Last synced: September 28, 2026 against the official CISA KEV catalog and the National Vulnerability Database. Updated daily.
As of September 2026, the median exploited vulnerability was publicly known for 245 days before CISA flagged it in the KEV catalog — measured across 1728 CVEs with verified publication dates. When CISA adds a CVE to the Known Exploited Vulnerabilities (KEV) catalog, it is official confirmation that attackers are exploiting it in the wild. This tracker measures the lag: how many days each vulnerability was publicly known (published in NVD) before it landed on the KEV list — broken down by vendor. A long lag means defenders had the information but no urgency signal; a lag of zero or less means the vulnerability was already being exploited when it was published.
Headline Numbers
- 1728 CVEs in the KEV catalog (1728 with verified NVD publication dates)
- Median lag from CVE publication to KEV listing: 245 days
- 24% were added to KEV within 7 days of publication — exploited almost immediately
- 45% took more than a year — old, unpatched software still being exploited
- 19% of all KEV entries are associated with known ransomware campaigns
- 57.2% were not in the top 10% of EPSS risk the day before CISA confirmed exploitation, across the 1419 entries with a forecast on file — full accuracy analysis
Vendor Leaderboard — Longest Median Lag
Vendors ranked by the median number of days their vulnerabilities were public before CISA confirmed active exploitation. Only vendors with at least 5 KEV entries with verified publication dates are ranked. “0-day rate” is the share of entries added to KEV on or before their NVD publication date — exploited at or before disclosure.
| # | Vendor | KEV entries | Median lag (days) | 0-day rate | Ransomware |
|---|---|---|---|---|---|
| 1 | Red Hat | 9 | 3915 | 0% | 3 |
| 2 | GNU | 5 | 2682 | 0% | 0 |
| 3 | Adobe | 82 | 2571 | 4% | 10 |
| 4 | NETGEAR | 8 | 1842 | 0% | 0 |
| 5 | SAP | 14 | 1575 | 0% | 2 |
| 6 | Oracle | 46 | 1464 | 0% | 13 |
| 7 | Exim | 5 | 1364 | 0% | 1 |
| 8 | Jenkins | 6 | 1151 | 0% | 1 |
| 9 | Cisco | 99 | 1134 | 16% | 6 |
| 10 | Drupal | 5 | 1128 | 0% | 2 |
| 11 | DrayTek | 5 | 1056 | 0% | 0 |
| 12 | Mozilla | 13 | 1035 | 15% | 1 |
| 13 | D-Link | 26 | 926 | 0% | 2 |
| 14 | Samsung | 15 | 616 | 0% | 0 |
| 15 | TP-Link | 6 | 614 | 0% | 0 |
| 16 | QNAP | 11 | 573 | 9% | 9 |
| 17 | Linux | 31 | 551 | 0% | 2 |
| 18 | Sophos | 7 | 546 | 14% | 1 |
| 19 | IBM | 8 | 545 | 0% | 2 |
| 20 | Microsoft | 389 | 531 | 23% | 104 |
| 21 | Apache | 40 | 469 | 3% | 7 |
| 22 | Roundcube | 11 | 308 | 0% | 0 |
| 23 | WordPress | 6 | 212 | 0% | 0 |
| 24 | SonicWall | 19 | 197 | 16% | 10 |
| 25 | GitLab | 5 | 194 | 20% | 1 |
Trend by Year
Median lag and median remediation window (days CISA gives federal agencies to patch, per BOD deadlines) by the year each CVE entered the catalog. The remediation window collapsed from 21 days to 3 under BOD 26-04 — CISA now expects near-immediate patching.
| Year added | Entries | Median lag (days) | Median patch window (days) |
|---|---|---|---|
| 2026 | 244 | 15 | 10 |
| 2025 | 245 | 26 | 21 |
| 2024 | 186 | 22 | 21 |
| 2023 | 187 | 12 | 21 |
| 2022 | 555 | 1436 | 21 |
| 2021 | 311 | 446 | 181 |
Latest KEV Additions
“EPSS (eve)” is the percentile the EPSS forecast assigned to each CVE on the day before CISA confirmed exploitation — the last prediction available to a defender at the time. Values in the top decile are shown in bold. A dash means EPSS had no score for that CVE that day.
