Signal vs noise

CISA KEV vs NVD: what a CIO should actually watch

Updated 2026-08-28

NVD is the encyclopedia of CVEs. CISA KEV is the short list of vulnerabilities being exploited. A CIO without a SOC should watch KEV first, then critical CVEs on named SaaS vendors.

NVD answers “what exists.” KEV answers “what is on fire.”

The National Vulnerability Database records CVEs as they are published, scored, and sometimes revised. It is necessary. It is also a firehose. Tens of thousands of entries a year, many with delayed or missing scores, many for software you do not run.

CISA’s Known Exploited Vulnerabilities catalog is a much shorter list: vulnerabilities CISA believes are being used in the wild, with a required action and (for federal agencies) a due date. It lags some private intel. It is still the highest-signal public patch list a company without Mandiant can get.

What this means if you do not have a vuln-management team

If you operate servers, you still need NVD (or a scanner) joined to an inventory. If you mostly buy SaaS, your first question is not “are we on last week’s CVE list?” It is “did CISA just add a name we pay, or a cloud/identity parent we depend on?”

ZeroDayTracker uses KEV as the primary feed and adds recent critical NVD CVEs that match the same catalog. That is a deliberate compromise: more than KEV-only, far less than “subscribe to Microsoft in OpenCVE.” CIOs should be able to explain the rule in one sentence.

Do not throw CVSS away. Do not lead with it.

A CVSS 10 with no exploitation is a scheduled patch. A KEV entry with a middling score and known ransomware use is tonight. Recorded Future sells the richer version of that ranking. CISA KEV is the public version. Start there.

All guides · SaaS KEV tracker

Watch the SaaS that holds your data.

Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.

Start watching — freePricing