In August 2026, CISA added 29 vulnerabilities to its Known Exploited Vulnerabilities catalog — up 3 from July 2026 (26).
0 (0%) were linked to known ransomware campaigns. Most-listed vendors: Microsoft (4), Linux (2), N-able (2). Trailing-12-month average: 23/month.
KEV additions by month (count, and ransomware-linked)
Recent months
| Month | Added | Ransomware | Top vendors |
|---|---|---|---|
| August 2026 | 29 | 0 (0%) | Microsoft (4), Linux (2), N-able (2) |
| July 2026 | 26 | 3 (12%) | Microsoft (5), Fortinet (3), Cisco (2) |
| June 2026 | 23 | 3 (13%) | Cisco (3), Ubiquiti (3), Oracle (2) |
| May 2026 | 21 | 3 (14%) | Microsoft (7), Palo Alto Networks (2), Adobe (1) |
| April 2026 | 31 | 9 (29%) | Microsoft (8), Cisco (3), Adobe (2) |
| March 2026 | 26 | 2 (8%) | Apple (6), Google (2), Aquasecurity (1) |
| February 2026 | 28 | 2 (7%) | Microsoft (8), Cisco (2), GitLab (2) |
| January 2026 | 17 | 2 (12%) | Microsoft (3), SmarterTools (2), Broadcom (1) |
| December 2025 | 20 | 1 (5%) | Android (2), Apple (1), Array Networks (1) |
| November 2025 | 11 | 0 (0%) | Fortinet (2), Gladinet (2), CWP (1) |
| October 2025 | 31 | 3 (10%) | Microsoft (8), Adobe (2), Dassault Systèmes (2) |
| September 2025 | 16 | 1 (6%) | Cisco (3), TP-Link (3), Adminer (1) |
| August 2025 | 15 | 1 (7%) | Citrix (3), D-Link (3), Microsoft (2) |
How we count
Each month counts entries in CISA’s Known Exploited Vulnerabilities catalog by their dateAdded (the day CISA listed them), refreshed daily. “Ransomware” counts entries CISA marks as used in known ransomware campaigns. The headline uses the most recent complete calendar month; the current month is shown separately and marked partial. Direct counts over official CISA data — nothing generated. Snapshot as of 2026-08-31.
State of Exploited Vulnerabilities → · Most-exploited vendors · How fast they’re exploited