June 4, 2025
CISA Known Exploited Vulnerability Catalog – May 2025
For a detailed CISA’s KEV Catalog, download the pdf file here

Summary
The Known Exploited Vulnerability (KEV) catalog, maintained by CISA, is the authoritative source of vulnerabilities that have been exploited in the wild.
It is recommended that all organizations review and monitor the KEV catalog, prioritize remediation of listed vulnerabilities, and reduce the likelihood of compromise by threat actors. In May 2025, twenty five vulnerabilities met the criteria for inclusion in the CISA’s KEV catalog. Of these, seventeen are zero-day vulnerabilities; seven have been exploited by known threat actors and employed in attacks.