KEV Statistics
The CISA Known Exploited Vulnerabilities catalog in numbers, computed from all 1,739 KEV entries in this database. Every figure is recalculated from the catalog feed on each sync.
Key Findings
- As of October 10, 2026, the CISA Known Exploited Vulnerabilities (KEV) catalog lists 1,739 CVEs with reliable evidence of active exploitation in the wild.
- CISA added 303 vulnerabilities to the KEV catalog in the 12 months to October 10, 2026, and 255 so far in 2026.
- For vulnerabilities added to the CISA KEV catalog in 2026, the median time from CVE publication to KEV listing is 15 days, and 42% were listed no later than 7 days after publication, compared with a median of 26 days in 2025 (as of October 10, 2026).
- Since June 10, 2026, 81% of new CISA KEV entries (99 of 122) have had a remediation due date 3 days or less after they were added, compared with 3% of entries added in 2025.
- Microsoft has the most entries in the CISA KEV catalog (390), followed by Cisco (100) and Apple (95), as of October 10, 2026.
- Among CISA KEV entries whose CVE record names a weakness, the most common is OS Command Injection (CWE-78), with 48 entries, as of October 10, 2026.
- 21% of CISA KEV entries (361 of 1,739) are marked by CISA as known to be used in ransomware campaigns, as of October 10, 2026.
- 50% of CISA KEV entries have a current EPSS score of 50% or higher, and 26% score below 10% (as of October 10, 2026).
KEV Additions per Month
Since Jan 2023Show as table
| Month | entries added |
|---|---|
| Oct 2026 (in progress) | 9 |
| Sep 2026 | 43 |
| Aug 2026 | 31 |
| Jul 2026 | 26 |
| Jun 2026 | 23 |
| May 2026 | 21 |
| Apr 2026 | 31 |
| Mar 2026 | 26 |
| Feb 2026 | 28 |
| Jan 2026 | 17 |
| Dec 2025 | 20 |
| Nov 2025 | 11 |
| Oct 2025 | 31 |
| Sep 2025 | 16 |
| Aug 2025 | 15 |
| Jul 2025 | 20 |
| Jun 2025 | 20 |
| May 2025 | 24 |
| Apr 2025 | 15 |
| Mar 2025 | 32 |
| Feb 2025 | 27 |
| Jan 2025 | 14 |
| Dec 2024 | 16 |
| Nov 2024 | 22 |
| Oct 2024 | 17 |
| Sep 2024 | 25 |
| Aug 2024 | 19 |
| Jul 2024 | 14 |
| Jun 2024 | 9 |
| May 2024 | 14 |
| Apr 2024 | 10 |
| Mar 2024 | 10 |
| Feb 2024 | 9 |
| Jan 2024 | 21 |
| Dec 2023 | 11 |
| Nov 2023 | 18 |
| Oct 2023 | 18 |
| Sep 2023 | 19 |
| Aug 2023 | 8 |
| Jul 2023 | 16 |
| Jun 2023 | 24 |
| May 2023 | 19 |
| Apr 2023 | 17 |
| Mar 2023 | 18 |
| Feb 2023 | 14 |
| Jan 2023 | 5 |
Entries added per year: 2021: 311, 2022: 555, 2023: 187, 2024: 186, 2025: 245, 2026: 255 (through 2026-10-10). The earliest addition date in the catalog is 2021-11-03.
Time from CVE Publication to KEV
- Before the CVE was published25 (3%)
- Same day156 (18%)
- 1 to 7 days186 (21%)
- 8 to 30 days100 (11%)
- 31 to 365 days209 (24%)
- More than a year197 (23%)
Days between the CVE record's publication date and the date CISA added it to the catalog, for the 873 entries added since 2023. An entry counts as listed before publication when CISA added it before the CVE record was published.
Time to KEV by Year Added
| Year added | Entries | Median days | Within 7 days |
|---|---|---|---|
| 2023 | 187 | 12 | 45% |
| 2024 | 186 | 21.5 | 42% |
| 2025 | 245 | 26 | 40% |
| 2026 (to date) | 255 | 15 | 42% |
Within 7 days includes entries listed on or before the CVE's publication date. Additions from 2021 and 2022 are left out: they are dominated by older CVEs listed when the catalog started.
