GCVE BCP-07 Updated: A Directory for Known Exploited Vulnerability Catalogues

GCVE BCP-07 Updated: A Directory for Known Exploited Vulnerability Catalogues

September 1, 2026

 #GCVE#GNA#vulnerability-intelligence#open-source#KEV

GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are published.

The volume of published vulnerability advisories continues to increase, making it increasingly difficult for defenders to treat every vulnerability with the same priority. KEV information provides one of the most useful operational signals for prioritisation: vulnerabilities known or observed to be exploited should receive particular attention.

The GCVE KEV Directory is a catalogue of catalogues. It allows KEV producers—vendors, CSIRTs, security organisations and other observers—to publish a stable entry pointing to their human-readable catalogue, machine-readable feed, and optionally a native BCP-07 feed. This makes distributed KEV information easier to discover, correlate and consume automatically while preserving attribution to the organisation making the exploitation assertion.

At the time of publication, the directory contains KEV sources from CISA, CIRCL, ENISA, The Shadowserver Foundation and Previdian.

We particularly encourage software and hardware vendors to publish their own KEV catalogues. Vendors are often in the best position to confirm exploitation affecting their products, and publishing this information in a machine-readable form can significantly improve vulnerability prioritisation for users, CSIRTs and vulnerability-management platforms.

The GCVE KEV Directory is intentionally open and non-authoritative: multiple organisations can publish independent exploitation assertions about the same vulnerability. BCP-07 provides the common format and attribution model needed to make these different perspectives interoperable.

Overview of KEV catalogue on db.gcve.eu instance