Skip to main content

Key Findings

  • As of October 10, 2026, the CISA Known Exploited Vulnerabilities (KEV) catalog lists 1,739 CVEs with reliable evidence of active exploitation in the wild.
  • CISA added 303 vulnerabilities to the KEV catalog in the 12 months to October 10, 2026, and 255 so far in 2026.
  • For vulnerabilities added to the CISA KEV catalog in 2026, the median time from CVE publication to KEV listing is 15 days, and 42% were listed no later than 7 days after publication, compared with a median of 26 days in 2025 (as of October 10, 2026).
  • Since June 10, 2026, 81% of new CISA KEV entries (99 of 122) have had a remediation due date 3 days or less after they were added, compared with 3% of entries added in 2025.
  • Microsoft has the most entries in the CISA KEV catalog (390), followed by Cisco (100) and Apple (95), as of October 10, 2026.
  • Among CISA KEV entries whose CVE record names a weakness, the most common is OS Command Injection (CWE-78), with 48 entries, as of October 10, 2026.
  • 21% of CISA KEV entries (361 of 1,739) are marked by CISA as known to be used in ransomware campaigns, as of October 10, 2026.
  • 50% of CISA KEV entries have a current EPSS score of 50% or higher, and 26% score below 10% (as of October 10, 2026).

KEV Additions per Month

Since Jan 2023
Show as table
KEV entries added per month
Monthentries added
Oct 2026 (in progress)9
Sep 202643
Aug 202631
Jul 202626
Jun 202623
May 202621
Apr 202631
Mar 202626
Feb 202628
Jan 202617
Dec 202520
Nov 202511
Oct 202531
Sep 202516
Aug 202515
Jul 202520
Jun 202520
May 202524
Apr 202515
Mar 202532
Feb 202527
Jan 202514
Dec 202416
Nov 202422
Oct 202417
Sep 202425
Aug 202419
Jul 202414
Jun 20249
May 202414
Apr 202410
Mar 202410
Feb 20249
Jan 202421
Dec 202311
Nov 202318
Oct 202318
Sep 202319
Aug 20238
Jul 202316
Jun 202324
May 202319
Apr 202317
Mar 202318
Feb 202314
Jan 20235

Entries added per year: 2021: 311, 2022: 555, 2023: 187, 2024: 186, 2025: 245, 2026: 255 (through 2026-10-10). The earliest addition date in the catalog is 2021-11-03.

Time from CVE Publication to KEV

  • Before the CVE was published
    25 (3%)
  • Same day
    156 (18%)
  • 1 to 7 days
    186 (21%)
  • 8 to 30 days
    100 (11%)
  • 31 to 365 days
    209 (24%)
  • More than a year
    197 (23%)

Days between the CVE record's publication date and the date CISA added it to the catalog, for the 873 entries added since 2023. An entry counts as listed before publication when CISA added it before the CVE record was published.

Time to KEV by Year Added

Year addedEntriesMedian daysWithin 7 days
20231871245%
202418621.542%
20252452640%
2026 (to date)2551542%

Within 7 days includes entries listed on or before the CVE's publication date. Additions from 2021 and 2022 are left out: they are dominated by older CVEs listed when the catalog started.

Remediation Window

Days from addition to due date
  • 3 days or less
  • 4 to 14 days
  • 15 days or more
  • 2023 (187)
  • 2024 (186)
  • 2025 (245)
  • 2026, before Jun 10 (133)
  • Since Jun 10, 2026 (122)
Show as table
KEV remediation windows by period added
Period3 days or less4 to 14 days15 days or moreTotal
20230 (0%)9 (5%)178 (95%)187
20241 (1%)10 (5%)175 (94%)186
20257 (3%)12 (5%)226 (92%)245
2026, before Jun 1033 (25%)56 (42%)44 (33%)133
Since Jun 10, 202699 (81%)23 (19%)0 (0%)122

Since June 10, 2026, KEV due dates fall under Binding Operational Directive 26-04. Of the 122 entries added since then, 99 (81%) carry a due date 3 days or less after the addition date.

The 10 vendors with the most entries, out of 283 in the catalog. Names follow the vendor hubs on this site where one exists, otherwise the vendor CISA lists for the entry.

Current EPSS Score

  • Below 1%
    60 (3%)
  • 1% to 10%
    395 (23%)
  • 10% to 50%
    418 (24%)
  • 50% or higher
    866 (50%)

EPSS estimates the probability that a CVE is exploited in the next 30 days. The scores are the current values from the latest sync, not the values at the time each entry was added.

Highest CVSS Severity

  • Critical
    613 (35%)
  • High
    915 (53%)
  • Medium
    202 (12%)
  • Low
    9 (1%)

The severity rating of the highest CVSS base score in each CVE record, across CVSS versions, as shown on the CVE pages.

SSVC Decision Points

Automatable
41%
Total Impact
84%

Of the 1,739 entries with SSVC data in their CVE record, as enriched by CISA: the share marked automatable, and the share marked with total technical impact.

Frequently Asked Questions

How many vulnerabilities are in the CISA KEV catalog?→

As of October 10, 2026, the CISA Known Exploited Vulnerabilities (KEV) catalog lists 1,739 CVEs with reliable evidence of active exploitation in the wild. CISA added 303 vulnerabilities to the KEV catalog in the 12 months to October 10, 2026, and 255 so far in 2026.

How long does it take for a CVE to be added to the KEV catalog?→

For vulnerabilities added to the CISA KEV catalog in 2026, the median time from CVE publication to KEV listing is 15 days, and 42% were listed no later than 7 days after publication, compared with a median of 26 days in 2025 (as of October 10, 2026).

How long do agencies have to fix KEV vulnerabilities?→

Since June 10, 2026, 81% of new CISA KEV entries (99 of 122) have had a remediation due date 3 days or less after they were added, compared with 3% of entries added in 2025. The due dates apply to US federal civilian executive branch agencies.

Which vendor has the most known exploited vulnerabilities?→

Microsoft has the most entries in the CISA KEV catalog (390), followed by Cisco (100) and Apple (95), as of October 10, 2026.

How many KEV vulnerabilities are used in ransomware attacks?→

21% of CISA KEV entries (361 of 1,739) are marked by CISA as known to be used in ransomware campaigns, as of October 10, 2026.

Method

  • Every number on this page is computed from the 1,739 KEV entries in this database, synced every 12 hours from the CISA catalog feed. Data as of 2026-10-10.
  • Only KEV entries are counted. The rest of the database is a curated selection of CVEs, so it is not a baseline for comparison.
  • Publication dates come from the CVE record. Addition and due dates, vendor, and known ransomware use come from the KEV entry.
  • Day counts are calendar days between two dates. The 12 months to the data date start the day after the same date one year earlier.
  • Medians are the middle value of the entries in a year; with an even count, the average of the two middle values.
  • Vendor names are the ones CISA lists, grouped under the vendor hub name on this site where one exists (for example, Pulse Secure entries count under Ivanti).
  • EPSS scores are the current values from FIRST. CVSS, CWE, and SSVC values come from the CVE record and its CISA enrichment.
  • Percentages are rounded to whole numbers, so the shares in a chart may not add up to exactly 100%.

Cite This Page

ImmunitySec. "CISA KEV Statistics." Data as of October 10, 2026. https://www.immunitysec.com/vulnerabilities/kev/statistics/

The figures change with each sync, so a citation should include the data date.

Related

Data: CISA Known Exploited Vulnerabilities catalog (CC0), CVE records from the CVE Program, EPSS by FIRST (first.org/epss). This site is not endorsed or certified by CISA or FIRST.