilities were added, marking a 20% increase over the previous year.
Understanding the KEV Catalog Framework
CISA's KEV catalog enhances vulnerability management by focusing on vulnerabilities with confirmed active exploitation, moving beyond traditional severity ratings.
The catalog is regularly updated based on intelligence about threat actors exploiting these vulnerabilities. Each entry includes information such as the CVE identifier, vendor and product details, and remediation actions with due dates for federal agencies.
Under Binding Operational Directive (BOD) 22-01, federal agencies must remediate vulnerabilities with CVE IDs from 2021 or later within two weeks and older vulnerabilities within six months. CISA encourages all organizations to utilize the KEV catalog for vulnerability management prioritization.
Ransomware Exploitation: A Critical Threat Vector
In 2025, 304 of the 1,484 vulnerabilities were exploited by ransomware groups. Notable vulnerabilities include CVE-2025-5777 and Oracle E-Business Suite vulnerabilities targeted by the CL0P ransomware group.
The following table highlights top vulnerabilities used in ransomware attacks:
CVE ID Vendor Product Vulnerability Type
CVE-2025-55182 Meta React Server Components Remote Code Execution Vulnerability
CVE-2025-61884 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-61882 Oracle E-Business Suite Unspecified Vulnerability
This expansion represents a significant step in the federal government's efforts to address actively exploited security flaws.
CVE-2025-10035 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability
Microsoft leads with 100 ransomware-related vulnerabilities, followed by Fortinet, Ivanti, and Oracle. This highlights the need for effective patch management and security updates for widely used platforms.
Vendor and Product Distribution Analysis
Microsoft accounts for 350 vulnerabilities, nearly 24% of the catalog, reflecting its market presence. Apple, Cisco, Adobe, and Google follow. Microsoft's Windows alone has 159 product-specific vulnerabilities.
The data indicates that widely deployed technologies are attractive targets. Some vendors, such as Adobe and Apache, showed reduced vulnerability additions, suggesting improved security practices.
Common Weakness Enumeration (CWE) Patterns
The KEV catalog reveals patterns in vulnerability types. CWE-20 (Improper Input Validation) is the most common, with 113 instances. CWE-78 (OS Command Injection) ranks second with 97 instances.
Memory corruption issues, including CWE-787 (Out-of-bounds Write) and CWE-416 (Use After Free) , are prominent. CWE-502 (Deserialization of Untrusted Data) also appears frequently.
The catalog's growth reflects the evolving threat landscape. After its launch in November 2021, 2022 saw significant additions, followed by stabilization in 2023 and 2024. In 2025, there was renewed growth with 245 additions.
Year Vulnerabilities Added Cumulative Total
2021 311 311
2022 555 866
2023 187 1,053
2024 186 1,239
2025 245 1,484
In 2025, 94 older vulnerabilities were added, indicating enhanced detection and reporting mechanisms. The oldest entry added was CVE-2007-0671, while the oldest in the catalog is CVE-2002-0367.
High-Impact Additions and Threat Intelligence
In 2025, CISA added critical vulnerabilities with significant exploitation potential, including CVE-2025-61884, CVE-2025-33073, and CVE-2025-2746. These vulnerabilities span various technologies and attack vectors.
Darknet intelligence provided early warnings for several KEV additions, highlighting the importance of monitoring underground forums for emerging threats.
Federal agencies must comply with BOD 22-01, with strict remediation timelines for KEV-listed vulnerabilities. However, the KEV catalog offers valuable intelligence for all organizations to prioritize vulnerability remediation.
Based on reporting by Cyber Security News.
