Security1 publisher2 min readPublished
CISA marks which KEV vulnerabilities ransomware crews are known to use
The known exploited vulnerabilities catalog now carries a column saying whether CISA has seen each bug used in ransomware campaigns. A companion list does the same for misconfigurations and exposed services.
The Watch · Security desk

What happened
- CISA added a column to the known exploited vulnerabilities catalog titled "known to be used in ransomware campaigns", covering entries already listed and every vulnerability added to the catalog from here on.
- Any organization can now read that determination in the catalog itself; CISA had been delivering it through direct notifications to critical infrastructure entities it identified as vulnerable.
- The Ransomware Vulnerability Warning Pilot behind the flag has initiated notifications for more than 800 vulnerable systems running internet-accessible, ransomware-linked vulnerabilities.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability A defender can pull the flagged subset the day a vulnerability lands in the catalog, without waiting to be scanned and contacted first.
- decision Teams whose patch backlog runs longer than their remediation window now have a published basis for deciding which catalog entries move to the front of the queue.
- exposure Reading an unflagged entry as safe understates it: the column reports what CISA has observed, and ransomware crews use a wider set of bugs.
- constraint Anyone automating against the catalog inherits the ransomware flag but not the weaknesses list, which has to be tracked as a second artifact.
The column's wording sets what the flag means. It indicates whether CISA is aware that a vulnerability has been associated with ransomware [3]. A blank tells you about the agency's visibility, and a crew may still have found a use for the bug.
Until now that determination traveled one way. The Ransomware Vulnerability Warning Pilot, which CISA stood up in January 2023 as required by CIRCIA, identifies vulnerabilities commonly associated with known ransomware exploitation and warns the critical infrastructure entities carrying them [1][2]. You had to be scanned, matched and contacted. The catalog column removes that dependency for anyone who reads the list [4].
The notification channel was narrow. More than 800 vulnerable systems have been notified since the pilot began, all of them running internet-accessible vulnerabilities tied to known ransomware campaigns [6]. Divide 800 by the twelve months from January 2023 and the average is about 67 systems a month for the entire country [11]. The count is a floor and the period is at least a year, so the scale runs in the tens of systems a month. CISA named Energy, Healthcare and Public Health, Water and Wastewater Systems and the Education Facilities subsector among the sectors that benefited [8]. Identification runs off existing data sources, technologies and authorities, including the agency's free cyber hygiene vulnerability scanning service [7].
Enrollment in that scanning service still buys faster and more targeted notifications, and CISA says it is free to any organization in the United States [9].
The second resource covers misconfigurations and exposed services. It is a companion list of misconfigurations and weaknesses known to be used in ransomware campaigns, meant to help organizations spot the services those actors use and apply mitigations or compensating controls [5]. That one sits outside the catalog as its own document. A shop that pulls the catalog gets the ransomware flag with it and has to fetch the weaknesses list separately.
The announcement asks all organizations to review the revised catalog and the list, and it does not set a remediation deadline for the flagged entries [12]. CISA also restated its position that responsibility for secure software should move from the customer to software manufacturers [10].
For a team that already clears every KEV entry inside its window, the column adds no work. Where the backlog runs longer than the window, it says which entries go first.
What to watch
- Whether the ransomware column keeps pace with new KEV additions or lags the notifications RVWP is already sending.
- Whether CISA attaches a separate remediation timeline to the ransomware-flagged subset of the catalog.
- Whether the misconfigurations and weaknesses list is folded into the catalog or stays a standalone document.