CVE Statistics 2026
By Axis Intelligence Research
Co-author: Marcus Chen | Last updated: August 13, 2026 | License: CC BY 4.0
Through July 31, 2026, 45,626 CVE records were published — 66.4% more than the same window in 2025, and within 2,536 records of matching all of last year. Over the same seven months, CISA added 172 vulnerabilities to its Known Exploited Vulnerabilities catalog: 20 more than a year earlier. Volume nearly doubled. Confirmed exploitation barely moved.
Quick Answer
How many CVEs have been published in 2026? 45,626 through July 31, against 48,162 for all of 2025. FIRST projects roughly 66,000 for the full year. Of those, 172 entered the CISA KEV catalog between January and July — a rate Axis Intelligence Research calls Vulnerability Signal Density (VSD™): 3.77 confirmed-exploited CVEs per 1,000 published, down 32.0% from 5.54 in the same window last year. Security teams now review 265 published CVEs to find one with confirmed exploitation, up from 180.
Key Findings
- According to Axis Intelligence Research, Vulnerability Signal Density fell to 3.77 confirmed-exploited CVEs per 1,000 published in January–July 2026, a 32.0% decline from 5.54 in the same period of 2025.
- Axis Intelligence Research finds that 39.2% of the 181 vulnerabilities CISA added to the KEV catalog in 2026 carry CVE identifiers issued before 2026, with the oldest, CVE-2008-4128, dating to an eighteen-year-old disclosure.
- CVE publication volume grew 66.4% year over year in January–July 2026 while KEV additions grew 13.2% — a divergence of 53.2 percentage points, per Axis Intelligence Research calculations from CISA and NVD data.
- Exploitation of vulnerabilities became the leading initial access vector in breaches for the first time in the Verizon DBIR’s 19-year history, reaching 31% of the 2026 dataset against 20% the prior year.
- Only 26% of CISA KEV vulnerabilities were fully remediated by organizations in 2025, down from 38%, with median time to full resolution rising to 43 days from 32.
How Many CVEs Have Been Published in 2026?
45,626 CVE records were published between January 1 and July 31, 2026, excluding rejected records. The comparable 2025 window produced 27,426. That is a 66.4% increase, and it puts 2026 on pace to become the first year in the CVE Program’s history to approach 70,000 disclosures.
The National Vulnerability Database held 376,135 CVE records and 1,798,763 CPE product identifiers as of August 13, 2026. The all-time count of published, non-rejected CVE records since 1988 stood at 354,521 at the end of July.
CVE Records Published by Year, 2021–2026
| Year | CVE records published | Change vs prior year | Source |
|---|---|---|---|
| 2021 | 20,149 | — | NVD feed (monthlyCVEStats pipeline) |
| 2022 | 25,074 | +24.4% | NVD feed (monthlyCVEStats pipeline) |
| 2023 | 28,817 | +14.9% | NVD feed (monthlyCVEStats pipeline) |
| 2024 | 39,957 | +38.7% | NVD feed (monthlyCVEStats pipeline) |
| 2025 | 48,162 | +20.5% | NVD feed (monthlyCVEStats pipeline) |
| 2026 (Jan–Jul) | 45,626 | +66.4% vs Jan–Jul 2025 | NVD feed (monthlyCVEStats pipeline) |
Counts exclude rejected CVE records. Retrieved August 13, 2026 from the monthlyCVEStats pipeline, which derives its figures from the NIST NVD feed.
At the end of July, 2026 sat 2,536 records short of 2025’s full-year total. The pipeline’s own projection, generated August 1 from July’s publication rate, put the crossover on or about August 12. That is a projection rather than an observed count — but it means the calendar year overtook its predecessor with more than four months still to run.
Month-by-Month CVE Publication, 2026
| Month | CVE records published | Source |
|---|---|---|
| January 2026 | 4,305 | NVD feed |
| February 2026 | 4,616 | NVD feed |
| March 2026 | 6,234 | NVD feed |
| April 2026 | 5,810 | NVD feed |
| May 2026 | 6,940 | NVD feed |
| June 2026 | 7,946 | NVD feed |
| July 2026 | 9,775 | NVD feed |
July averaged 315.3 records per day. On July 21 alone, 1,474 CVEs were published — roughly a third of January’s entire output, in twenty-four hours.
