Vulnerabilities added to KEV, by year
Counted by CISA KEV dateAdded. 2026 is a partial year (through 2026-09-04).
Most-exploited vendors
Vendors with the most vulnerabilities in the KEV catalog.
| 1 | Microsoft | 386 |
| 2 | Cisco | 96 |
| 3 | Apple | 94 |
| 4 | Adobe | 80 |
| 5 | 72 | |
| 6 | Oracle | 46 |
| 7 | Apache | 40 |
| 8 | Ivanti | 35 |
| 9 | Fortinet | 29 |
| 10 | VMware | 29 |
Ransomware & exploitation speed
352 of 1,694 (21%) known-exploited vulnerabilities are tied to ransomware campaigns (per CISA’s ransomware flag).
Exploitation moves fast: across the vulnerabilities in our verified corpus, the median gap from NVD publication to KEV listing is just a few days — see the exploitation-timing study. New additions are tracked month by month in the KEV monthly report.
Where ransomware concentrates
Ransomware crews don’t hit the catalog evenly. Among vendors with at least 10 KEV entries, these carry the highest share flagged for ransomware use — well above the 21% catalog average. Internet-facing access products — NAS, firewalls and VPNs — feature heavily, consistent with how ransomware operators gain initial access.
| Vendor | Ransomware | of KEV | Share | |
|---|---|---|---|---|
| 1 | QNAP | 9 | 12 | 75% |
| 2 | SonicWall | 13 | 19 | 68% |
| 3 | Atlassian | 8 | 13 | 62% |
| 4 | Fortinet | 14 | 29 | 48% |
| 5 | Palo Alto Networks | 6 | 15 | 40% |
| 6 | Ivanti | 12 | 35 | 34% |
| 7 | VMware | 10 | 29 | 34% |
| 8 | Microsoft | 114 | 386 | 30% |
By contrast, Cisco (6 of 96), Apple (0 of 94), Google (0 of 72) — among the most-listed vendors overall — are almost never flagged for ransomware, a reminder that ransomware exposure concentrates in specific product types rather than tracking a vendor’s overall exploited-bug count.
Share = CISA’s knownRansomwareCampaignUse flag ÷ that vendor’s KEV entries; small catalogs (n as low as 10) are shown with their raw counts. CISA sometimes applies the flag retroactively, so the most recent additions can be undercounted; shares shift as the catalog updates.
How we count
Every figure is a direct count over CISA’s Known Exploited Vulnerabilities catalog, refreshed daily — no estimates, no AI-generated values. “Ransomware-linked” uses CISA’s knownRansomwareCampaignUse flag (the remainder are “unknown” to CISA, not confirmed ransomware-free). The remediation deadline is CISA’s BOD 22-01 dueDate minus dateAdded. The underlying data is available as an open CC BY dataset. Snapshot as of 2026-09-04.