CISA's Known Exploited Vulnerabilities catalogue has grown in recent years into one of the most widely used signals in vulnerability management. For OT environments in the energy sector this raises a concrete question: is the nature of these entries changing, and what does that mean for how you prioritise?
A shift in the kind of vulnerabilities
Where KEV entries initially mostly concerned IT software — operating systems, browsers, office applications — we are seeing a gradual increase in entries that touch equipment also used in industrial environments: network components, VPN solutions and management interfaces of industrial equipment. This is no coincidence: as OT environments become more IP-based and externally connectable, the same attack surface that is abused in IT becomes relevant to OT as well.
Why this matters for asset owners
A KEV entry says something fundamentally different from a high CVSS score: it means there is evidence of actual exploitation, not just a theoretical risk. For a grid operator this means that KEV entries relating to equipment within substations or control centres should by definition be high on the priority list, regardless of the exact CVSS score.
Practical implication: prioritise on evidence, not just on score
A common assumption is that the CVSS score is the only or most important prioritisation factor. In practice the combination of three signals is more effective:
- Is the vulnerability in the KEV catalogue? (proven exploitation)
- Is the affected device reachable from the internet, or reachable from a less trusted zone?
- Is the device used in a critical function, such as substation automation or protection relays?
When all three answers are yes, a vulnerability almost always deserves priority — even if its CVSS score is not the highest on the list.
What this means for 2026 and beyond
For OT security teams in the energy sector, this development means that KEV monitoring is no longer an IT-only matter. Anyone who still bases OT vulnerability management exclusively on vendor advisories is missing a growing part of the relevant threat picture. See the KEV page of this platform for the current energy-related entries (demonstration data in this environment).