CISA KEV Statistics 2026
By Axis Intelligence Research
Co-author: Marcus Chen | Last updated: August 13, 2026 | License: CC BY 4.0
CISA’s Known Exploited Vulnerabilities Catalog holds 1,665 entries as of catalog version 2026.08.11. Axis Intelligence Research finds that 181 of them were added in 2026 alone — a 16.8% increase over the same window last year — and that the median federal remediation window for a new KEV entry has fallen from 21 days to 14.
Quick Answer
The CISA KEV catalog contains 1,665 actively exploited vulnerabilities from 276 vendors as of August 11, 2026. Axis Intelligence Research finds that 60.8% of 2026 additions carry a CVE identifier assigned in 2026, meaning most newly cataloged flaws are exploited in the same calendar year they are named. Since March 2026, 49.3% of new KEV entries carry a three-day federal remediation deadline — a tier that did not exist a year ago.
Key Findings
- Axis Intelligence Research finds the CISA Known Exploited Vulnerabilities Catalog reached 1,665 entries at catalog version 2026.08.11, up from 1,484 at the close of 2025.
- Axis Intelligence Research finds that 339 KEV entries — 20.4% of the catalog — are flagged by CISA as used in known ransomware campaigns.
- Axis Intelligence Research finds that KEV entries represent 0.44% of the 376,310 CVE records held in the NIST National Vulnerability Database as of August 12, 2026.
- Axis Intelligence Research finds that 67 of the 136 KEV entries added since March 2026 carry a three-day remediation deadline, compared with a flat 21-day deadline applied to every entry added in 2025.
- Axis Intelligence Research finds that perimeter and network-appliance vendors accounted for 21.9% of KEV additions between 2024 and August 2026, against 15.4% in 2021–2022.
How Many Vulnerabilities Are in the CISA KEV Catalog?
The catalog held 1,665 entries on August 11, 2026, drawn from 276 distinct vendors. The CISA Known Exploited Vulnerabilities Catalog publishes a version-stamped JSON and CSV feed on every update; the analysis below works from catalog version 2026.08.11, retrieved on August 13, 2026 via CISA’s own kev-data repository, which mirrors the agency’s published files with commit history.
Growth has not been steady, and the shape of that curve matters more than the total.
KEV Additions by Year
| Year | Entries added | Cumulative catalog | Source |
|---|---|---|---|
| 2021 (from Nov 3) | 311 | 311 | CISA KEV Catalog |
| 2022 | 555 | 866 | CISA KEV Catalog |
| 2023 | 187 | 1,053 | CISA KEV Catalog |
| 2024 | 186 | 1,239 | CISA KEV Catalog |
| 2025 | 245 | 1,484 | CISA KEV Catalog |
| 2026 (to Aug 11) | 181 | 1,665 | CISA KEV Catalog |
The 2022 spike is a backfill artifact, not a threat signal. When BOD 22-01 established the catalog in November 2021, CISA spent roughly fourteen months loading a decade of historical exploitation — 555 entries in 2022 alone, most of them for old CVEs. Treat 2023 onward as the catalog’s steady state.
Against that steady state, 2026 is running hot. Axis Intelligence Research recorded 181 additions through August 11 against 155 over the identical window in 2025, a 16.8% year-over-year increase. Projected across a full year at the observed daily rate — 181 additions across 223 elapsed days, extended to 365 — the 2026 pace implies roughly 296 additions, which would be the highest non-backfill year on record.
Marcus Chen: The catalog count is the number everyone quotes and the least useful one in the file. A vulnerability enters KEV when CISA has evidence of active exploitation, so the total measures two things at once: what attackers are doing, and how much analyst capacity CISA has to confirm it. The 2023–2024 plateau at 186–187 entries in consecutive years is not a coincidence about attacker behavior. It looks like throughput. What changed in 2025 and 2026 is the mix, not just the count — and the mix is where the story is.
Source: Axis Intelligence Research — CC BY 4.0
What Share of All CVEs End Up in the KEV Catalog?
The NIST National Vulnerability Database held 376,310 CVE records on August 12, 2026, per the response metadata returned by the NVD CVE API. Against that denominator, the KEV catalog covers 0.44% of every CVE ever published.