| CVE | Vendor / Product | Added to KEV | Lag (days) | EPSS (eve) | Patch deadline | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-88771 | Citrix NetScaler | September 27, 2026 | 0 | — | September 30, 2026 | No |
| CVE-2026-88772 | Citrix NetScaler | September 27, 2026 | 0 | — | September 30, 2026 | No |
| CVE-2026-65660 | Microsoft SharePoint | September 25, 2026 | 45 | 66.6% | September 28, 2026 | No |
| CVE-2026-67279 | MikroTik RouterOS | September 25, 2026 | 20 | 51.5% | September 28, 2026 | No |
| CVE-2026-87902 | WordPress Core | September 25, 2026 | 3 | 86.3% | September 28, 2026 | No |
| CVE-2026-5430 | WSO2 Multiple Products | September 24, 2026 | 49 | 25.4% | September 27, 2026 | No |
| CVE-2026-71362 | Adobe Commerce and Magento | September 24, 2026 | 44 | 97.8% | September 27, 2026 | No |
| CVE-2026-85102 | Check Point Multiple Products | September 22, 2026 | 13 | 26.2% | September 25, 2026 | No |
| CVE-2026-93616 | Check Point Multiple Products | September 22, 2026 | 0 | — | September 25, 2026 | No |
| CVE-2026-93952 | Arista VeloCloud Orchestrator | September 22, 2026 | 0 | — | September 25, 2026 | No |
| CVE-2026-94127 | F5 BIG-IP APM | September 22, 2026 | 0 | — | September 25, 2026 | No |
| CVE-2026-7273 | Zyxel GS1900 Series Switches | September 21, 2026 | 97 | 24.7% | September 24, 2026 | No |
| CVE-2025-39682 | Linux Kernel | September 18, 2026 | 378 | 42.0% | September 21, 2026 | No |
| CVE-2025-39964 | Linux Kernel | September 18, 2026 | 340 | 25.4% | September 21, 2026 | No |
| CVE-2026-53266 | Linux Kernel | September 18, 2026 | 85 | 2.2% | September 21, 2026 | No |
CVE Data Cards
One page per tracked CVE, with its verified NVD publication date, the lag we measured, the federal patch deadline and how it compares to the rest of its vendor’s record. 29 published so far:
- CVE-2026-42016 — JFrog Artifactory (46 day lag)
- CVE-2026-42018 — JFrog Artifactory (30 day lag)
- CVE-2026-84869 — ConnectWise ScreenConnect (3 day lag)
- CVE-2025-25249 — Fortinet Multiple Products (239 day lag)
- CVE-2026-87491 — Google Chromium V8 (0 day lag)
- CVE-2026-86218 — N-able N-central (2 day lag)
- CVE-2026-48710 — Kludex Starlette (99 day lag)
- CVE-2026-59822 — BerriAI LiteLLM (56 day lag)
- CVE-2026-82329 — JFrog Artifactory (5 day lag)
- CVE-2026-9586 — Sangoma Switchvox (47 day lag)
- CVE-2026-66384 — JFrog Artifactory (15 day lag)
- CVE-2026-60004 — Gitea Gitea (-1 day lag)
- CVE-2026-72898 — Metabase Metabase (1 day lag)
- CVE-2026-18556 — N-able N-central (3 day lag)
- CVE-2026-18577 — N-able N-central (1 day lag)
- CVE-2025-68686 — Fortinet FortiOS (167 day lag)
- CVE-2026-16812 — Arista VeloCloud Orchestrator (0 day lag)
- CVE-2026-16232 — Check Point SmartConsole (0 day lag)
- CVE-2026-0770 — Langflow Langflow (179 day lag)
- CVE-2026-60137 — WordPress Core (4 day lag)
- CVE-2026-15409 — SonicWall SMA1000 Appliances (0 day lag)
- CVE-2026-15410 — SonicWall SMA1000 Appliances (0 day lag)
- CVE-2026-56155 — Microsoft Active Directory Federation Services (0 day lag)
- CVE-2026-56164 — Microsoft SharePoint Server (0 day lag)
- CVE-2008-4128 — Cisco IOS (6507 day lag)
- CVE-2026-48939 — iCagenda iCagenda (20 day lag)
- CVE-2026-48282 — Adobe ColdFusion (7 day lag)
- CVE-2026-48908 — JoomShaper SP Page Builder (17 day lag)
- CVE-2026-45659 — Microsoft SharePoint Server (40 day lag)
Frequently Asked Questions
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog is the official list maintained by CISA of CVEs with confirmed exploitation in the wild. When a CVE is added, U.S. federal agencies are required to patch it by a fixed deadline.
What is the median lag between CVE publication and KEV listing?
As of September 2026, the median lag is 245 days, measured across 1728 KEV entries with verified NVD publication dates. That is how long the average exploited vulnerability was publicly known before CISA confirmed active exploitation.
How many KEV vulnerabilities are exploited as zero-days?
24% of KEV entries were added within 7 days of their NVD publication date, meaning they were being exploited essentially at or before public disclosure.
Did EPSS predict the vulnerabilities in the KEV catalog?
Not consistently. We measured the EPSS forecast from the day before each KEV listing across 1419 entries: 57.2% of the vulnerabilities CISA later confirmed as actively exploited were not in the top 10% of EPSS risk on the eve of that confirmation. The full breakdown, including the current watchlist of high-EPSS CVEs not yet in the KEV catalog, is at cvedaily.io/epss/.
How often is this KEV lag data updated?
Daily. Our automated tracking framework syncs the official CISA KEV JSON feed every day and enriches each new entry with its NVD publication date. No numbers are estimated or taken from third-party sources.
Can I cite this dataset?
Yes — the dataset is free to use and cite under CC BY 4.0 with attribution to CVEDaily (cvedaily.io/kev/).
Methodology
Our automated tracking framework syncs the official CISA KEV catalog JSON feed daily and records every new entry with the date it was added. For each CVE we retrieve the original publication date from the NVD API and compute the lag in calendar days. A negative lag means CISA listed the vulnerability before NVD finished publishing it — typically zero-days exploited before disclosure. We do not estimate or reconstruct dates from third-party sources: every number on this page comes directly from CISA and NVD records. Entries whose CVE is not yet in NVD are counted in the catalog total but excluded from lag statistics until NVD publishes them.
This dataset is free to cite with attribution to CVEDaily (CC BY 4.0).