CISA Known Exploited Vulnerabilities: Overview

The Known Exploited Vulnerabilities (KEV) Content Pack is available as an add-on for BigFix. It is a collection of BigFix Fixlets that is derived from extensive research of the CISA KEV catalog, NVD, and Vendor Advisories. This KEV Content Pack provides BigFix operators with the ability to quickly identify endpoints with vulnerabilities that are high-risk and time-sensitive given that they are known to have been exploited or are actively being exploited.

The KEV Content Pack focuses on vulnerabilities associated with the devices that are in scope for BigFix. For a list of supported CVEs, refer to BigFix Wiki at BigFix Known Exploited Vulnerabilities (KEV) Content Pack.

The KEV Content Pack highlights how it has been divided into four distinct sections such as Windows, NIX, MacOS, and Mobile streamlining the management of multiple operating systems and enhancing the overall efficiency of vulnerability scanning.

Currently, both the legacy site and new sites are enabled for the Known Exploited Vulnerabilities (KEV). However, for optimal performance and smoother functionality, it is recommended to switch to the new site, which is organized by operating system family. Disabling the legacy site will help avoid conflicts or redundancy.
Legacy Site Name
Known Exploited Vulnerabilities Content Pack
Note: This is the older version of the site.
New Site Names
Known Exploited Vulnerabilities Content Pack for Windows
Known Exploited Vulnerabilities Content Pack for NIX
Known Exploited Vulnerabilities Content Pack for MacOS
Known Exploited Vulnerabilities Content Pack for Mobile