Axis cross-source calculation: 1,665 KEV entries ÷ 376,310 NVD CVE records × 100 = 0.44%. Inputs: CISA KEV Catalog v2026.08.11 (as of 2026-08-11) and NIST NVD CVE API 2.0 response metadata (as of 2026-08-12). Both figures are direct observations from primary feeds; neither is an estimate.
That ratio is the entire argument for exploitation-based prioritization. Fewer than one CVE in two hundred has ever been confirmed exploited in the wild by CISA. A vulnerability management program that treats CVSS severity as its queue order is sorting a haystack; KEV is the list of needles that have already drawn blood.
The ratio is also a floor, not a ceiling. KEV is scoped to vulnerabilities with confirmed active exploitation, a clear remediation action, and an assigned CVE — so it undercounts real-world exploitation by design. It is the most conservative exploitation signal in public circulation, which is precisely why it carries weight.
How Fast Do Vulnerabilities Move From Disclosure to Active Exploitation?
The catalog does not carry an exploitation timestamp, but it carries something nearly as useful: the CVE identifier year against the date CISA added the entry. Comparing the two produces a listing lag in years — a coarse but honest measure of how quickly a named vulnerability becomes a confirmed weapon.
Same-Year Exploitation Rate by Addition Year
| Addition year | Same-year CVE IDs | Total additions | Same-year rate | Source |
|---|---|---|---|---|
| 2021 | 120 | 311 | 38.6% | Axis calculation on CISA KEV Catalog |
| 2022 | 91 | 555 | 16.4% | Axis calculation on CISA KEV Catalog |
| 2023 | 121 | 187 | 64.7% | Axis calculation on CISA KEV Catalog |
| 2024 | 116 | 186 | 62.4% | Axis calculation on CISA KEV Catalog |
| 2025 | 151 | 245 | 61.6% | Axis calculation on CISA KEV Catalog |
| 2026 (to Aug 11) | 110 | 181 | 60.8% | Axis calculation on CISA KEV Catalog |
Once the backfill cleared, the same-year rate locked into a band between 60.8% and 64.7% and has stayed there for four consecutive years. Across the full catalog, 709 of 1,665 entries — 42.6% — carry a CVE identifier from the same year they were cataloged, and the median lag across all entries is one year.
That stability is the finding. The popular framing says exploitation is accelerating year over year; the KEV data says it accelerated once, around 2023, and then plateaued at a new normal where roughly six in ten newly exploited vulnerabilities are current-year flaws. The remaining four in ten are old bugs in unpatched estates — CVE-2008-4250, a Microsoft flaw from 2008, entered the catalog in May 2026.
Marcus Chen: Two numbers sit next to each other here and they point in opposite directions. Six in ten KEV additions are current-year CVEs, which is the number that makes headlines about collapsing patch windows. Four in ten are not, and the oldest addition this year dates to 2008 — an eighteen-year-old flaw that someone was still successfully exploiting against a live system in 2026. Both are true. The first tells you what your patch pipeline has to keep up with. The second tells you what your asset inventory has been quietly hiding.
Which Vendors Appear Most in the CISA KEV Catalog?
Microsoft accounts for 383 entries — 23.0% of the entire catalog, more than the next three vendors combined. That concentration reflects installed base as much as code quality, and reading it as a security verdict would be a mistake.
Top KEV Vendors by Lifetime Entries
| Vendor | Lifetime entries | 2026 YTD | Ransomware-linked rate | Source |
|---|---|---|---|---|
| Microsoft | 383 | 33 | 27.4% | CISA KEV Catalog |
| Cisco | 96 | 14 | 6.2% | CISA KEV Catalog |
| Apple | 93 | 7 | 0.0% | CISA KEV Catalog |
| Adobe | 80 | 4 | 12.5% | CISA KEV Catalog |
| 72 | 5 | 0.0% | CISA KEV Catalog | |
| Oracle | 45 | 3 | 28.9% | CISA KEV Catalog |
| Apache | 40 | 2 | 20.0% | CISA KEV Catalog |
| Ivanti | 35 | 5 | 34.3% | CISA KEV Catalog |
| Fortinet | 29 | 6 | 44.8% | CISA KEV Catalog |
| VMware | 26 | 0 | 34.6% | CISA KEV Catalog |
| Citrix | 22 | 1 | 31.8% | CISA KEV Catalog |
| SonicWall | 17 | 2 | 70.6% | CISA KEV Catalog |
| Palo Alto Networks | 15 | 2 | 40.0% | CISA KEV Catalog |
| Atlassian | 13 | 0 | 61.5% | CISA KEV Catalog |
| QNAP | 11 | 0 | 81.8% | CISA KEV Catalog |
Look down the ransomware column rather than the volume column and the ranking inverts. Microsoft’s 383 entries carry a 27.4% ransomware linkage rate. SonicWall’s seventeen entries carry 70.6%. QNAP’s eleven carry 81.8%. Volume tells you where attackers spend their time; linkage rate tells you what happens to you when they succeed.
