What the KEV catalogue actually says
Analysis of all 1,699 entries in CISA's Known Exploited Vulnerabilities catalogue. Unlike the rest of this site, nothing here is a summary of someone else's reporting — these are counts taken directly from the catalogue, recomputed on every build.
Source: CISA KEV · analysed 2026-09-08 · figures regenerate each build
How long you actually get
The remediation window is not a sliding scale — it is a handful of discrete policy values. 60.3% of the catalogue carries a 21-day deadline. The 182-day tail is the legacy BOD 22-01 treatment applied to older entries, not a relaxed modern deadline.
| Window | Entries | Share |
|---|---|---|
| 3 days | 93 | 5.5% |
| 7 days | 20 | 1.2% |
| 14 days | 274 | 16.1% |
| 21 days | 1,025 | 60.3% |
| 181 days | 238 | 14.0% |
| 182 days | 11 | 0.6% |
Ransomware labelling has shifted
CISA flags entries known to be used in ransomware campaigns. That share sat near 24.2% across 2021–2024 and is near 12.0% across 2025–2026. Read that as a change in the catalogue, not in the world. `knownRansomwareCampaignUse` is CISA's own annotation, so a change in labelling practice and a change in attacker behaviour look identical from here, and nothing in this dataset separates them.
| Year | Added | Ransomware-linked | Share |
|---|---|---|---|
| 2021 | 311 | 82 | 26.4% |
| 2022 | 555 | 131 | 23.6% |
| 2023 | 187 | 43 | 23.0% |
| 2024 | 186 | 44 | 23.7% |
| 2025 | 245 | 31 | 12.7% |
| 2026 | 215 | 24 | 11.2% |
The catalogue is more concentrated than it looks
283 distinct vendors appear in the catalogue, which suggests breadth. The running total says otherwise: the top ten account for 53.6% of every entry, and Microsoft alone is 22.8%.
| Vendor | Entries | Share | Cumulative |
|---|---|---|---|
| Microsoft | 388 | 22.8% | 22.8% |
| Cisco | 96 | 5.7% | 28.5% |
| Apple | 94 | 5.5% | 34.0% |
| Adobe | 81 | 4.8% | 38.8% |
| 73 | 4.3% | 43.1% | |
| Oracle | 46 | 2.7% | 45.8% |
| Apache | 40 | 2.4% | 48.1% |
| Ivanti | 35 | 2.1% | 50.2% |
| Fortinet | 29 | 1.7% | 51.9% |
| Linux | 28 | 1.6% | 53.6% |
Deadlines still open
14 of 1,699 entries still have a federal remediation deadline in the future as of 2026-09-08. The list is short because the catalogue is overwhelmingly historical — if it is ever long, that is itself the story.
| Due | CVE | Vendor / product |
|---|---|---|
| 2026-09-09 | CVE-2022-0995 | Linux Kernel |
| 2026-09-09 | CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional |
| 2026-09-09 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool |
| 2026-09-09 | CVE-2015-3246 | Red Hat Libuser |
| 2026-09-10 | CVE-2026-66384 | JFrog Artifactory |
| 2026-09-11 | CVE-2026-86218 | N-able N-central |
| 2026-09-11 | CVE-2026-75650 | Adobe Commerce and Magento |
| 2026-09-14 | CVE-2026-82078 | PaperCut NG/MF |
| 2026-09-14 | CVE-2026-81578 | PaperCut NG/MF |
| 2026-09-16 | CVE-2026-59822 | BerriAI LiteLLM |
| 2026-09-16 | CVE-2026-48710 | Kludex Starlette |
| 2026-09-18 | CVE-2026-85046 | Google Chromium V8 |
| 2026-09-22 | CVE-2026-85880 | Microsoft Windows |
| 2026-09-22 | CVE-2026-81963 | Microsoft Windows |
How much of this we have covered
This site has published at least one article on 296 of 1,699 catalogue entries — 17.4%. The remaining 1,403 are largely historical entries added before this site existed. Of the 168 covered close to their listing date, 137 were covered within a week and the median gap was 1 day.
Method: every figure is computed at build time from the KEV catalogue snapshot in this repository and from this site's own article corpus — no figure is copied from another publication. Coverage latency is measured only for entries covered from three days before to 400 days after their KEV addition; articles about decade-old entries would otherwise register as years late and mean nothing. Counts change as CISA updates the catalogue. Reuse permitted under CC BY 4.0 with attribution.