Research · KEV velocity

KEV Monthly: how many vulnerabilities CISA flags as exploited

CISA KEV additions by month · snapshot 2026-08-31

In August 2026, CISA added 29 vulnerabilities to its Known Exploited Vulnerabilities catalog — up 3 from July 2026 (26).

0 (0%) were linked to known ransomware campaigns. Most-listed vendors: Microsoft (4), Linux (2), N-able (2). Trailing-12-month average: 23/month.

KEV additions by month (count, and ransomware-linked)

August 2025
15 (1 rw)
September 2025
16 (1 rw)
October 2025
31 (3 rw)
November 2025
11 (0 rw)
December 2025
20 (1 rw)
January 2026
17 (2 rw)
February 2026
28 (2 rw)
March 2026
26 (2 rw)
April 2026
31 (9 rw)
May 2026
21 (3 rw)
June 2026
23 (3 rw)
July 2026
26 (3 rw)
August 2026
29 (0 rw)

Recent months

MonthAddedRansomwareTop vendors
August 2026290 (0%)Microsoft (4), Linux (2), N-able (2)
July 2026263 (12%)Microsoft (5), Fortinet (3), Cisco (2)
June 2026233 (13%)Cisco (3), Ubiquiti (3), Oracle (2)
May 2026213 (14%)Microsoft (7), Palo Alto Networks (2), Adobe (1)
April 2026319 (29%)Microsoft (8), Cisco (3), Adobe (2)
March 2026262 (8%)Apple (6), Google (2), Aquasecurity (1)
February 2026282 (7%)Microsoft (8), Cisco (2), GitLab (2)
January 2026172 (12%)Microsoft (3), SmarterTools (2), Broadcom (1)
December 2025201 (5%)Android (2), Apple (1), Array Networks (1)
November 2025110 (0%)Fortinet (2), Gladinet (2), CWP (1)
October 2025313 (10%)Microsoft (8), Adobe (2), Dassault Systèmes (2)
September 2025161 (6%)Cisco (3), TP-Link (3), Adminer (1)
August 2025151 (7%)Citrix (3), D-Link (3), Microsoft (2)

How we count

Each month counts entries in CISA’s Known Exploited Vulnerabilities catalog by their dateAdded (the day CISA listed them), refreshed daily. “Ransomware” counts entries CISA marks as used in known ransomware campaigns. The headline uses the most recent complete calendar month; the current month is shown separately and marked partial. Direct counts over official CISA data — nothing generated. Snapshot as of 2026-08-31.

State of Exploited Vulnerabilities →  ·  Most-exploited vendors  ·  How fast they’re exploited

🤖 Generated deterministically from the CISA KEV catalog. Updated as CISA adds entries. Free to cite with attribution to defend.network.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.