The Axis KEV Exposure Pressure Index (KEPI™)
Raw entry counts flatter large vendors and hide small ones with concentrated, current, ransomware-adjacent exposure. KEPI™ — the KEV Exposure Pressure Index — is an Axis Intelligence Research metric that scores each eligible vendor 0–100 on how much live exploitation pressure its products currently carry, rather than how many historical entries it has accumulated.
KEPI™ formula and inputs
KEPI is computed entirely from the CISA KEV catalog. Three components, each min-max normalized against the highest-scoring eligible vendor, then weighted:
| Component | Weight | Definition |
|---|---|---|
| Recent volume | 45% | Vendor’s KEV additions in the trailing 24 months (2024-08-12 to 2026-08-11) |
| Ransomware linkage | 30% | Share of the vendor’s lifetime KEV entries flagged Known for ransomware campaign use |
| Live share | 25% | Share of the vendor’s lifetime KEV entries added in the trailing 24 months |
KEPI = (0.45 × Recent_norm) + (0.30 × Ransomware_norm) + (0.25 × Live_norm)
Eligibility: vendors with ten or more lifetime KEV entries, so that rate-based components rest on a usable denominator. Twenty-seven vendors qualify at this snapshot. Normalization anchors: Microsoft at 92 trailing-24-month additions, QNAP at 81.8% ransomware linkage, Palo Alto Networks at 66.7% live share.
KEPI™ readings — baseline, as of August 11, 2026
| Rank | Vendor | KEPI™ | Trailing 24-mo adds | Ransomware rate | Live share |
|---|---|---|---|---|---|
| 1 | Microsoft | 64.1 | 92 | 27.4% | 24.0% |
| 2 | SonicWall | 47.4 | 8 | 70.6% | 47.1% |
| 3 | Fortinet | 45.0 | 16 | 44.8% | 55.2% |
| 4 | Palo Alto Networks | 44.6 | 10 | 40.0% | 66.7% |
| 5 | Ivanti | 40.7 | 18 | 34.3% | 51.4% |
| 6 | Synacor | 33.3 | 9 | 27.8% | 50.0% |
| 7 | SolarWinds | 30.1 | 6 | 18.2% | 54.5% |
| 8 | QNAP | 30.0 | 0 | 81.8% | 0.0% |
| 9 | Linux | 26.0 | 12 | 7.7% | 46.2% |
| 10 | Atlassian | 25.9 | 1 | 61.5% | 7.7% |
| 11 | Oracle | 25.1 | 11 | 28.9% | 24.4% |
| 12 | Citrix | 24.8 | 6 | 31.8% | 27.3% |
| 13 | Cisco | 23.4 | 24 | 6.2% | 25.0% |
| 14 | VMware | 22.3 | 5 | 34.6% | 19.2% |
| 15 | Apple | 16.1 | 18 | 0.0% | 19.4% |
Source for all inputs: CISA KEV Catalog v2026.08.11. This is the baseline reading of KEPI™; no prior readings exist, and the index makes no claim about its own history.
Four of the top five are perimeter security vendors. That is not a coincidence, and it is not a slight on those companies — an appliance that terminates untrusted traffic is exposed by function. What KEPI captures is that a Fortinet or Ivanti entry is far more likely than a Microsoft entry to be recent and ransomware-linked, which is exactly the combination that triggers the fastest federal deadline.
Cisco is the instructive counter-case. It sits thirteenth on KEPI despite 24 trailing-24-month additions — second only to Microsoft — because its ransomware linkage rate is 6.2%. High attacker attention, low observed ransomware conversion.
