CISA Opens Known Exploited Vulnerabilities Catalog to Community Nomination for Faster Threat Sharing
On May 21, CISA announced a new online nomination form through which researchers, vendors, and industry partners can submit vulnerabilities for possible KEV catalog inclusion
The structured form addresses a real discoverability gap, but the sourcing weight is thin: two duplicate CISA press releases amplified without independent reporting. Time-to-exploit has compressed to roughly five days, the pressure directly justifying an open submission pipeline. Federal agencies and private-sector teams prioritizing remediation against KEV additions will face a faster, noisier signal as community nominations enter the validation queue. CISA has not publicly committed to the adjudication capacity needed to manage that load. Community nominations at scale, compounded by the deliberate manipulation a structured public form invites, risk converting the KEV from a leading indicator into a lagging one.
4 sources
- CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form
- CISA new KEV nomination form opens reporting to vendors and researchers -
Help Net Security - You can now nominate vulnerabilities for CISA's KEV with this form -
SC Media - CISA to allow researchers to report vulnerabilities to exploited bugs catalog -
The Record by Recorded Future