Exploited vulnerabilities: the difference between severe and actually used
Tens of thousands of vulnerabilities are published each year and a small fraction are ever used against anyone. One federal catalogue is the closest thing to an official record of which ones - and it is short.
At a glance
- The catalogue
- CISA's Known Exploited Vulnerabilities list - entries require evidence of active exploitation
- Cadence
- Small batches, most weeks - one to eight entries at a time through 2026
- The teeth
- A binding directive obliges federal civilian agencies to remediate listed items on a deadline
- What it is not
- A severity ranking. A critical score with no observed exploitation does not qualify
Three different things that get called the same thing
A vulnerability is a flaw. It gets an identifier, a description and usually a severity score, and tens of thousands are published every year. The score is an assessment of how bad exploitation would be if it happened - it says nothing about whether anyone has ever tried.
An exploit is working code that uses the flaw. Its existence is a completely separate fact from the flaw's severity, and many high-scoring vulnerabilities never acquire one because they are difficult to reach, require conditions that rarely hold, or simply are not worth the effort compared with easier routes.
A zero-day is a flaw being exploited before a fix exists. That is a statement about timing relative to the vendor, not about severity, and it is the narrowest of the three categories. Conflating these is the most common error in reading security news: a headline about a critical vulnerability and a headline about active exploitation describe different situations with very different consequences.
A severity score answers "how bad if". The catalogue answers "is anyone actually doing it". Only the second one changes what you should do today.
What the catalogue is for
It exists to force prioritisation. No organisation can remediate everything published, so the catalogue answers the only question that reliably narrows the list: which of these is being used right now. Entry requires evidence of active exploitation rather than a severity threshold, which is what makes it short and useful where a severity-ranked list is long and paralysing.
It carries an obligation, and that is what separates it from every private threat feed. A binding directive establishes vulnerability management requirements for federal civilian agencies and requires them to prioritise rapid remediation of listed items. The deadline is real for those agencies, and because the catalogue is public, everyone else uses it as a free, curated priority list with government resourcing behind the curation.
It also functions as a dated public record, which is what makes it usable for markets. An entry has a date and an identifier, and additions arrive in small batches most weeks - four on 18 August 2026, three the week before, and batches of one to eight through the year. A contract about whether a particular product's flaw becomes known-exploited by a date resolves against a published list with a timestamp.
- Entry requires evidence of exploitation, not a severity score.
- A binding directive makes remediation mandatory for federal civilian agencies.
- Dated entries in small weekly batches — a settleable public record.
1Discovery
By a researcher, a vendor, or an attacker using it first
2Identifier and severity score
Published; the score says how bad it would be, not whether it is happening
3Patch available
Or not — a flaw exploited before this point is what zero-day means
4Evidence of active exploitation
The threshold for the catalogue, and a completely separate fact from severity
Where a vulnerability stops being theoretical
5Catalogue entry
Dated, identified, published in a small batch most weeks
The artefact a contract can actually resolve against
6Remediation deadline
Binding on federal civilian agencies; a free priority list for everyone else
What is published and what is not
The catalogue itself is public, machine-readable and free, with each entry naming the affected product, the identifier, the date added and the remediation due date. Alerts accompany each batch. For a subject that feels closed and specialist, the primary source could hardly be more open.
What is not published is the evidence. An entry states that exploitation has been observed; it does not say by whom, against whom, at what scale or with what success. That is deliberate - the sourcing is frequently sensitive - but it means the catalogue tells you that a flaw is being used and almost nothing about how widely. Treating an entry as a measure of scale rather than of existence is a misreading.
Vendor advisories are the complementary source and they run on their own schedules, with the largest vendors publishing on fixed monthly cycles. Those cycles are predictable and are one of the few calendars in this domain, which matters for any contract whose deadline sits near one.
- The catalogue: public, machine-readable, dated, with remediation deadlines.
- The evidence behind an entry: deliberately not published.
- Vendor advisories: fixed monthly cycles, and a rare predictable calendar here.
Behind the subscription
The rest of this entry is the part that changes a decision: what moves the price, which contract sets it, who ships it and where that can be cut off.
What determines whether a flaw gets used
Why reachability beats severity in predicting exploitation, why exploitation often rises after a patch rather than before, and the entire attack category that never appears in this catalogue.
Where this shows up in a price
Why a catalogue entry moves a vendor's equity less than the coverage suggests, and how to use exploitation rates as the base rate behind an incident contract.
How an exploit reaches an attacker
The three competing buyers for the same vulnerability research, how quickly an exploit commoditises after a patch, and why the defensive flow structurally loses that race.
How to use this
How to convert catalogue cadence into a base rate for an incident contract, the severity-versus-exploitation gap in every headline, and why an absence of entries is not evidence of safety.
Included with a subscription
Create an account to unlock the full entry — price drivers, trading venues, trade flows and the live markets attached to it.
Frequently asked questions
- What is the KEV catalogue?
- CISA's list of vulnerabilities with evidence of active exploitation. Entry requires observed exploitation rather than a severity threshold, which is why it is short and useful where a severity-ranked list is long and paralysing. Entries carry dates and remediation deadlines.
- Is a high severity score the same as being exploited?
- No, and conflating them is the most common error in reading security news. A score assesses how bad exploitation would be; the catalogue records that exploitation is actually happening. Many high-scoring flaws are never used because they are hard to reach or not worth the effort.
- What is a zero-day?
- A flaw being exploited before a fix exists. It is a statement about timing relative to the vendor rather than about severity, and it is the narrowest of the three categories people mix up — flaw, exploit, and zero-day.
- Why does exploitation often rise after a patch?
- Because the patch reveals what was wrong. Once a fix is published, the mechanism becomes analysable, proof-of-concept code circulates within days and automated tooling follows. The window between disclosure and widespread patching is the most productive period for an attacker.
- What does the catalogue miss?
- Attacks that compromise a distribution channel rather than exploit a flaw. Those produce no vulnerability identifier and therefore no entry, however damaging they are — so an absence from the catalogue is not evidence of safety.
Primary sources
Related entries
Prediction markets carry real risk of loss. Nothing on Market Guy is financial advice — it is research tooling to help you think, not a signal to trade.