Skip to main content

Vendors

30 total
Microsoft394 CVEs

Windows, Internet Explorer, Office

389 KEV117 ransomware2026-09-25
Cisco101 CVEs

IOS and IOS XE Software, Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), IOS software

100 KEV7 ransomware2026-09-30
Apple95 CVEs

Multiple Products, iOS, iPadOS, and macOS, iOS

95 KEV2026-09-29
Adobe82 CVEs

Flash Player, ColdFusion, Acrobat and Reader

82 KEV11 ransomware2026-09-24
Google77 CVEs

Chromium V8, Chromium, Chrome

75 KEV2026-09-16
D-Link61 CVEs

DNS-120, DIR-823X, DIR-615

27 KEV2 ransomware2026-04-24
Oracle46 CVEs

WebLogic Server, Java SE, Fusion Middleware

46 KEV13 ransomware2026-08-24
Apache43 CVEs

Struts, Tomcat, HTTP Server

41 KEV8 ransomware2026-10-08
Ivanti38 CVEs

Pulse Connect Secure, Endpoint Manager Mobile (EPMM), Endpoint Manager (EPM)

36 KEV12 ransomware2026-06-11
VMware33 CVEs

vCenter Server, ESXi, Multiple Products

33 KEV11 ransomware2026-08-18
Linux Kernel31 CVEs

Kernel

31 KEV2 ransomware2026-09-18
Fortinet31 CVEs

FortiOS, Multiple Products, FortiOS and FortiProxy

31 KEV14 ransomware2026-10-01
Citrix27 CVEs

NetScaler, NetScaler ADC and NetScaler Gateway, Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

27 KEV7 ransomware2026-10-04
Zimbra19 CVEs

Zimbra Collaboration Suite (ZCS), Zimbra Collaboration Suite (ZCS), Zimbra Collaborate Suite (ZCS)

19 KEV6 ransomware2026-08-21
SonicWall19 CVEs

SMA1000 Appliances, SonicOS, SonicWall Email Security

19 KEV13 ransomware2026-09-02
Wavlink19 CVEs

NU516U1, WL-NU516U1, WL-WN579A3

0 KEV
Android17 CVEs

Framework, Pixel, Kernel

17 KEV2026-06-02
Samsung15 CVEs

Mobile Devices, MagicINFO 9 Server

15 KEV2026-04-24
Palo Alto Networks15 CVEs

PAN-OS, Expedition

15 KEV6 ransomware2026-05-29
Tenda15 CVEs

AC6, F453, G103

3 KEV2021-11-03
SAP14 CVEs

NetWeaver, Commerce Cloud, Customer Relationship Management (CRM)

14 KEV3 ransomware2025-05-15
Zyxel13 CVEs

Multiple Firewalls, DSL CPE Devices, Multiple Network-Attached Storage (NAS) Devices

13 KEV2 ransomware2026-09-21
Mozilla13 CVEs

Firefox and Thunderbird, Firefox, Firefox, Firefox ESR, and Thunderbird

13 KEV1 ransomware2025-10-06
Atlassian13 CVEs

Confluence Data Center and Server, Confluence Server and Data Center, Jira Server and Data Center

13 KEV8 ransomware2024-11-12
Trend Micro12 CVEs

Apex One, Apex One and OfficeScan, Apex One, Apex One as a Service, and Worry-Free Business Security

12 KEV2026-05-21
Qualcomm12 CVEs

Multiple Chipsets, Multiple Chipsets , Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

12 KEV2026-03-03
QNAP12 CVEs

Network Attached Storage (NAS), Photo Station, Helpdesk

12 KEV9 ransomware2023-12-21
SolarWinds11 CVEs

Web Help Desk, Serv-U, Orion

11 KEV2 ransomware2026-06-05
Roundcube11 CVEs

Webmail, Roundcube Webmail

11 KEV2026-02-20
TRENDnet11 CVEs

TEW-657BRM, TEW-432BRP, TEW-713RE

0 KEV

Frequently Asked Questions

Which vendors have the most actively exploited vulnerabilities?→

By count of CISA KEV entries in this database, the top vendors are Microsoft (389), Cisco (100), Apple (95). The count measures confirmed exploitation only. It is not a rating of overall product security.

How are vendors assigned to vulnerabilities?→

For CVEs in the CISA KEV catalog, the vendor and product come from the vendorProject and product fields CISA publishes. For other CVEs, the vendor comes from the affected-product data in the CVE record.

Why is a vendor missing from this list?→

A vendor gets its own page once at least 10 CVE records in this database belong to it. Vendors with fewer records are still listed on the individual CVE pages.

Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). CVE record data © The MITRE Corporation, used under the CVE Terms of Use. This site is not endorsed or certified by MITRE or CISA.