Marcus Chen: The monthly curve is the part worth staring at. January to July is not a gentle ramp; it is 4,305 to 9,775, and the steepest months are the most recent ones. A vulnerability management program budgeted in December against last year’s intake is now running at roughly double its planned throughput, and nobody sent it a revised headcount. The interesting question is not whether the number is big. It is whether the number means what it used to.
What Share of Published CVEs Are Actually Exploited?
This is where the raw count stops being useful and a ratio has to take over.
The Vulnerability Signal Density Metric (VSD™)
Vulnerability Signal Density (VSD™) is an Axis Intelligence Research metric measuring how much confirmed-exploitation signal a given volume of vulnerability disclosure carries.
VSD™ = (KEV entries added in window ÷ CVE records published in same window) × 1,000
The output is the number of CVEs published in a period that CISA subsequently confirmed as exploited in the wild, expressed per 1,000 disclosures. Both inputs are counts, not estimates: KEV additions come from the CISA Known Exploited Vulnerabilities Catalog counted by dateAdded, and publication counts come from the NVD feed excluding rejected records. Any competent analyst can recompute every reading below from those two public files.
The reciprocal is the number practitioners actually feel: triage load, or how many published CVEs a team must pass over to reach one with confirmed exploitation.
VSD Readings by Year
| Period | KEV additions | CVEs published | VSD™ (per 1,000) | Triage load (CVEs per KEV entry) |
|---|---|---|---|---|
| 2021 | 311 | 20,149 | 15.44 | 65 |
| 2022 | 555 | 25,074 | 22.13 | 45 |
| 2023 | 187 | 28,817 | 6.49 | 154 |
| 2024 | 186 | 39,957 | 4.66 | 215 |
| 2025 | 245 | 48,162 | 5.09 | 197 |
| 2026 (Jan–Jul) | 172 | 45,626 | 3.77 | 265 |
Sources: CISA KEV Catalog v2026.08.11 and the NVD publication series, both retrieved August 13, 2026. Axis Intelligence Research calculation.
The 2021 and 2022 readings are not comparable with what follows. CISA launched the KEV catalog in November 2021 and spent its first year backfilling historical vulnerabilities, which inflates additions in both years. We publish them for completeness and exclude them from trend comparison rather than quietly dropping them.
From 2023 onward the series is clean, and it points one direction. The 2026 partial-year reading of 3.77 is the lowest in the comparable record. Against the like-for-like January–July window of 2025, which read 5.54, that is a decline of 32.0%.
Monthly VSD, 2026
| Month | KEV additions | CVEs published | VSD™ |
|---|---|---|---|
| January 2026 | 17 | 4,305 | 3.95 |
| February 2026 | 28 | 4,616 | 6.07 |
| March 2026 | 26 | 6,234 | 4.17 |
| April 2026 | 31 | 5,810 | 5.34 |
| May 2026 | 21 | 6,940 | 3.03 |
| June 2026 | 23 | 7,946 | 2.89 |
| July 2026 | 26 | 9,775 | 2.66 |
Source: Axis Intelligence Research, from CISA KEV and NVD data. Retrieved August 13, 2026.
The monthly series shows the mechanism plainly. KEV additions oscillate in a narrow band — 17 to 31 per month, with no trend. The denominator more than doubles. July’s reading of 2.66 is the lowest month of the year, and it is low not because attackers slowed down but because 9,775 records arrived.
The divergence is the finding. Between January–July 2025 and January–July 2026, CVE publication grew 66.4% and KEV additions grew 13.2%. That gap of 53.2 percentage points is what dilution looks like when you put a number on it.
FIRST reached the same conclusion from a different direction in its 2026 Mid-Year Vulnerability Forecast, published June 15, which raised the full-year projection to roughly 66,000 CVEs — 46.3% above the February baseline median of 59,427, with 6,420 excess records recorded through April alone. The forecast team’s phrasing for the same phenomenon was “rain versus flood”: total volume up, actionable exploitability flat.
Marcus Chen: Two readings of this are available and only one of them is right. The comforting reading is that the exploited fraction is shrinking, so the real workload is stable and everyone can relax. The correct reading is that the signal is unchanged in absolute terms and the noise around it tripled, which makes finding it harder, not easier. A team that reviewed 180 advisories to reach one confirmed-exploited flaw last summer reviews 265 today for the same result. Same needle. Bigger haystack. And as the section below shows, the people who have to find that needle are getting worse at it, not better.