Scope: KEPI measures exposure pressure inside the KEV catalog. It says nothing about installed base, patch availability, mean time to vendor fix, or how quickly customers actually deploy. A vendor with few products in federal environments will be under-represented in the catalog regardless of its code. And CISA’s ransomware flag records what has been observed and attributed, not everything that occurred — the Unknown label on 1,326 entries means unconfirmed, not absent.
How Did BOD 26-04 Change the KEV Remediation Clock?
This is where the 2026 catalog breaks from every year before it, and where the data has not yet been reported.
On June 10, 2026, CISA issued BOD 26-04: Prioritizing Security Updates Based on Risk, which supersedes and revokes both BOD 19-02 and BOD 22-01. Where BOD 22-01 applied one flat clock to every KEV entry, BOD 26-04 sets the deadline from four binary variables — public exposure, KEV status, automatability, and technical impact — mapped across sixteen combinations in its Table 1 remediation timelines. The most severe combination requires remediation within three calendar days, plus forensic triage to establish whether the system was already compromised.
That change is visible in the dueDate field of every KEV entry, and Axis Intelligence Research measured it.
Federal Remediation Window on New KEV Entries
| Period | Median window | 3-day | 14-day | 21-day | Other | Total | Source |
|---|---|---|---|---|---|---|---|
| 2022 | 21 days | 0 | 88 | 403 | 64 | 555 | Axis calculation on CISA KEV Catalog |
| 2023 | 21 days | 0 | 0 | 177 | 10 | 187 | Axis calculation on CISA KEV Catalog |
| 2024 | 21 days | 0 | 0 | 175 | 11 | 186 | Axis calculation on CISA KEV Catalog |
| 2025 | 21 days | 0 | 0 | 226 | 19 | 245 | Axis calculation on CISA KEV Catalog |
| 2026 (to Aug 11) | 14 days | 73 | 61 | 44 | 3 | 181 | Axis calculation on CISA KEV Catalog |
The 14-day windows visible in 2022 are the backfill period’s dual-track deadlines, applied alongside the 21-day default. From 2023 through 2025 the catalog is effectively uniform: 578 of 618 additions across those three years carry a flat 21-day dueDate. The 40 exceptions are one-off emergency deadlines, not a tier.
Restricting to entries added since March 2026 sharpens the break: of 136 additions, 67 carry a three-day deadline and 61 carry fourteen days — 49.3% at the fastest tier. The 21-day window that governed nearly every entry from 2023 to 2025 appears seven times in that period.
Two details in the timing deserve attention. The first three-day KEV deadline appears on January 27, 2026 — more than four months before BOD 26-04 was signed. The 14-day tier arrives in March 2026, and the 21-day tier disappears entirely after March. Axis Intelligence Research finds that CISA was operating BOD 26-04’s tiered remediation timelines in the KEV catalog before the directive was published, which means the pilot period is legible in the public data for anyone who reads the dueDate column.
The three-day tier is also strongly selected. Of the 73 entries carrying it, 62 (84.9%) have a same-year CVE identifier and 27 (37.0%) belong to perimeter vendors — a fresh, internet-facing, total-control profile that matches the directive’s most severe combination almost exactly.
The mandate is spreading beyond federal civilian agencies. FedRAMP’s public notice on BOD 26-04 sets December 7, 2026 as the adoption deadline for its aligned Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules, which pulls every authorized cloud service provider onto the same clock.
Marcus Chen: Three days is not a patching target. Three days is an admission that patching alone stopped being the answer. You cannot regression-test a firewall firmware update across a federal enterprise in seventy-two hours, and CISA knows that — which is why the same tier requires forensic triage and permits taking the system off the internet as a way to relax the clock. Read Table 1 as a decommissioning schedule with a patching option, and it makes more sense than reading it as a service-level agreement. The organizations that will hit three days are the ones that already know which assets are internet-facing without running a scan to find out.
What Weakness Types Dominate Actively Exploited Vulnerabilities?
Of 1,665 entries, 1,494 carry at least one CWE mapping. The lifetime distribution is led by classic memory and input-handling flaws, but the recent distribution has shifted.
