The Government Keeps a List of Bugs Hackers Are Using Right Now, and It Is Free
I was up early this morning going through the weekly vulnerability reports the way I have for most of the last twenty years, and I fell down a rabbit hole that I think every small business owner needs to hear about, because it changed how I do patching and it did not cost me a dime.
Here is the short version. There is a government agency called CISA, the Cybersecurity and Infrastructure Security Agency, and they maintain a public list called the Known Exploited Vulnerabilities catalog, or KEV for short. It is not a list of every bug that exists. It is a list of the bugs that attackers are confirmed to be using against real companies right now. When a vulnerability lands on that list, it is because somebody has already been hit with it.
You can read it for free at cisa.gov, no login and no subscription, and most business owners I talk to have never heard of it.
Why this matters more than the score on the patch
If you have ever had an IT person or an MSP hand you a vulnerability report, you have probably seen a column full of severity scores. Critical, High, Medium, Low, or a number from 1 to 10. The problem is that Microsoft alone shipped somewhere north of 960 fixes on this month's Patch Tuesday, and a good chunk of those were rated High or Critical. Nobody with a twelve person office and one part-time IT guy is patching 960 things this week.
So how do you decide what goes first?
That is the question KEV answers. The score tells you how bad a bug could be in theory. KEV tells you which bugs are actually being used. Those are two very different lists, and the second one is a lot shorter.
Just to give you a feel for the pace, CISA added four entries on September 22 and two more on September 27. Some of the ones that came due this week were a SharePoint Server flaw (CVE-2026-65660) that attackers were using to drop webshells, and a pair of Citrix NetScaler bugs (CVE-2026-88771 and 88772) that let someone in from the outside with no password at all. If you run either of those products, that is your patch list for this week, however long the rest of the report is.
The part nobody tells you about
Each KEV entry comes with a due date. That date is the deadline federal agencies are required to patch by under a binding directive, and it is usually two to three weeks from the day the bug is added. Your business is not bound by that directive, but I would argue that if the federal government has decided a bug is dangerous enough that every agency has to fix it in fourteen days, that is about as clear a signal as you are going to get for free.
I treat those dates as my own SLA. If it is on KEV, it gets patched inside the federal window, and everything else waits its turn behind it.
How to actually use it without an IT department
You do not need a security team to put this to work. Here is what I do, and what I would tell a friend who owns a business to do.
Know what you run — you cannot check a list against an inventory you do not have. Write down the products that sit on the edge of your network, meaning your firewall, your VPN, your email server, your remote access tool, and anything with a public login page. That is where the KEV hits cluster.
Check the list once a week — CISA publishes a short alert every time they add entries, and you can subscribe by email. Monday morning, coffee in hand, five minutes. Search the catalog for your vendors.
If there is a match, that is job one — however busy the week is, whatever else is on the report, the KEV match gets patched first and it gets patched inside that federal due date.
Write down that you did it — this is the step everyone skips. Your cyber insurance renewal is going to ask how you prioritize vulnerabilities, and "we patch the ones on the government's exploited list within the federal deadline" is an answer an underwriter understands.
Where I can help
I built a couple of things for exactly this problem, because I got tired of doing it by hand.
The first is a free KEV Triage Checklist, a one-page PDF that walks through the steps above and adds a second signal called EPSS, which is a probability score for how likely a bug is to be exploited in the next thirty days. Between KEV and EPSS you can cut a 900 line report down to the ten things that matter.
The second is the Remediation SLA Calculator, also free, a single file you open in your browser that takes a severity and a discovery date and tells you the date it needs to be fixed by. No install, no account, nothing leaves your machine.
If you are the person who has to prove the patching happened, not just do it, that is what RemedyOps is for. It turns any scanner's output into a tracked, dated, auditable remediation workflow inside GitHub, so when the insurance form or the client's auditor asks for evidence, you have it. And if you need to explain all of this to a business owner in plain English, ClarityOps takes the raw scanner export and turns it into a branded report a non-technical reader can act on.
All of it is at opstacks.net.
I started OpStacks because I have watched IT tools drain the budgets of small businesses for two decades, and in a year like this one that can be the difference between making payroll and not. The KEV catalog is one of the few things in this industry that costs nothing and does exactly what it says. Go look at it this week, and let me know what you think.
Curtis
opstacks@outlook.com · opstacks.net
Sources: CISA Known Exploited Vulnerabilities Catalog (cisa.gov/known-exploited-vulnerabilities-catalog); CISA KEV alerts of September 22 and September 27, 2026; Help Net Security, "September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor" (Sept 9, 2026); TechJack Solutions, Weekly Security Intelligence Briefing, week of September 28, 2026.