Which Vulnerabilities Do Attackers Actually Exploit?
The KEV catalog held 1,665 entries at version 2026.08.11, of which 181 were added during 2026 and 23 of those carry CISA’s ransomware-campaign flag.
That total tracks cleanly against independently published counts. FIRST reported 1,587 KEV entries as of May 1, 2026; our snapshot returns exactly 1,587 at that date. Verizon reported 1,526 as of February 2026; our snapshot returns 1,529 at February 28, consistent with a mid-month cut.
KEV Additions by Vendor, 2026
| Vendor | KEV entries added in 2026 | Share of 2026 additions | Source |
|---|---|---|---|
| Microsoft | 33 | 18.2% | CISA KEV Catalog |
| Cisco | 14 | 7.7% | CISA KEV Catalog |
| Apple | 7 | 3.9% | CISA KEV Catalog |
| Fortinet | 6 | 3.3% | CISA KEV Catalog |
| Ivanti | 5 | 2.8% | CISA KEV Catalog |
| 5 | 2.8% | CISA KEV Catalog |
Source: CISA KEV Catalog v2026.08.11, retrieved August 13, 2026. Percentages are Axis Intelligence Research calculations against 181 total 2026 additions across 81 distinct vendors.
Eighty-one distinct vendors appear among 2026’s additions, and the top five account for 35.9% of them. Exploitation is concentrated at the network edge and in the productivity stack, not distributed evenly across the software estate.
The Age of Exploited Vulnerabilities
Here is the finding that most vulnerability-management dashboards are structurally incapable of showing.
Of the 181 vulnerabilities CISA added to KEV in 2026, 71 — 39.2% — carry CVE identifiers issued before 2026. Twenty-one of them, 11.6% of additions, are numbered 2021 or earlier. The oldest is CVE-2008-4128.
| CVE ID vintage | Entries added to KEV in 2026 | Share |
|---|---|---|
| 2026 | 110 | 60.8% |
| 2025 | 33 | 18.2% |
| 2024 | 9 | 5.0% |
| 2023 | 6 | 3.3% |
| 2022 or earlier | 23 | 12.7% |
| Total | 181 | 100% |
Source: Axis Intelligence Research, derived from CISA KEV Catalog v2026.08.11 by parsing the year component of each CVE identifier. Retrieved August 13, 2026.
Verizon’s independent analysis reaches the same place from the exploitation-frequency side: of KEV entries showing persistent exploitation activity, only 20% were registered in the CVE database during 2024 and 2025. For the other 80%, defenders had roughly two years of advance notice.
Marcus Chen: Two out of every five vulnerabilities that started getting exploited this year were already sitting in the estate, already catalogued, already patchable. This is the part that should reorder budgets. The industry’s instinct is to treat the newest disclosure as the most dangerous one, and the KEV data says that instinct is wrong roughly 39% of the time. An eighteen-year-old flaw entering the catalog in 2026 is not an exotic edge case. It is what happens when a product reaches end of life, stops receiving attention, and keeps answering on port 443.
Why Is Vulnerability Exploitation Now the Top Breach Vector?
The 2026 Verizon Data Breach Investigations Report analysed more than 22,000 confirmed breaches across 145 countries, covering incidents from November 1, 2024 through October 31, 2025. For the first time in the report’s 19-year run, exploitation of vulnerabilities is the leading initial access vector.
| Initial access vector | Share of breaches (2026 dataset) | Prior year | Source |
|---|---|---|---|
| Exploitation of vulnerabilities | 31% | 20% | Verizon 2026 DBIR |
| Phishing | 16% | 16% | Verizon 2026 DBIR |
| Credential abuse | 13% | 22% | Verizon 2026 DBIR |
Source: Verizon 2026 Data Breach Investigations Report, Figure 10 (n=20,023). Retrieved August 13, 2026. Verizon notes credential abuse would read 16% on a like-for-like basis before Pretexting was added as a tracked vector, and that credential abuse appears at 39% when counted at any stage of the breach chain rather than as initial access.
