Vulnerabilities added to KEV, by year
Counted by CISA KEV dateAdded. 2026 is a partial year (through 2026-08-31).
Most-exploited vendors
Vendors with the most vulnerabilities in the KEV catalog.
| 1 | Microsoft | 386 |
| 2 | Cisco | 96 |
| 3 | Apple | 94 |
| 4 | Adobe | 80 |
| 5 | 72 | |
| 6 | Oracle | 46 |
| 7 | Apache | 40 |
| 8 | Ivanti | 35 |
| 9 | Fortinet | 29 |
| 10 | Linux | 28 |
Ransomware & exploitation speed
352 of 1,685 (21%) known-exploited vulnerabilities are tied to ransomware campaigns (per CISA’s ransomware flag).
Exploitation moves fast: across the vulnerabilities in our verified corpus, the median gap from NVD publication to KEV listing is just a few days — see the exploitation-timing study.
How we count
Every figure is a direct count over CISA’s Known Exploited Vulnerabilities catalog, refreshed daily — no estimates, no AI-generated values. “Ransomware-linked” uses CISA’s knownRansomwareUse flag (the remainder are “unknown” to CISA, not confirmed ransomware-free). The remediation deadline is CISA’s BOD 22-01 dueDate minus dateAdded. The underlying data is available as an open CC BY dataset. Snapshot as of 2026-08-31.