Last synced: August 12, 2026 against the official CISA KEV catalog and the National Vulnerability Database. Updated daily.

As of August 2026, the median exploited vulnerability was publicly known for 271 days before CISA flagged it in the KEV catalog — measured across 1665 CVEs with verified publication dates. When CISA adds a CVE to the Known Exploited Vulnerabilities (KEV) catalog, it is official confirmation that attackers are exploiting it in the wild. This tracker measures the lag: how many days each vulnerability was publicly known (published in NVD) before it landed on the KEV list — broken down by vendor. A long lag means defenders had the information but no urgency signal; a lag of zero or less means the vulnerability was already being exploited when it was published.

Headline Numbers

Vendor Leaderboard — Longest Median Lag

Vendors ranked by the median number of days their vulnerabilities were public before CISA confirmed active exploitation. Only vendors with at least 5 KEV entries with verified publication dates are ranked. “0-day rate” is the share of entries added to KEV on or before their NVD publication date — exploited at or before disclosure.

#VendorKEV entriesMedian lag (days)0-day rateRansomware
1GNU526820%0
2Adobe8026324%10
3NETGEAR818420%0
4Red Hat717870%3
5SAP1415750%2
6Oracle4515260%13
7Exim513640%1
8Cisco96124515%6
9Jenkins611510%1
10Drupal511280%2
11DrayTek510560%0
12Mozilla13103515%1
13D-Link269260%2
14Linux268480%2
15Samsung156160%0
16TP-Link66140%0
17QNAP115739%9
18Microsoft38356723%104
19Sophos754614%1
20IBM85450%2
21Apache404693%7
22WordPress54200%0
23Roundcube113080%0
24Citrix2223523%7
25SonicWall1720818%10

Trend by Year

Median lag and median remediation window (days CISA gives federal agencies to patch, per BOD deadlines) by the year each CVE entered the catalog. The remediation window collapsed from 21 days to 3 under BOD 26-04 — CISA now expects near-immediate patching.

Year addedEntriesMedian lag (days)Median patch window (days)
20261811514
20252452621
20241862221
20231871221
2022555143621
2021311446181

Latest KEV Additions

CVEVendor / ProductAdded to KEVLag (days)Patch deadlineRansomware
CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)August 11, 20260August 14, 2026No
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSockAugust 11, 20260August 25, 2026No
CVE-2026-72898Metabase MetabaseAugust 11, 20261August 14, 2026No
CVE-2026-8037Progress LoadMasterAugust 7, 202664August 10, 2026No
CVE-2026-63077JetBrains TeamCityAugust 5, 20269August 8, 2026No
CVE-2026-18556N-able N-centralAugust 4, 20263August 7, 2026No
CVE-2026-34486Apache TomcatAugust 4, 2026117August 7, 2026No
CVE-2026-9198IBM LangflowAugust 4, 202618August 7, 2026No
CVE-2026-18577N-able N-centralAugust 3, 20261August 6, 2026No
CVE-2026-20316Cisco Secure Firewall Management Center (FMC)July 29, 20260August 1, 2026No
CVE-2025-68686Fortinet FortiOSJuly 27, 2026167August 10, 2026No
CVE-2026-16812Arista VeloCloud OrchestratorJuly 27, 20260July 30, 2026No
CVE-2026-16232Check Point SmartConsoleJuly 22, 20260July 25, 2026No
CVE-2026-50522Microsoft SharePointJuly 22, 20268July 25, 2026No
CVE-2021-27137DD-WRT DD-WRTJuly 21, 20265July 24, 2026No

CVE Data Cards

One page per tracked CVE, with its verified NVD publication date, the lag we measured, the federal patch deadline and how it compares to the rest of its vendor’s record. 4 published so far:

Frequently Asked Questions

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities (KEV) catalog is the official list maintained by CISA of CVEs with confirmed exploitation in the wild. When a CVE is added, U.S. federal agencies are required to patch it by a fixed deadline.

What is the median lag between CVE publication and KEV listing?

As of August 2026, the median lag is 271 days, measured across 1665 KEV entries with verified NVD publication dates. That is how long the average exploited vulnerability was publicly known before CISA confirmed active exploitation.

How many KEV vulnerabilities are exploited as zero-days?

24% of KEV entries were added within 7 days of their NVD publication date, meaning they were being exploited essentially at or before public disclosure.

How often is this KEV lag data updated?

Daily. Our automated tracking framework syncs the official CISA KEV JSON feed every day and enriches each new entry with its NVD publication date. No numbers are estimated or taken from third-party sources.

Can I cite this dataset?

Yes — the dataset is free to use and cite under CC BY 4.0 with attribution to CVEDaily (cvedaily.io/kev/).

Methodology

Our automated tracking framework syncs the official CISA KEV catalog JSON feed daily and records every new entry with the date it was added. For each CVE we retrieve the original publication date from the NVD API and compute the lag in calendar days. A negative lag means CISA listed the vulnerability before NVD finished publishing it — typically zero-days exploited before disclosure. We do not estimate or reconstruct dates from third-party sources: every number on this page comes directly from CISA and NVD records. Entries whose CVE is not yet in NVD are counted in the catalog total but excluded from lag statistics until NVD publishes them.

This dataset is free to cite with attribution to CVEDaily (CC BY 4.0).