KEV Remediation Is Moving Backwards
| Remediation metric | 2025 | Prior year | Source |
|---|---|---|---|
| KEV vulnerabilities fully remediated | 26% | 38% | Verizon 2026 DBIR |
| KEV vulnerabilities unremediated | 16% | 12% | Verizon 2026 DBIR |
| Median days to full resolution | 43 | 32 | Verizon 2026 DBIR |
| Median unique KEV CVEs per organization | 16 | 11 | Verizon 2026 DBIR |
| Instances remediated before KEV listing | 12% | 17% | Verizon 2026 DBIR |
Source: Verizon 2026 DBIR (n=515,170 KEV resolution records; n=13,773 organizations). Retrieved August 13, 2026.
Verizon’s survival analysis, built on more than 527 million vulnerability detection records for 2025 against 68.7 million in 2022, found 35% of KEV vulnerabilities still open at day 28 — up from 27% the year before. In absolute terms that is 184 million open instances at day 28, against 31 million in 2022, with roughly 47 million instances the curve suggests will never be addressed.
One finding in that analysis deserves separate attention, because it sets a ceiling on what triage can achieve. By day seven, between 60% and 70% of KEV vulnerabilities remain open regardless of year, volume, or organizational maturity. Three years of tooling investment and mandate pressure did not move that first-week rate. Verizon floats it as a possible “speed of light” for remediation processes.
I would disagree with the framing rather than the measurement. A first-week ceiling that holds constant across maturity levels looks less like a physical limit and more like evidence that the input queue is mis-sorted before it reaches the patching team. If the same 30–40% gets fixed in week one no matter how good you are, the leverage is not in patching faster. It is in being right about which 30–40%.
What Is Driving the 2026 CVE Surge?
FIRST attributes the increase to three structural drivers, none of which is a decline in software quality:
- AI-assisted vulnerability discovery. The Mozilla CNA’s Q1 2026 disclosures rose 164%, attributed directly to AI-assisted tooling run against the Firefox engine.
- GitHub Security Advisory volume, up 449% year over year.
- VulnCheck’s CNA-of-Last-Resort activity, up 3,119% as it absorbed a large backlog of previously unassigned vulnerabilities.
FIRST also notes that the number of distinct software products with tracked vulnerabilities has grown by two orders of magnitude, driving workload independently of either AI or CNA changes.
The assignment layer has scaled to match. 510 organizations across 42 countries now participate as CVE Numbering Authorities, according to ENISA, which became a CVE Root for European entities in November 2025. In July 2026, 208 distinct assigning sources published at least one record.
Verizon’s collaboration with Anthropic on 793 threat actors subject to enforcement action offers the other half of the picture: 32% of AI-assisted initial access techniques mapped to exploitation of vulnerabilities, against 44% for phishing. The median actor sought assistance across about 15 distinct MITRE ATT&CK techniques, and fewer than 2.5% of observed techniques qualified as rare. AI is currently scaling known methods rather than inventing new ones — on both sides of the disclosure pipeline.
How Severe Are 2026 CVEs?
| CVSS v3 severity | July 2026 records | Share of scored | Source |
|---|---|---|---|
| Critical | 1,199 | 13.9% | NVD feed |
| High | 3,855 | 44.6% | NVD feed |
| Medium | 3,216 | 37.2% | NVD feed |
| Low | 365 | 4.2% | NVD feed |
Source: NVD publication data for July 2026 (n=8,636 CVSS v3-scored records; a further 760 carried CVSS v4 only and 379 were unscored). Retrieved August 13, 2026.
Mean CVSS v3 base score for July was 7.07, median 7.3, with 96.1% of the month’s records carrying a score of some kind. Critical and High together account for 58.5% of scored records — which is precisely why severity alone cannot function as a triage filter. In July, 5,054 records landed in those two bands and 26 entered the KEV catalog.
Marcus Chen: Any prioritisation scheme that starts with “patch everything Critical and High” committed itself to 5,054 items in July alone and will not survive contact with an actual maintenance window. The severity score describes what a vulnerability could do in a laboratory. It says nothing about whether anyone is doing it. That distinction used to be an argument among practitioners. As of June, it is federal policy.
How Does CISA’s BOD 26-04 Change Vulnerability Prioritisation?
