Map your assets to the KEV. Practical howto: export what you actually run, cross-reference it against CISA's Known Exploited Vulnerabilities CSV or JSON feeds, then apply BOD 26-04-style tiers with internet-facing systems first.

This drill is distinct from "check the KEV feed first," which taught feed-first literacy on a Chromium worked example. Here the centre of gravity is asset inventory meeting the catalog, then tiered clocks. No exploit steps. No proof-of-concept content.

Step one — inventory that can answer product names. Pull installed software from endpoint management, MDM, vulnerability scanners, SBOMs, and network device inventories. Normalise vendor and product strings enough to match KEV rows. If your CMDB can't say where Apache, Cisco, Chromium, or a VPN concentrator lives, fix inventory before you argue about severity. Write the discovery method into the ticket so next week's person isn't archaeology.

Tap to enlarge

Step two — fetch the KEV feed from the agency, not from a screenshot. Open cisa.gov/known-exploited-vulnerabilities-catalog and the CSV or JSON distribution your operations team trusts. Snapshot daily if you automate; date-stamp the file if you don't. Diff today against yesterday. New CVE IDs are the only rows that should create adrenaline.

Step three — join inventory to KEV. Match on CVE where your scanner already mapped one, and on vendor/product where you must hunt. Produce a short list: asset, owner, CVE, internet-facing yes/no, last seen. Human-readable beats a thousand unmatched SIEM events. Keep legacy estates in the join; forgotten lab networks are how KEV rows become incidents.

Step four — apply BOD 26-04-style tiers without pretending you are FCEB unless you are. Factors in the directive's spirit: exposure, KEV membership, whether exploitation is automatable, and whether impact is total or partial. Highest-risk combinations inherit the three-calendar-day thinking plus forensic triage where the matrix says so. Internet-facing assets jump the queue inside any tier. Lower combinations may land on fourteen days, sixty days, or fix-on-upgrade logic — still tracked, not ignored.

Internet-facing first, explained. A KEV on a public VPN, mail gateway, or web app is a different operational object from the same CVE on an air-gapped build laptop. BOD 26-04's exposure variable exists for that reason. If you can only patch twenty systems today, patch the ones that answer on the open internet before the ones that don't. Then still patch the others on their tier clocks.

Worked pattern, defender-only. New KEV row appears in the September wave. Diff catches CVE-ID. Inventory join finds twelve assets: three internet-facing, nine internal. Label exposure. Estimate automatable and impact using CISA definitions or your signed SSVC process — don't guess from a blog comment. Open three emergency changes for the exposed set; open standard changes for the internal set with the tier due date in the title. No lab exploit. No "validate with PoC." Validate with version strings and config state after the vendor fix.

Distinct from check-the-kev-feed-first. That howto stressed catalog page literacy, CSV/JSON habit, and a Chromium CVE as practice. This howto stresses CMDB quality, join logic, exposure flags, and BOD 26-04 tier application after the join. Keep both. Don't merge into one slurried checklist that forgets either feed ops or asset truth.

Artefacts. Feeds: CISA KEV CSV/JSON. Directive mindset: BOD 26-04 (10 June 2026). Priority: internet-facing first. Outputs: dated feed snapshot; join table; tickets with CVE IDs and tier due dates; post-change version evidence. Sources: CISA.gov; defensive explainers aligned to BOD 26-04. Forbidden outputs: exploit code, reproduction steps, payload samples.

Automation sketch at human altitude. A small job that pulls JSON, diffs CVE IDs, queries your asset API for product matches, and opens a draft ticket queue is enough machinery for a mid-size estate. Fancy AI triage is optional; honest exposure flags aren't. If automation can't see shadow IT browsers or forgotten appliances, schedule a quarterly discovery walk.

Legacy equally in scope. Windows holdouts, old appliances, deferred update rings, and conference-room systems that still browse or terminate TLS are where "we mapped the KEV" statements go to die. Decommission is a valid remediation. Ignoring isn't. Equal dignity for old metal is how you stop being surprised.

Forensic triage note when tiers demand it. On rows that inherit three-day-plus-triage thinking, check for prior compromise per your IR playbooks and CISA's triage guidance before you declare victory with a patch alone. Triage is defensive assessment, not an excuse to run attacks against production "to see if it works."

Weekly rhythm you can keep. Monday: feed diff and join. Same day: internet-facing tickets. Tuesday–Wednesday: remaining high tiers. Thursday: legacy and exceptions board. Friday: verify samples and close with CVE IDs in titles. Mid-week KEV adds trigger an out-of-band diff. The feed is the pager.

Federal versus everyone else. If you are FCEB, live due dates and required actions come from CISA's directive and the live KEV row — believe the agency over a newspaper. If you aren't, still map assets to KEV and still prefer exploited-in-the-wild over theoretical criticals. Steal the method. Print the caveat.

Common mistakes. Matching on severity instead of CVE and product. Leaving exposure blank. Opening one ticket for fifty assets with no owners. Chasing PoCs from random repositories. Measuring success by ticket close count instead of version evidence on the exposed set. Fix the mistakes; keep the map.

Tooling questions for vendors. Can your VM platform ingest KEV JSON daily? Can it flag internet-facing from CMDB or scan metadata? Can ticket templates carry BOD-style tier fields? If the answer is three nos, your "KEV programme" is a PDF ritual. Buy or build until at least the first two are yes.

Ownership and escalation. Every joined row needs a named human or team, not a shared inbox black hole. If the internet-facing set can't be patched inside the tier window, escalate for mitigation — remove from internet, WAF virtual patch only as documented temporary control, or take offline — and record why the clock slipped. Mitigation that changes exposure can change the tier; update the flag when you do it.

Close. Inventory what you run. Cross-ref CISA KEV CSV/JSON. Apply BOD 26-04-style tiers with internet-facing first. Distinct from the feed-first Chromium drill. No exploit steps — ever. Snapshot, join, tier, patch, verify. Map your assets to the KEV, then touch the metal that answers on the open network before anything else.