Preview draft · Pending review by the publication’s editor.

A useful starting point

CISA’s Known Exploited Vulnerabilities catalog identifies vulnerabilities with evidence of exploitation. It can help a team separate an active threat from a large backlog of findings. It does not replace an asset inventory or a full risk assessment.

Turn a record into a decision

Our suggested workflow is to match the affected product to your inventory, check the vendor’s instructions, assign an owner and record the result. Consider internet exposure, business importance and recovery options alongside exploitation evidence.

Verify the finish line

A closed ticket is useful only when the fix has been checked. Record the installed version or mitigation, the verification time and any remaining exception. Catalog deadlines should be read with their stated scope; a federal remediation deadline is not automatically every business’s deadline.

Sources & further reading

Our practical suggestions are editorial guidance. Verify applicability against current source and vendor instructions.

Suggest a correction →