Research · Statistics

The State of Exploited Vulnerabilities

Every vulnerability CISA has confirmed exploited in the wild, in numbers — drawn from the 1,685-entry Known Exploited Vulnerabilities (KEV) catalog. Updated from CISA. As of 2026-08-31.

1,685
vulnerabilities in the CISA KEV catalog
confirmed exploited in the wild
+29
added in the last 30 days
77 in the last 90
352 (21%)
linked to ransomware
per CISA
21 days
median remediation deadline
CISA BOD 22-01 window

Vulnerabilities added to KEV, by year

2021
311
2022
555
2023
187
2024
186
2025
245
2026 (partial)
201

Counted by CISA KEV dateAdded. 2026 is a partial year (through 2026-08-31).

Most-exploited vendors

Vendors with the most vulnerabilities in the KEV catalog.

1Microsoft386
2Cisco96
3Apple94
4Adobe80
5Google72
6Oracle46
7Apache40
8Ivanti35
9Fortinet29
10Linux28

All 281 vendors, ranked →

Ransomware & exploitation speed

352 of 1,685 (21%) known-exploited vulnerabilities are tied to ransomware campaigns (per CISA’s ransomware flag).

Exploitation moves fast: across the vulnerabilities in our verified corpus, the median gap from NVD publication to KEV listing is just a few days — see the exploitation-timing study.

How we count

Every figure is a direct count over CISA’s Known Exploited Vulnerabilities catalog, refreshed daily — no estimates, no AI-generated values. “Ransomware-linked” uses CISA’s knownRansomwareUse flag (the remainder are “unknown” to CISA, not confirmed ransomware-free). The remediation deadline is CISA’s BOD 22-01 dueDate minus dateAdded. The underlying data is available as an open CC BY dataset. Snapshot as of 2026-08-31.

🤖 Generated deterministically from the CISA KEV catalog. Free to cite with attribution to defend.network.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.