New KEV Additions — March 2025 Week 2
| CVE | Vendor | Product | CVSS | Deadline |
|---|---|---|---|---|
| CVE-2025-24054 | Microsoft | Windows NTLM | 6.5 | 2025-04-01 |
| CVE-2025-26633 | Microsoft | MMC | 7.0 | 2025-04-01 |
| CVE-2025-24983 | Microsoft | Win32k | 7.0 | 2025-04-01 |
| CVE-2025-24985 | Microsoft | Windows NTFS | 7.8 | 2025-04-01 |
| CVE-2025-24993 | Microsoft | Windows NTFS | 7.8 | 2025-04-01 |
| CVE-2024-20439 | Cisco | Smart Licensing | 9.8 | 2025-04-01 |
What Is the KEV Catalog?
CISA's Known Exploited Vulnerabilities catalog is a curated list of CVEs with confirmed active exploitation. Federal agencies (BOD 22-01) must remediate KEV entries within specified deadlines.
For private sector: While not mandatory, KEV additions represent CISA's highest-confidence threat intelligence and should be treated as immediate patch priorities.How to Use KEV in Your Patch Process
- Subscribe to KEV RSS feed or API for real-time notifications
- Map KEV entries to your asset inventory weekly
- Escalate KEV-matching vulnerabilities outside normal patch windows
- Use KEV status in vulnerability scanner reports to prioritize remediation