New KEV Additions — March 2025 Week 2

CVEVendorProductCVSSDeadline
CVE-2025-24054MicrosoftWindows NTLM6.52025-04-01
CVE-2025-26633MicrosoftMMC7.02025-04-01
CVE-2025-24983MicrosoftWin32k7.02025-04-01
CVE-2025-24985MicrosoftWindows NTFS7.82025-04-01
CVE-2025-24993MicrosoftWindows NTFS7.82025-04-01
CVE-2024-20439CiscoSmart Licensing9.82025-04-01

What Is the KEV Catalog?

CISA's Known Exploited Vulnerabilities catalog is a curated list of CVEs with confirmed active exploitation. Federal agencies (BOD 22-01) must remediate KEV entries within specified deadlines.

For private sector: While not mandatory, KEV additions represent CISA's highest-confidence threat intelligence and should be treated as immediate patch priorities.

How to Use KEV in Your Patch Process

  1. Subscribe to KEV RSS feed or API for real-time notifications
  2. Map KEV entries to your asset inventory weekly
  3. Escalate KEV-matching vulnerabilities outside normal patch windows
  4. Use KEV status in vulnerability scanner reports to prioritize remediation