What the KEV catalogue actually says
Analysis of all 1,662 entries in CISA's Known Exploited Vulnerabilities catalogue. Unlike the rest of this site, nothing here is a summary of someone else's reporting — these are counts taken directly from the catalogue, recomputed on every build.
Source: CISA KEV · analysed 2026-08-09 · figures regenerate each build
How long you actually get
The remediation window is not a sliding scale — it is a handful of discrete policy values. 61.7% of the catalogue carries a 21-day deadline. The 182-day tail is the legacy BOD 22-01 treatment applied to older entries, not a relaxed modern deadline.
| Window | Entries | Share |
|---|---|---|
| 3 days | 71 | 4.3% |
| 7 days | 20 | 1.2% |
| 14 days | 259 | 15.6% |
| 21 days | 1,025 | 61.7% |
| 181 days | 238 | 14.3% |
| 182 days | 11 | 0.7% |
Ransomware labelling has shifted
CISA flags entries known to be used in ransomware campaigns. That share sat near 23.2% across 2021–2024 and is near 11.8% across 2025–2026. Read that as a change in the catalogue, not in the world. `knownRansomwareCampaignUse` is CISA's own annotation, so a change in labelling practice and a change in attacker behaviour look identical from here, and nothing in this dataset separates them.
| Year | Added | Ransomware-linked | Share |
|---|---|---|---|
| 2021 | 311 | 77 | 24.8% |
| 2022 | 555 | 125 | 22.5% |
| 2023 | 187 | 43 | 23.0% |
| 2024 | 186 | 43 | 23.1% |
| 2025 | 245 | 28 | 11.4% |
| 2026 | 178 | 22 | 12.4% |
The catalogue is more concentrated than it looks
276 distinct vendors appear in the catalogue, which suggests breadth. The running total says otherwise: the top ten account for 54.0% of every entry, and Microsoft alone is 23.0%.
| Vendor | Entries | Share | Cumulative |
|---|---|---|---|
| Microsoft | 382 | 23.0% | 23.0% |
| Cisco | 95 | 5.7% | 28.7% |
| Apple | 93 | 5.6% | 34.3% |
| Adobe | 80 | 4.8% | 39.1% |
| 72 | 4.3% | 43.4% | |
| Oracle | 45 | 2.7% | 46.1% |
| Apache | 40 | 2.4% | 48.6% |
| Ivanti | 35 | 2.1% | 50.7% |
| Fortinet | 29 | 1.7% | 52.4% |
| D-Link | 26 | 1.6% | 54.0% |
Deadlines still open
2 of 1,662 entries still have a federal remediation deadline in the future as of 2026-08-09. The list is short because the catalogue is overwhelmingly historical — if it is ever long, that is itself the story.
| Due | CVE | Vendor / product |
|---|---|---|
| 2026-08-10 | CVE-2026-8037 | Progress LoadMaster |
| 2026-08-10 | CVE-2025-68686 | Fortinet FortiOS |
How much of this we have covered
This site has published at least one article on 261 of 1,662 catalogue entries — 15.7%. The remaining 1,401 are largely historical entries added before this site existed. Of the 137 covered close to their listing date, 108 were covered within a week and the median gap was 1 day.
Method: every figure is computed at build time from the KEV catalogue snapshot in this repository and from this site's own article corpus — no figure is copied from another publication. Coverage latency is measured only for entries covered from three days before to 400 days after their KEV addition; articles about decade-old entries would otherwise register as years late and mean nothing. Counts change as CISA updates the catalogue. Reuse permitted under CC BY 4.0 with attribution.