Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

CISA KEV Tracker 2026: Every Known Exploited Vulnerability Added, With Confirmation Lag

CISA KEV Tracker 2026

Last updated: 13 August 2026 08:15 UTC — Update frequency: within 24 hours of each CISA catalog release. | Maintained by: Axis Intelligence Research & Marcus Chen

Axis Intelligence Research tracks every addition to CISA’s Known Exploited Vulnerabilities Catalog and records one thing the catalog itself does not publish: how long the vulnerability had been a named, public CVE before the U.S. government confirmed it was being exploited. We call that interval the Exploitation Confirmation Lag™ (ECL™). Across the twelve entries logged here, the median is 2 days.


Quick Answer

The CISA KEV catalog held 1,665 entries at catalog version 2026.08.11. This tracker logs each new addition with its CVE Program publication date, its CNA-assigned CVSS base score, its BOD 26-04 remediation window, and its ECL™. Across the twelve entries added between July 27 and August 11, 2026, the median ECL™ is 2 days and the mean is 31.7 days — a gap that exists because the distribution is bimodal, not because the average entry sits near a month.

Key Findings

  1. Axis Intelligence Research finds a median Exploitation Confirmation Lag™ of 2.0 days across the twelve KEV entries added between July 27 and August 11, 2026.
  2. Axis Intelligence Research finds that 6 of those 12 entries were added to the KEV catalog within one calendar day of the CVE record being published.
  3. Axis Intelligence Research finds that 10 of the 12 entries carry a three-day federal remediation deadline under BOD 26-04, and none carries the 21-day window that governed nearly every 2025 addition.
  4. Axis Intelligence Research finds three entries with an ECL™ above 60 days — Progress LoadMaster at 64, Apache Tomcat at 117, and Fortinet FortiOS at 167 — all patched months before exploitation was confirmed.
  5. Axis Intelligence Research finds that all twelve entries carry CISA’s Unknown ransomware flag, which records unconfirmed attribution rather than confirmed absence.

What Is the Exploitation Confirmation Lag™ (ECL™)?

ECL™ is an Axis Intelligence Research metric computed per KEV entry:

ECL™ = dateAdded (CISA KEV Catalog) − datePublished (CVE Program record), in calendar days.

Both inputs are primary, machine-readable, and version-stamped. Nothing is estimated. A vulnerability with an ECL™ of zero was confirmed exploited the same day the world learned its name. A vulnerability with an ECL™ of 167 sat in public catalogs, with a vendor patch available, for nearly six months before CISA attested to exploitation.

The metric answers a question the KEV catalog is structurally unable to answer on its own: is this a fresh flaw that outran the patch cycle, or an old one that outlasted it? Those two failures have nothing in common operationally. The first is a disclosure-response problem. The second is an asset-inventory problem, and no amount of patching speed fixes it.

Baseline reading, as of August 11, 2026: median ECL™ 2.0 days across 12 entries (n=12, window 2026-07-27 to 2026-08-11). This is the inaugural baseline. No prior readings exist and the metric makes no claim about its own history.

Marcus Chen: The mean is 31.7 days and the median is 2. When those two numbers are sixteen times apart, the average is not describing anything real — it is describing two separate populations that happen to share a table. Six entries landed within a day of disclosure. Three landed more than two months later. There is almost nothing in between. Report the median, publish the distribution, and never let anyone quote the mean back at you as “the typical KEV entry.”

Current Entries

Reverse chronological. Every row is sourced to the CISA KEV Catalog v2026.08.11 and the CVE Program record for that identifier, both retrieved August 13, 2026.

August 11, 2026 — Metabase SQL injection (CVE-2026-72898)

AXKEV-0012 · Metabase · CWE-89 · CVSS 10.0 CRITICAL (CNA: CISA) · ECL™ 1 day · Due 2026-08-14 (3-day window)

A SQL injection flaw in the Metabase analytics platform, cataloged one day after the CVE record was published. The CVE was assigned by CISA’s own CNA rather than by the vendor, and the CVSS 10.0 base score reflects unauthenticated network access with scope change. Primary record: NVD CVE-2026-72898. Vendor advisory of record: GHSA-vwf4-m7j8-wcjf.

