IC Technology & Cyber — 2026-05-24

CISA Opens Known Exploited Vulnerabilities Catalog to Community Nomination for Faster Threat Sharing

BLUFOpening community nominations widens KEV's input aperture but shifts the burden to CISA's unproven validation capacity, where adjudication discipline, not submission volume, will determine whether the catalog gains or loses signal value.

On May 21, CISA announced a new online nomination form through which researchers, vendors, and industry partners can submit vulnerabilities for possible KEV catalog inclusion 12. Acting Executive Assistant Director for Cybersecurity Chris Butera said the form "enhances CISA's ability to identify, validate, and quickly share critical threat information," with email submissions to [email protected] remaining available alongside it 1. Nominations must still satisfy CISA's existing criteria: an assigned CVE, confirmed exploitation evidence, and available remediation guidance 23. The Record cited former CISA CIO Robert Costello describing the form as operationalizing the agency's research community partnership, while Qualys analyst Mayuresh Dani noted that prior email submissions left no public record of how many KEV additions they generated 4.

Analysis
The structured form addresses a real discoverability gap, but the sourcing weight is thin: two duplicate CISA press releases amplified without independent reporting. Time-to-exploit has compressed to roughly five days, the pressure directly justifying an open submission pipeline. Federal agencies and private-sector teams prioritizing remediation against KEV additions will face a faster, noisier signal as community nominations enter the validation queue. CISA has not publicly committed to the adjudication capacity needed to manage that load. Community nominations at scale, compounded by the deliberate manipulation a structured public form invites, risk converting the KEV from a leading indicator into a lagging one.
4 sources
  1. CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form
  2. CISA new KEV nomination form opens reporting to vendors and researchers - Help Net Security
  3. You can now nominate vulnerabilities for CISA's KEV with this form - SC Media
  4. CISA to allow researchers to report vulnerabilities to exploited bugs catalog - The Record by Recorded Future

View in full brief →

UNCLASSIFIED // OPEN SOURCE