Research · Statistics

The State of Exploited Vulnerabilities

Every vulnerability CISA has confirmed exploited in the wild, in numbers — drawn from the 1,694-entry Known Exploited Vulnerabilities (KEV) catalog. Updated from CISA. As of 2026-09-04.

1,694
vulnerabilities in the CISA KEV catalog
confirmed exploited in the wild
+34
added in the last 30 days
82 in the last 90
352 (21%)
linked to ransomware
per CISA
21 days
median remediation deadline
CISA BOD 22-01 window

Vulnerabilities added to KEV, by year

2021
311
2022
555
2023
187
2024
186
2025
245
2026 (partial)
210

Counted by CISA KEV dateAdded. 2026 is a partial year (through 2026-09-04).

Most-exploited vendors

Vendors with the most vulnerabilities in the KEV catalog.

1Microsoft386
2Cisco96
3Apple94
4Adobe80
5Google72
6Oracle46
7Apache40
8Ivanti35
9Fortinet29
10VMware29

Browse the full vendor ranking →

Ransomware & exploitation speed

352 of 1,694 (21%) known-exploited vulnerabilities are tied to ransomware campaigns (per CISA’s ransomware flag).

Exploitation moves fast: across the vulnerabilities in our verified corpus, the median gap from NVD publication to KEV listing is just a few days — see the exploitation-timing study. New additions are tracked month by month in the KEV monthly report.

Where ransomware concentrates

Ransomware crews don’t hit the catalog evenly. Among vendors with at least 10 KEV entries, these carry the highest share flagged for ransomware use — well above the 21% catalog average. Internet-facing access products — NAS, firewalls and VPNs — feature heavily, consistent with how ransomware operators gain initial access.

VendorRansomwareof KEVShare
1QNAP91275%
2SonicWall131968%
3Atlassian81362%
4Fortinet142948%
5Palo Alto Networks61540%
6Ivanti123534%
7VMware102934%
8Microsoft11438630%

By contrast, Cisco (6 of 96), Apple (0 of 94), Google (0 of 72) — among the most-listed vendors overall — are almost never flagged for ransomware, a reminder that ransomware exposure concentrates in specific product types rather than tracking a vendor’s overall exploited-bug count.

Share = CISA’s knownRansomwareCampaignUse flag ÷ that vendor’s KEV entries; small catalogs (n as low as 10) are shown with their raw counts. CISA sometimes applies the flag retroactively, so the most recent additions can be undercounted; shares shift as the catalog updates.

How we count

Every figure is a direct count over CISA’s Known Exploited Vulnerabilities catalog, refreshed daily — no estimates, no AI-generated values. “Ransomware-linked” uses CISA’s knownRansomwareCampaignUse flag (the remainder are “unknown” to CISA, not confirmed ransomware-free). The remediation deadline is CISA’s BOD 22-01 dueDate minus dateAdded. The underlying data is available as an open CC BY dataset. Snapshot as of 2026-09-04.

🤖 Generated deterministically from the CISA KEV catalog. Free to cite with attribution to defend.network.