Remediation Window
Days from addition to due date- 3 days or less
- 4 to 14 days
- 15 days or more
- 2023 (187)
- 2024 (186)
- 2025 (245)
- 2026, before Jun 10 (133)
- Since Jun 10, 2026 (122)
Show as table
| Period | 3 days or less | 4 to 14 days | 15 days or more | Total |
|---|---|---|---|---|
| 2023 | 0 (0%) | 9 (5%) | 178 (95%) | 187 |
| 2024 | 1 (1%) | 10 (5%) | 175 (94%) | 186 |
| 2025 | 7 (3%) | 12 (5%) | 226 (92%) | 245 |
| 2026, before Jun 10 | 33 (25%) | 56 (42%) | 44 (33%) | 133 |
| Since Jun 10, 2026 | 99 (81%) | 23 (19%) | 0 (0%) | 122 |
Since June 10, 2026, KEV due dates fall under Binding Operational Directive 26-04. Of the 122 entries added since then, 99 (81%) carry a due date 3 days or less after the addition date.
Top Vendors
Top Weaknesses
- 48
- 41
- 36
- 36
- 31
- 25
- 23
- 22
- 18
- 17
Counted over the 610 entries (35%) whose CVE record names a CWE. An entry with more than one CWE counts once for each.
Current EPSS Score
- Below 1%60 (3%)
- 1% to 10%395 (23%)
- 10% to 50%418 (24%)
- 50% or higher866 (50%)
EPSS estimates the probability that a CVE is exploited in the next 30 days. The scores are the current values from the latest sync, not the values at the time each entry was added.
Highest CVSS Severity
- Critical613 (35%)
- High915 (53%)
- Medium202 (12%)
- Low9 (1%)
The severity rating of the highest CVSS base score in each CVE record, across CVSS versions, as shown on the CVE pages.
SSVC Decision Points
Of the 1,739 entries with SSVC data in their CVE record, as enriched by CISA: the share marked automatable, and the share marked with total technical impact.
Frequently Asked Questions
How many vulnerabilities are in the CISA KEV catalog?→
As of October 10, 2026, the CISA Known Exploited Vulnerabilities (KEV) catalog lists 1,739 CVEs with reliable evidence of active exploitation in the wild. CISA added 303 vulnerabilities to the KEV catalog in the 12 months to October 10, 2026, and 255 so far in 2026.
How long does it take for a CVE to be added to the KEV catalog?→
For vulnerabilities added to the CISA KEV catalog in 2026, the median time from CVE publication to KEV listing is 15 days, and 42% were listed no later than 7 days after publication, compared with a median of 26 days in 2025 (as of October 10, 2026).
How long do agencies have to fix KEV vulnerabilities?→
Since June 10, 2026, 81% of new CISA KEV entries (99 of 122) have had a remediation due date 3 days or less after they were added, compared with 3% of entries added in 2025. The due dates apply to US federal civilian executive branch agencies.
Which vendor has the most known exploited vulnerabilities?→
Microsoft has the most entries in the CISA KEV catalog (390), followed by Cisco (100) and Apple (95), as of October 10, 2026.
How many KEV vulnerabilities are used in ransomware attacks?→
21% of CISA KEV entries (361 of 1,739) are marked by CISA as known to be used in ransomware campaigns, as of October 10, 2026.
Method
- Every number on this page is computed from the 1,739 KEV entries in this database, synced every 12 hours from the CISA catalog feed. Data as of 2026-10-10.
- Only KEV entries are counted. The rest of the database is a curated selection of CVEs, so it is not a baseline for comparison.
- Publication dates come from the CVE record. Addition and due dates, vendor, and known ransomware use come from the KEV entry.
- Day counts are calendar days between two dates. The 12 months to the data date start the day after the same date one year earlier.
- Medians are the middle value of the entries in a year; with an even count, the average of the two middle values.
- Vendor names are the ones CISA lists, grouped under the vendor hub name on this site where one exists (for example, Pulse Secure entries count under Ivanti).
- EPSS scores are the current values from FIRST. CVSS, CWE, and SSVC values come from the CVE record and its CISA enrichment.
- Percentages are rounded to whole numbers, so the shares in a chart may not add up to exactly 100%.
Cite This Page
ImmunitySec. "CISA KEV Statistics." Data as of October 10, 2026. https://www.immunitysec.com/vulnerabilities/kev/statistics/The figures change with each sync, so a citation should include the data date.
Related
Data: CISA Known Exploited Vulnerabilities catalog (CC0), CVE records from the CVE Program, EPSS by FIRST (first.org/epss). This site is not endorsed or certified by CISA or FIRST.