Top CWEs in the KEV Catalog
| CWE | Weakness | Lifetime entries | 2021–22 share of mapped | 2025–26 share of mapped | Source |
|---|---|---|---|---|---|
| CWE-20 | Improper input validation | 118 | 12.5% | 2.3% | CISA KEV Catalog |
| CWE-78 | OS command injection | 107 | 6.8% | 7.1% | CISA KEV Catalog |
| CWE-787 | Out-of-bounds write | 100 | 9.1% | 3.8% | CISA KEV Catalog |
| CWE-416 | Use after free | 93 | 6.5% | 4.5% | CISA KEV Catalog |
| CWE-119 | Buffer overflow | 84 | 9.5% | 1.8% | CISA KEV Catalog |
| CWE-22 | Path traversal | 76 | 5.6% | 5.3% | CISA KEV Catalog |
| CWE-502 | Deserialization of untrusted data | 70 | 3.2% | 6.8% | CISA KEV Catalog |
| CWE-94 | Code injection | 67 | 4.2% | 5.1% | CISA KEV Catalog |
Deserialization of untrusted data more than doubled its share of mapped entries between the 2021–22 cohort (3.2% of 755) and the 2025–26 cohort (6.8% of 396). OS command injection now leads the recent cohort outright at 7.1%. Memory-safety classes moved the other way: out-of-bounds write fell from 9.1% to 3.8% of mapped entries, and buffer overflow from 9.5% to 1.8%.
The direction is consistent with where the attack surface moved. Memory-safety bugs live in browsers and operating systems, which have absorbed a decade of mitigations and are increasingly written in memory-safe languages. Deserialization and command injection live in web-facing management interfaces on appliances — the exact class of product climbing the KEPI table.
Are Network Appliances Really the Fastest-Growing KEV Category?
Yes, and the shift is measurable. Axis Intelligence Research classified a fixed set of twenty perimeter and network-appliance vendors (listed in Methodology) and compared their share of additions across two cohorts.
| Cohort | Perimeter additions | Total additions | Perimeter share | Source |
|---|---|---|---|---|
| 2021–2022 | 133 | 866 | 15.4% | Axis calculation on CISA KEV Catalog |
| 2024–2026 YTD | 134 | 612 | 21.9% | Axis calculation on CISA KEV Catalog |
Perimeter vendors now supply roughly one in five KEV additions, up from roughly one in seven. Of the 134 perimeter additions in the recent cohort, 29 (21.6%) are ransomware-linked — above the 20.4% catalog-wide rate, despite the recent cohort skewing toward entries too new to have accumulated ransomware attribution.
The 2021–22 comparison cohort is backfill-heavy and skews old, which flatters the recent period slightly. The direction survives the caveat: three of the four highest KEPI scores after Microsoft belong to firewall and remote-access vendors, and 37.0% of three-day-deadline entries in 2026 are perimeter products.
When Does CISA Add Entries to the KEV Catalog?
Additions arrive in irregular batches rather than on a fixed schedule, which matters for anyone building alerting on the feed.
| Month (2026) | Entries added | Source |
|---|---|---|
| January | 17 | CISA KEV Catalog |
| February | 28 | CISA KEV Catalog |
| March | 26 | CISA KEV Catalog |
| April | 31 | CISA KEV Catalog |
| May | 21 | CISA KEV Catalog |
| June | 23 | CISA KEV Catalog |
| July | 26 | CISA KEV Catalog |
| August (to Aug 11) | 9 | CISA KEV Catalog |
April 2026 was the heaviest month at 31 additions. The monthly floor since February has not dropped below 21, against a 2025 pattern that dipped to 11 in November. Consumers of the feed should poll the version-stamped JSON rather than assume a weekly cadence.
Methodology
Collection. The complete CISA Known Exploited Vulnerabilities Catalog was retrieved on August 13, 2026 at catalog version 2026.08.11 (dateReleased 2026-08-11T18:59:43Z, count 1665), via CISA’s own cisagov/kev-data repository, which mirrors the agency’s published JSON and CSV files. Catalog version, release timestamp, and entry count were confirmed against the metadata block in the retrieved file. Every entry’s cveID, vendorProject, dateAdded, dueDate, knownRansomwareCampaignUse, and cwes fields were parsed programmatically; no entry was hand-transcribed.
