Across the 98 recently-disclosed vulnerabilities in our verified corpus that CISA later confirmed exploited in the wild, the median time from NVD publication to KEV listing was 6 days.
21 of 109 (19%) were listed as exploited at or before their NVD record was even published — exploitation that ran ahead of public disclosure.
Time from NVD publication to KEV listing
n = 109 vulnerabilities in our corpus with both an NVD publication date and a CISA KEV listing date.
Why we report the median, not the mean
Two different things land a CVE in KEV. Most are recently disclosed and confirmed exploited within days (median 6 days, n = 98). A minority are old vulnerabilities CISA back-catalogs years after disclosure — a 2008 CVE added in 2026 carries a ~6,500-day “lag” that describes cataloging, not exploitation speed. Those 12 legacy cases drag the mean to hundreds of days while the median stays a robust 8 days across the full sample. We report the median and show the whole distribution so you can see both populations.
Method & what this sample is
Lag = (CISA KEV dateAdded) − (NVD publication date), in days, per CVE. Both dates come straight from NVD and the CISA KEV catalog — authoritative sources, never generated.
This is a convenience sample: the 109 KEV vulnerabilities in our verified corpus for which we hold an NVD publication date — not the full 1685-entry KEV catalog. It reflects the vulnerabilities we cover, which skew recent, so treat it as indicative of current exploitation tempo rather than a census. Snapshot as of 2026-08-31.
Which vendors are exploited most → · How we verify