Evidence-backed facts
- Cybersecurity and Infrastructure Security Agency documents known-exploited CVE records, vendors, products, required actions, due dates, and machine-readable catalog files. informative
- Public reads do not grant vulnerability, remediation, directive, asset, incident, or CISA decision authority. informative
- Clients must bind catalog version, CVE identifier, vendor, product, date added, due date, known-ransomware field, and file representation. informative
- Catalog inclusion reflects evidence of exploitation and scoped directives; absence does not prove safety, and inclusion does not establish local exposure or exploitability. informative