Derived fields. Listing lag is computed as (year of dateAdded) − (year component of the CVE identifier). The CVE identifier year reflects the year the identifier was reserved, which usually but not always matches public disclosure — this is a coarse proxy and is labeled as such wherever it appears. Remediation window is computed as (dueDate − dateAdded) in calendar days. Same-year exploitation rate is the count of entries whose CVE identifier year equals their dateAdded year, divided by all entries added that year.
KEPI™ formula. For each vendor with ten or more lifetime KEV entries (27 vendors at this snapshot):
- Recent_raw = additions where
dateAdded> 2024-08-11 - Ransomware_raw = (entries flagged
Known) ÷ (lifetime entries) - Live_raw = Recent_raw ÷ (lifetime entries)
Each component is normalized as (vendor_raw ÷ max_raw across eligible vendors) × 100, then combined as KEPI = 0.45 × Recent_norm + 0.30 × Ransomware_norm + 0.25 × Live_norm. Weights are editorial judgment, set to privilege current activity over historical accumulation while preventing a single high-linkage, low-volume vendor from topping the table on one component alone. All inputs are catalog fields; a reader with the same catalog version can reproduce every score.
Perimeter vendor set. Fixed classification across both cohorts: Ivanti, Fortinet, Citrix, SonicWall, Palo Alto Networks, Cisco, Zyxel, D-Link, Netgear, F5, Check Point, Juniper Networks, Sophos, Barracuda Networks, Array Networks, Pulse Secure, WatchGuard, TP-Link, DrayTek, Progress. Vendors are assigned by vendorProject string, so a vendor shipping both appliance and non-appliance products is counted whole — this inflates perimeter share modestly, most notably for Cisco.
Cross-source ratio. The KEV-to-CVE ratio combines the KEV entry count (CISA, as of 2026-08-11) with the total CVE record count returned in NVD CVE API 2.0 response metadata (NIST, as of 2026-08-12). Both are direct counts from primary feeds; the one-day gap between snapshots is immaterial at this magnitude and is disclosed rather than smoothed.
Scope. KEV records confirmed exploitation with a clear remediation action and an assigned CVE. It is not a complete record of exploitation in the wild, and additions depend on CISA’s analyst capacity as well as attacker behavior — the 2023–2024 plateau at 187 and 186 entries should be read with that in mind. The Unknown ransomware flag on 1,326 entries denotes unconfirmed attribution, not confirmed absence. Vendor counts reflect federal-relevant installed base and CISA’s visibility, not relative code quality. CISA occasionally removes entries; this snapshot reflects the catalog as published on August 11, 2026.
Verification. Every figure in this article was computed in Python directly from the retrieved catalog and re-run in an independent second pass. Cumulative catalog size at year-end 2025 computes to 1,484, matching the figure independently reported by outside analysts for that date — an external check on the parse. Every number in the prose corresponds to a row in the accompanying CSV.
About This Dataset
cisa-kev-statistics-2026.csv contains 133 observations covering the CISA KEV catalog from November 2021 through August 11, 2026: annual and monthly additions, cumulative catalog size, ransomware linkage, same-year exploitation rates, remediation-window distributions, per-vendor entry counts and ransomware rates, KEPI™ component inputs and scores, CWE distributions across two cohorts, and the cross-source KEV-to-NVD ratio.
Each row carries metric, value, unit, dimension, geography, as_of_date, source_org, source_document, source_url, retrieved_date, is_primary, axis_calculated, method_note, and license. Values are raw — no currency symbols, no percent signs, no thousands separators. Dates are ISO 8601. Rows marked axis_calculated = yes carry a method_note pointing to the formula disclosed above.
License: CC BY 4.0. Free to use, redistribute, and build on with attribution.
Cite This Research
APA Axis Intelligence Research. (2026). CISA KEV statistics 2026: Catalog growth, ransomware linkage, and the new 3-day remediation clock. https://axis-intelligence.com/cisa-kev-statistics/
MLA Axis Intelligence Research. “CISA KEV Statistics 2026: Catalog Growth, Ransomware Linkage, and the New 3-Day Remediation Clock.” Axis Intelligence, 13 Aug. 2026, axis-intelligence.com/cisa-kev-statistics/.