On June 10, 2026, CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” which supersedes and revokes both BOD 19-02 and BOD 22-01. The older directives keyed remediation deadlines to CVSS severity and to blanket KEV listing. The replacement keys them to a combination of risk signals: whether the asset is publicly exposed, whether the vulnerability is exploitable, whether exploitation can be automated, and what an attacker gains on success.
Vulnerabilities meeting all four conditions must be remediated within three days, with forensic triage to establish whether compromise preceded the patch. Lower tiers run to 14 and 60 days, and the lowest-risk findings may be deferred to the next system upgrade.
The directive binds Federal Civilian Executive Branch agencies only. Its significance for everyone else is that the agency that built the KEV catalog has formally conceded that KEV membership alone is too coarse a trigger — which is the same conclusion the VSD series reaches from the data side.
Which Weaknesses Produce Exploited Vulnerabilities?
Across CVEs published in July 2026, 357 distinct CWE identifiers were assigned, led by CWE-284 (Improper Access Control) at 901 assignments, CWE-79 (Cross-site Scripting) at 749, CWE-862 (Missing Authorization) at 453, CWE-306 (Missing Authentication for Critical Function) at 388, and CWE-89 (SQL Injection) at 386.
The picture changes when the lens narrows to weaknesses behind vulnerabilities that organizations actually had to patch. Verizon found Memory Safety weaknesses present in 89% of organizations’ detected KEV vulnerabilities, followed by Access Control at 85%. Fixing them is slow: the top three CWE categories carry a median of six to seven months to remediate half the associated codebase flaws.
Methodology
Collection. Four primary sources underpin this dataset. CVE publication counts derive from the NIST National Vulnerability Database feed, processed through the open-source monthlyCVEStats pipeline (MIT licensed), which excludes rejected records; figures were taken from that pipeline’s machine-readable outputs on August 13, 2026. KEV data comes from the CISA Known Exploited Vulnerabilities Catalog at version 2026.08.11 (released August 11, 2026, 1,665 entries). Because cisa.gov rate-limits automated retrieval, the catalog was obtained through a daily public mirror of CISA’s JSON feed; the values are CISA’s own and were validated as described below. Breach and remediation figures come from the Verizon 2026 Data Breach Investigations Report PDF. Forecast and ecosystem figures come from FIRST’s 2026 Mid-Year Vulnerability Forecast release. CVE Program participation figures come from ENISA. NVD corpus totals were read directly from the NVD Dashboard.
Validation. The KEV snapshot was checked against two independently published counts before use. FIRST reported 1,587 entries as of May 1, 2026; the snapshot returns 1,587 at that date. Verizon reported 1,526 as of February 2026; the snapshot returns 1,529 at February 28, consistent with a mid-February cut. Internal consistency was also confirmed arithmetically: the seven 2026 monthly publication counts sum to 45,626, and 45,626 plus the stated 2,536-record gap equals 48,162, the 2025 full-year total.
VSD™ formula. Vulnerability Signal Density = (KEV entries added in window ÷ CVE records published in same window) × 1,000. KEV entries are counted by dateAdded; CVE records exclude rejected entries. Windows are aligned exactly — the January–July comparison uses KEV additions through July 31 in both years, not the full catalog. Triage load is the reciprocal expressed as published CVEs per confirmed-exploited CVE. Every reading in this article is reproducible from the two named public files.
Vintage analysis. The age distribution of 2026 KEV additions was derived by parsing the year component of each CVE identifier. CVE ID year reflects the year an identifier was reserved or assigned, which is a close but not perfect proxy for disclosure date; a small number of records are assigned identifiers in one year and published in the next.
Scope. VSD measures confirmed exploitation as recorded by CISA, which is a U.S. federal catalog with a defined inclusion threshold, not a complete census of global exploitation. Vulnerabilities exploited without a CVE identifier, exploited only in targeted operations, or exploited but never catalogued fall outside it. The metric is deliberately conservative for that reason: it counts what a defender can act on from a public feed. A broader exploitability overlay such as EPSS — which covered 329,934 scored CVEs as of May 1, 2026 — would produce a higher and less certain numerator. Comparisons across years assume consistent KEV inclusion practice; the 2021 and 2022 readings are excluded from trend analysis because catalog backfill makes them incomparable. All calculations were verified in Python across two independent passes, the second using exact fractions.
