Skip to main content

What the KEV catalogue actually says

Analysis of all 1,662 entries in CISA's Known Exploited Vulnerabilities catalogue. Unlike the rest of this site, nothing here is a summary of someone else's reporting — these are counts taken directly from the catalogue, recomputed on every build.

Source: CISA KEV · analysed 2026-08-09 · figures regenerate each build

How long you actually get

The remediation window is not a sliding scale — it is a handful of discrete policy values. 61.7% of the catalogue carries a 21-day deadline. The 182-day tail is the legacy BOD 22-01 treatment applied to older entries, not a relaxed modern deadline.

CISA remediation windows by frequency across the KEV catalogue
Window Entries Share
3 days 71 4.3%
7 days 20 1.2%
14 days 259 15.6%
21 days 1,025 61.7%
181 days 238 14.3%
182 days 11 0.7%

Ransomware labelling has shifted

CISA flags entries known to be used in ransomware campaigns. That share sat near 23.2% across 2021–2024 and is near 11.8% across 2025–2026. Read that as a change in the catalogue, not in the world. `knownRansomwareCampaignUse` is CISA's own annotation, so a change in labelling practice and a change in attacker behaviour look identical from here, and nothing in this dataset separates them.

KEV additions per year and ransomware-linked share
Year Added Ransomware-linked Share
2021 311 77 24.8%
2022 555 125 22.5%
2023 187 43 23.0%
2024 186 43 23.1%
2025 245 28 11.4%
2026 178 22 12.4%

The catalogue is more concentrated than it looks

276 distinct vendors appear in the catalogue, which suggests breadth. The running total says otherwise: the top ten account for 54.0% of every entry, and Microsoft alone is 23.0%.

Top ten vendors by KEV entry count, with cumulative share
Vendor Entries Share Cumulative
Microsoft 382 23.0% 23.0%
Cisco 95 5.7% 28.7%
Apple 93 5.6% 34.3%
Adobe 80 4.8% 39.1%
Google 72 4.3% 43.4%
Oracle 45 2.7% 46.1%
Apache 40 2.4% 48.6%
Ivanti 35 2.1% 50.7%
Fortinet 29 1.7% 52.4%
D-Link 26 1.6% 54.0%

Deadlines still open

2 of 1,662 entries still have a federal remediation deadline in the future as of 2026-08-09. The list is short because the catalogue is overwhelmingly historical — if it is ever long, that is itself the story.

KEV entries with a federal remediation deadline still in the future
Due CVE Vendor / product
2026-08-10 CVE-2026-8037 Progress LoadMaster
2026-08-10 CVE-2025-68686 Fortinet FortiOS

How much of this we have covered

This site has published at least one article on 261 of 1,662 catalogue entries — 15.7%. The remaining 1,401 are largely historical entries added before this site existed. Of the 137 covered close to their listing date, 108 were covered within a week and the median gap was 1 day.

Method: every figure is computed at build time from the KEV catalogue snapshot in this repository and from this site's own article corpus — no figure is copied from another publication. Coverage latency is measured only for entries covered from three days before to 400 days after their KEV addition; articles about decade-old entries would otherwise register as years late and mean nothing. Counts change as CISA updates the catalogue. Reuse permitted under CC BY 4.0 with attribution.