August 11, 2026 — Microsoft Windows AFD.sys use-after-free (CVE-2026-68820)

AXKEV-0011 · Microsoft · CWE-416 · CVSS 7.0 HIGH base (CNA: Microsoft) · ECL™ 0 days · Due 2026-08-25 (14-day window) · ⚠ source_inconsistency

A use-after-free in the Ancillary Function Driver for WinSock, added to KEV the same day the CVE published. Microsoft’s CNA vector string carries the temporal modifiers E:U/RL:O/RC:C — an Exploit Code Maturity value of Unproven on a vulnerability CISA listed as actively exploited that same day. We flag the discrepancy rather than resolve it. The base score of 7.0 is what we record; the temporal string is disclosed because a reader comparing our figure to a vendor dashboard will otherwise see two different numbers. Primary record: NVD CVE-2026-68820. Advisory of record: MSRC CVE-2026-68820.

August 11, 2026 — Cisco Secure Firewall ASA/FTD heap inspection (CVE-2026-20349)

AXKEV-0010 · Cisco · CWE-244 · CVSS 8.6 HIGH (CNA: Cisco) · ECL™ 0 days · Due 2026-08-14 (3-day window)

Insufficient error checking in the Remote Access SSL VPN service allows an unauthenticated remote attacker to force a device reload. Cisco disclosed and CISA cataloged on the same day. CISA’s SSVC decision on this entry records exploitation active, automatable yes, technical impact partial — the combination that produces the three-day tier under BOD 26-04. Primary record: NVD CVE-2026-20349. Advisory of record: cisco-sa-asaftd-vpn-dos-dzv4mQFF.

August 7, 2026 — Progress LoadMaster command injection (CVE-2026-8037)

AXKEV-0009 · Progress · CWE-77 · CVSS 9.6 CRITICAL (CNA: Progress Software) · ECL™ 64 days · Due 2026-08-10 (3-day window)

Published June 4, cataloged August 7. Progress shipped a critical security bulletin covering this CVE two months before exploitation was confirmed, which means the three-day federal clock landed on estates that had already had sixty-four days to act. Primary record: NVD CVE-2026-8037.

August 5, 2026 — JetBrains TeamCity deserialization (CVE-2026-63077)

AXKEV-0008 · JetBrains · CWE-502 · CVSS 9.8 CRITICAL (CNA: JetBrains) · ECL™ 9 days · Due 2026-08-08 (3-day window)

Deserialization of untrusted data in a build server — the class of software that holds signing keys and deployment credentials by design. Nine days from disclosure to confirmed exploitation. Primary record: NVD CVE-2026-63077.

August 4, 2026 — Apache Tomcat missing encryption (CVE-2026-34486)

AXKEV-0006 · Apache · CWE-311 · CVSS not assigned by CNA · ECL™ 117 days · Due 2026-08-07 (3-day window) · ⚠ pending_primary

Published April 9, cataloged August 4. The Apache Software Foundation’s CVE record carries no CVSS metrics block, so we publish no severity score for this entry rather than substitute one from a scanner or aggregator. The row stays flagged until a primary score exists. Primary record: NVD CVE-2026-34486.

August 4, 2026 — IBM Langflow code injection (CVE-2026-9198)

AXKEV-0007 · IBM · CWE-94 · CVSS 9.8 CRITICAL (CNA: IBM) · ECL™ 18 days · Due 2026-08-07 (3-day window)

Code injection in an AI application framework, unauthenticated over the network. Eighteen days from publication to KEV. Primary record: NVD CVE-2026-9198.

