Research · Exploitation timing

How fast do vulnerabilities get exploited?

NVD publication → CISA KEV listing · snapshot 2026-08-31

Across the 98 recently-disclosed vulnerabilities in our verified corpus that CISA later confirmed exploited in the wild, the median time from NVD publication to KEV listing was 6 days.

21 of 109 (19%) were listed as exploited at or before their NVD record was even published — exploitation that ran ahead of public disclosure.

Time from NVD publication to KEV listing

Exploited at or before NVD publication
21 (19%)
1–7 days after publication
32 (29%)
8–30 days
23 (21%)
31–90 days
11 (10%)
91–365 days
10 (9%)
Over a year later (legacy back-cataloging)
12 (11%)

n = 109 vulnerabilities in our corpus with both an NVD publication date and a CISA KEV listing date.

Why we report the median, not the mean

Two different things land a CVE in KEV. Most are recently disclosed and confirmed exploited within days (median 6 days, n = 98). A minority are old vulnerabilities CISA back-catalogs years after disclosure — a 2008 CVE added in 2026 carries a ~6,500-day “lag” that describes cataloging, not exploitation speed. Those 12 legacy cases drag the mean to hundreds of days while the median stays a robust 8 days across the full sample. We report the median and show the whole distribution so you can see both populations.

Method & what this sample is

Lag = (CISA KEV dateAdded) − (NVD publication date), in days, per CVE. Both dates come straight from NVD and the CISA KEV catalog — authoritative sources, never generated.

This is a convenience sample: the 109 KEV vulnerabilities in our verified corpus for which we hold an NVD publication date — not the full 1685-entry KEV catalog. It reflects the vulnerabilities we cover, which skew recent, so treat it as indicative of current exploitation tempo rather than a census. Snapshot as of 2026-08-31.

Which vendors are exploited most →  ·  How we verify

🤖 Generated deterministically from NVD publication dates and the CISA KEV catalog. Median is robust to the legacy back-cataloging tail; the figure updates as the corpus grows.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.