Vendor Exploitation Records

Most-exploited vendors (CISA KEV)

47 vendors with 5 or more vulnerabilities confirmed exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog — 1310 entries in total. Ranked by KEV count. As of 2026-08-31.

#VendorIn KEVRansomware
1Microsoft386114
2Cisco966
3Apple94
4Adobe8010
5Google72
6Oracle4613
7Apache408
8Ivanti3512
9Fortinet2914
10VMware2910
11Linux282
12D-Link262
13Citrix237
14Synacor195
15Android17
16SonicWall1713
17Palo Alto Networks156
18Samsung15
19SAP143
20Atlassian138
21Mozilla131
22QNAP129
23Qualcomm12
24Trend Micro12
25Zyxel122
26Roundcube11
27SolarWinds112
28Arm9
29Progress94
30Red Hat94
31Zoho92
32IBM82
33Juniper8
34NETGEAR8
35F574
36Mitel75
37Sophos72
38Jenkins61
39TP-Link6
40Broadcom5
41DrayTek5
42Drupal52
43Exim51
44GNU5
45Langflow51
46RARLAB54
47WordPress5

Source: CISA KEV, counted by vendorProject. Only vendors with ≥5 KEV entries are listed. Ransomware column counts entries CISA marks as used in known ransomware campaigns.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.