About This Dataset
The complete fact table backing every figure in this article is published as a CSV containing 183 observations across seven source organizations. Each row carries the value, unit, as-of date, source organization, source document, source URL, retrieval date, a primary-source flag, an Axis-calculation flag, and a method note for every derived figure.
License: CC BY 4.0. Free to use, redistribute, and build on with attribution.
Review trigger: Next scheduled review at the close of Q3 2026 (October 2026), or immediately on publication of FIRST’s Q4 forecast update.
How to Cite This Research
APA: Axis Intelligence Research. (2026). CVE statistics 2026: Publication volume, exploitation rates, and the signal density problem. Axis Intelligence. https://axis-intelligence.com/cve-statistics/
MLA: Axis Intelligence Research. “CVE Statistics 2026: Publication Volume, Exploitation Rates, and the Signal Density Problem.” Axis Intelligence, 13 Aug. 2026, axis-intelligence.com/cve-statistics/.
Chicago: Axis Intelligence Research. “CVE Statistics 2026: Publication Volume, Exploitation Rates, and the Signal Density Problem.” Axis Intelligence, August 13, 2026. https://axis-intelligence.com/cve-statistics/.
Citing the VSD metric: Axis Intelligence Research, Vulnerability Signal Density (VSD™), as of July 31, 2026, axis-intelligence.com/cve-statistics/.
Frequently Asked Questions
What is Vulnerability Signal Density and how is it calculated?
Vulnerability Signal Density (VSD™) is an Axis Intelligence Research metric equal to KEV entries added in a period divided by CVE records published in the same period, multiplied by 1,000. It answers how many of every 1,000 disclosures carry confirmed real-world exploitation. The January–July 2026 reading is 3.77, against 5.54 for the same window in 2025.
Does a falling VSD mean vulnerability management is getting easier?
No. The numerator is roughly stable — 172 KEV additions in January–July 2026 against 152 a year earlier. What changed is the denominator. The same volume of genuinely urgent work is now buried in 66.4% more disclosures, and the DBIR’s remediation figures show organizations losing ground rather than gaining it.
Should we still use CVSS scores to prioritise patching?
Not as the primary filter. In July 2026, 58.5% of scored CVEs landed in the Critical or High bands — 5,054 records — while 26 entered the KEV catalog. CISA’s BOD 26-04 replaced severity-keyed deadlines with exposure, exploitability, automatability, and impact as the deciding signals in June 2026.
How many exploited vulnerabilities are actually new?
Fewer than most programs assume. Of the 181 vulnerabilities added to KEV in 2026, 39.2% carry pre-2026 CVE identifiers and 11.6% are from 2021 or earlier. Verizon’s exploitation-frequency analysis found that only 20% of persistently exploited KEV entries were registered in 2024 or 2025.
Why did CVE volume rise 66% in 2026?
FIRST identifies three drivers: AI-assisted vulnerability discovery, a 449% year-over-year rise in GitHub Security Advisory volume, and a 3,119% increase in VulnCheck’s CNA-of-Last-Resort activity clearing a backlog of unassigned vulnerabilities. Growth in the number of distinct tracked software products contributes independently of all three.
What does BOD 26-04 require, and does it apply to private companies?
It binds Federal Civilian Executive Branch agencies only. It requires remediation within three days for vulnerabilities that are publicly exposed, exploitable, automatable, and high-impact, with longer tiers below that, plus forensic triage on the top tier. It revokes BOD 19-02 and BOD 22-01.
How reliable is the KEV catalog as an exploitation measure?
It is authoritative for what it covers and incomplete by design. CISA adds entries on evidence of active exploitation against a defined threshold, so it undercounts targeted operations, exploitation of vulnerabilities without CVE identifiers, and activity that never surfaces publicly. Verizon found 991 of 1,526 KEV entries showed exploitation activity in the preceding twelve months — meaning roughly a third were quiet.
What is the realistic ceiling on patching speed?
Verizon’s survival analysis across more than 527 million detection records found that 60% to 70% of KEV vulnerabilities remain open at day seven regardless of year, volume, or organizational maturity. Three years of tooling investment did not move that figure, which shifts the leverage from patching faster to selecting better.
How many CVEs will be published in 2026 in total?
FIRST’s mid-year forecast, published June 15, projects approximately 66,000 — revised upward from a February median of 59,427 after actual publications ran 46.3% above baseline through April.