Chicago Axis Intelligence Research. “CISA KEV Statistics 2026: Catalog Growth, Ransomware Linkage, and the New 3-Day Remediation Clock.” Axis Intelligence, August 13, 2026. https://axis-intelligence.com/cisa-kev-statistics/.
KEPI™ attribution: KEPI™ (KEV Exposure Pressure Index) is a proprietary metric of Axis Intelligence Research, licensed CC BY 4.0. Cite as: Axis Intelligence Research, KEPI™ baseline reading, August 11, 2026, axis-intelligence.com/cisa-kev-statistics/.
Frequently Asked Questions
Does a vulnerability’s presence in the KEV catalog mean my organization is being attacked?
No. A KEV entry means CISA has reliable evidence of exploitation somewhere in the wild against some target, not that your instance is targeted. What it does change is the prior: exploitation has been proven feasible and productized, so the question shifts from “could this be exploited” to “is this asset reachable.” That reachability question is exactly what BOD 26-04’s public-exposure variable formalizes.
Why does my scanner flag KEV entries my SSVC decision tree deprioritizes?
Because they answer different questions. KEV is a binary exploitation observation. SSVC decision points — exposure, automatability, technical impact — combine with KEV status to produce a deployment-specific action, which is the model BOD 26-04 adopts across sixteen variable combinations. A KEV entry on an internal, non-automatable, partial-impact asset legitimately lands on a longer clock than the same CVE on an internet-facing host with total impact.
Should private-sector organizations follow the three-day BOD 26-04 tier?
BOD 26-04 binds Federal Civilian Executive Branch agencies. Its practical reach is wider: FedRAMP has set December 7, 2026 for adoption of its aligned rules, which brings authorized cloud service providers into scope, and contract language increasingly references federal remediation timelines. Whether a three-day tier is achievable depends far more on whether you can enumerate internet-facing assets in minutes than on your patching capacity.
Why do so many KEV entries carry an “Unknown” ransomware flag?
CISA marks Known only where ransomware campaign use has been observed and attributed. The 1,326 Unknown entries include vulnerabilities with no ransomware use, vulnerabilities used by ransomware operators without public attribution, and recent additions where attribution has not yet caught up. Reading Unknown as “safe from ransomware” inverts the field’s meaning.
Is the KEV catalog a complete list of vulnerabilities exploited in the wild?
No, and it does not claim to be. KEV requires an assigned CVE, reliable evidence of active exploitation, and a clear remediation action. Commercial exploitation feeds routinely track larger sets — VulnCheck’s parallel dataset, for instance, is broader by construction. KEV is the conservative, government-attested floor, which is why it carries disproportionate weight in policy and contracts.
How should I ingest the KEV feed programmatically?
Poll the version-stamped JSON and key on catalogVersion and dateReleased rather than assuming a cadence — 2026 additions ranged from 9 to 31 per month with no fixed publication day. CISA’s cisagov/kev-data repository mirrors the same files with git history, which makes diffing consecutive versions substantially easier than diffing snapshots you captured yourself.
Does a low KEPI™ score mean a vendor’s products are secure?
No. KEPI measures exploitation pressure recorded inside the KEV catalog, which is shaped by federal installed base and CISA’s visibility. A vendor with minimal federal deployment can score low while carrying real risk elsewhere. Apple scores 16.1 with 93 lifetime entries and zero ransomware-linked entries — a genuine signal about how Apple flaws get used, not a claim that Apple software is unexploited.
Why did the KEV catalog add 555 entries in 2022 and only 186 in 2024?
The 2022 figure is backfill. BOD 22-01 established the catalog in November 2021, and CISA spent the following year loading historical exploitation — which is why the 2022 same-year exploitation rate collapses to 16.4% while every year from 2023 onward sits above 60%. Any trend line drawn through 2022 measures cataloging effort, not attacker activity.
What is the difference between BOD 22-01 and BOD 26-04 for KEV remediation?
BOD 22-01 applied one flat clock to every KEV entry regardless of context; the catalog shows this as a uniform 21-day dueDate on 226 of 245 entries added in 2025. BOD 26-04 replaces that with tiered deadlines driven by four risk variables, produces three-day, 14-day, and 60-day outcomes, adds a mandatory forensic triage step at the top tier, and introduces a fix-on-upgrade tier for combinations meeting none of the criteria.
