Skip to main content

What the KEV catalogue actually says

Analysis of all 1,699 entries in CISA's Known Exploited Vulnerabilities catalogue. Unlike the rest of this site, nothing here is a summary of someone else's reporting — these are counts taken directly from the catalogue, recomputed on every build.

Source: CISA KEV · analysed 2026-09-08 · figures regenerate each build

How long you actually get

The remediation window is not a sliding scale — it is a handful of discrete policy values. 60.3% of the catalogue carries a 21-day deadline. The 182-day tail is the legacy BOD 22-01 treatment applied to older entries, not a relaxed modern deadline.

CISA remediation windows by frequency across the KEV catalogue
Window Entries Share
3 days 93 5.5%
7 days 20 1.2%
14 days 274 16.1%
21 days 1,025 60.3%
181 days 238 14.0%
182 days 11 0.6%

Ransomware labelling has shifted

CISA flags entries known to be used in ransomware campaigns. That share sat near 24.2% across 2021–2024 and is near 12.0% across 2025–2026. Read that as a change in the catalogue, not in the world. `knownRansomwareCampaignUse` is CISA's own annotation, so a change in labelling practice and a change in attacker behaviour look identical from here, and nothing in this dataset separates them.

KEV additions per year and ransomware-linked share
Year Added Ransomware-linked Share
2021 311 82 26.4%
2022 555 131 23.6%
2023 187 43 23.0%
2024 186 44 23.7%
2025 245 31 12.7%
2026 215 24 11.2%

The catalogue is more concentrated than it looks

283 distinct vendors appear in the catalogue, which suggests breadth. The running total says otherwise: the top ten account for 53.6% of every entry, and Microsoft alone is 22.8%.

Top ten vendors by KEV entry count, with cumulative share
Vendor Entries Share Cumulative
Microsoft 388 22.8% 22.8%
Cisco 96 5.7% 28.5%
Apple 94 5.5% 34.0%
Adobe 81 4.8% 38.8%
Google 73 4.3% 43.1%
Oracle 46 2.7% 45.8%
Apache 40 2.4% 48.1%
Ivanti 35 2.1% 50.2%
Fortinet 29 1.7% 51.9%
Linux 28 1.6% 53.6%

Deadlines still open

14 of 1,699 entries still have a federal remediation deadline in the future as of 2026-09-08. The list is short because the catalogue is overwhelmingly historical — if it is ever long, that is itself the story.

KEV entries with a federal remediation deadline still in the future
Due CVE Vendor / product
2026-09-09 CVE-2022-0995 Linux Kernel
2026-09-09 CVE-2021-23758 Ajax.NET Professional Ajax.NET Professional
2026-09-09 CVE-2015-5287 Red Hat Automatic Bug Reporting Tool
2026-09-09 CVE-2015-3246 Red Hat Libuser
2026-09-10 CVE-2026-66384 JFrog Artifactory
2026-09-11 CVE-2026-86218 N-able N-central
2026-09-11 CVE-2026-75650 Adobe Commerce and Magento
2026-09-14 CVE-2026-82078 PaperCut NG/MF
2026-09-14 CVE-2026-81578 PaperCut NG/MF
2026-09-16 CVE-2026-59822 BerriAI LiteLLM
2026-09-16 CVE-2026-48710 Kludex Starlette
2026-09-18 CVE-2026-85046 Google Chromium V8
2026-09-22 CVE-2026-85880 Microsoft Windows
2026-09-22 CVE-2026-81963 Microsoft Windows

How much of this we have covered

This site has published at least one article on 296 of 1,699 catalogue entries — 17.4%. The remaining 1,403 are largely historical entries added before this site existed. Of the 168 covered close to their listing date, 137 were covered within a week and the median gap was 1 day.

Method: every figure is computed at build time from the KEV catalogue snapshot in this repository and from this site's own article corpus — no figure is copied from another publication. Coverage latency is measured only for entries covered from three days before to 400 days after their KEV addition; articles about decade-old entries would otherwise register as years late and mean nothing. Counts change as CISA updates the catalogue. Reuse permitted under CC BY 4.0 with attribution.