For as long as I’ve worked in cybersecurity, defenders have faced the same math problem: more vulnerabilities than any team can patch, and not enough signal about which ones actually matter. Frontier AI is now rewriting that math. As increasingly capable models find and analyze vulnerabilities at machine speed, the volume and velocity of vulnerability discovery are about to accelerate dramatically. The question for every security leader is simple: Can your ability to understand, prioritize, and reduce risk keep pace?
At TrendAI™, the enterprise business unit of Trend Micro, our answer starts with something we’ve been doing for decades - and a commitment we’re deepening, not discovering.
Why CISA KEV is cybersecurity’s most practical signal
The Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) Catalog is a list of vulnerabilities with evidence of active exploitation in the wild. As of mid-2026, it includes more than 1,300 entries and keeps growing every week. That makes it one of the most practical prioritization signals in security: it tells defenders what attackers are already using, not what they theoretically could use.
TrendAI™ has long focused its virtual patching and vulnerability response on exactly these kinds of high-consequence flaws, and we are reinforcing that focus. Every vulnerability in the KEV Catalog is one attackers are actively exploiting - so fixing it delivers real, measurable risk reduction, not protection against a hypothetical.
What our customers are saying
“CISA KEV is one of the most practical signals in cybersecurity because it tells defenders what attackers are already using,” Mark Houpt, CISO, DataBank. “But as AI changes the speed of vulnerability discovery, security teams will need to move from static prioritization toward continuous decision-making and action. The organizations that can turn vulnerability intelligence into risk reduction fastest will have an important advantage.”
Virtual patching: protection before the patch
Virtual patching shields known vulnerabilities at the network and workload layer before a vendor fix is available or can be deployed, protecting systems while official patches are tested and rolled out. It’s the difference between waiting on a patch cycle and being protected today.
This capability is powered by original research from the TrendAI™ Zero Day Initiative™ (ZDI), the world’s largest vendor-agnostic bug bounty program. TrendAI™ ZDI research feeds directly into TrendAI Vision One™, so customers get patching protections up to 115 days before vendor patches ship. In a world where AI compresses the time between vulnerability discovery and exploitation, that head start matters more than ever.
Why no single catalog will be enough
Here’s the honest part: as AI increases the volume and velocity of vulnerability discovery, no single catalog or scoring system - KEV included - can provide the complete context an enterprise needs to determine what matters most.
The future of vulnerability management will depend on combining multiple signals: evidence of active exploitation, vulnerability intelligence, organizational exposure, asset and business context, and emerging threat activity. And it will depend on AI continuously weighing those signals to determine where action reduces the most risk. For TrendAI™, KEV is an important benchmark in that evolution, not the destination.
Shortening “time to zero”
We think about our goal as shortening “time to zero;” the time between vulnerability discovery and deployed, proactive risk reduction. Depending on the vulnerability, the affected service, your environment, and whether a vendor fix exists, the right response might be a virtual patch, new detection logic, compensating controls, or policy updates. What can’t change is the direction: as vulnerabilities arrive faster, protection has to arrive faster too.
AI is what makes this possible at scale. Across TrendAI Vision One™, we’re combining TrendAI™ ZDI research, exploit intelligence, exposure context, and business risk to drive AI-assisted prioritization, so security teams can make better decisions and take action using every available signal.
What security leaders should do now
If you’re thinking about how to prepare for AI-accelerated vulnerability discovery, start here: Measure your organization against the KEV Catalog, because it represents proven, active risk. Ask whether you have proactive protection like virtual patching-for the window between disclosure and patch deployment. And start moving from static, score-based prioritization toward continuous, context-aware decision-making.
The next era of vulnerability management won’t be defined by who finds the most vulnerabilities. It will be defined by how quickly organizations can understand and act on them. The organizations that turn vulnerability intelligence into risk reduction fastest will have an important advantage, and we intend to make sure our customers are among them.
Frequently asked questions
What is the CISA KEV Catalog? The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities Catalog is an authoritative list of vulnerabilities known to be actively exploited by attackers, used by defenders worldwide to prioritize remediation.
What is virtual patching? Virtual patching protects against exploitation of a known vulnerability at the network or workload layer before an official vendor patch is available or can be safely deployed.
How does TrendAI™ prioritize vulnerabilities? TrendAI™ combines the CISA KEV Catalog, original TrendAI™ ZDI vulnerability research, exploit intelligence, organizational exposure, and business context, using AI in TrendAI Vision One™ to continuously determine where action reduces the most risk.
About the author
Rachel Jin is chief platform and business officer at TrendAI™; which is Trend Micro's enterprise AI security business. She has spent more than two decades in cybersecurity across engineering, product management, and executive leadership.