August 4, 2026 — N-able N-central authentication bypass (CVE-2026-18556)

AXKEV-0005 · N-able · CWE-288 · CVSS 8.2 HIGH, CVSS 4.0 (CNA: N-able) · ECL™ 3 days · Due 2026-08-07 (3-day window)

The second of two N-central authentication bypasses cataloged within 24 hours of each other. N-central is remote monitoring and management software used by managed service providers, so a single compromised instance reaches every downstream client estate it administers. Primary record: NVD CVE-2026-18556.

August 3, 2026 — N-able N-central authentication bypass (CVE-2026-18577)

AXKEV-0004 · N-able · CWE-288 · CVSS 8.2 HIGH, CVSS 4.0 (CNA: N-able) · ECL™ 1 day · Due 2026-08-06 (3-day window)

Same weakness class, same product, cataloged one day after publication. The CNA vector carries an E:A (Attacked) exploit maturity modifier, which is consistent with the KEV listing rather than in tension with it. Primary record: NVD CVE-2026-18577.

July 29, 2026 — Cisco Secure Firewall Management Center hard-coded password (CVE-2026-20316)

AXKEV-0003 · Cisco · CWE-259 · CVSS 5.3 MEDIUM (CNA: Cisco) · ECL™ 0 days · Due 2026-08-01 (3-day window)

A hard-coded credential in the management plane of a firewall fleet, scored 5.3 because the direct impact is limited confidentiality loss. It carries a three-day deadline anyway. This entry is the clearest argument in the current set for reading BOD 26-04 tiers as an exposure-and-automatability judgment rather than a severity ranking — a MEDIUM-scored flaw and a CRITICAL-scored one sit on the same clock. Primary record: NVD CVE-2026-20316.

July 27, 2026 — Arista VeloCloud Orchestrator command injection (CVE-2026-16812)

AXKEV-0002 · Arista · CWE-78 · CVSS 10.0 CRITICAL, CVSS 4.0 (CNA: Arista) · ECL™ 0 days · Due 2026-07-30 (3-day window)

OS command injection in an SD-WAN orchestrator, scored 10.0 under CVSS 4.0 with subsequent-system impact high across the board. Disclosed and cataloged the same day. Primary record: NVD CVE-2026-16812.

July 27, 2026 — Fortinet FortiOS information exposure (CVE-2025-68686)

AXKEV-0001 · Fortinet · CWE-200 · CVSS 5.3 MEDIUM base (CNA: Fortinet) · ECL™ 167 days · Due 2026-08-10 (14-day window) · ⚠ temporal_modifiers_present

The longest lag in the current set. A 2025-identifier CVE published February 10, 2026 and cataloged July 27 — 167 days. Fortinet’s vector string carries E:P/RL:O/RC:C; the 5.3 we record is the base score, not the temporal score Fortinet’s PSIRT page displays by default. Primary record: NVD CVE-2025-68686. Advisory of record: FG-IR-25-934.

Marcus Chen: Ten of twelve entries carry a three-day clock, and the two that do not are the Microsoft privilege-escalation bug and the Fortinet information-disclosure bug — both local or low-impact by the directive’s variables, both on fourteen days. That is BOD 26-04 working as designed, which is worth saying plainly because the early commentary assumed the three-day tier would be reserved for the spectacular cases. It is not. It is the default for anything internet-facing and automatable, and in a two-week sample that turned out to be almost everything CISA cataloged.

How We Curate This List

What counts. An entry is added to this tracker if and only if it appears in a published, version-stamped release of the CISA Known Exploited Vulnerabilities Catalog. CISA’s inclusion bar — an assigned CVE identifier, reliable evidence of active exploitation, and a clear remediation action — is our inclusion bar. We do not add vulnerabilities we believe are exploited, and we do not add vulnerabilities that commercial exploitation feeds list but CISA does not.

What each entry must carry. Date added, CVE identifier, vendor, product, CWE, CNA-assigned CVSS base score and vector, CVE Program publication date, ECL™, BOD 26-04 due date and remediation window, and CISA’s ransomware flag. Every field traces to one of exactly two primary feeds. A row we cannot populate from those feeds does not ship a guessed value — it ships a flag.

Two sources, both primary, both retrieved per update:

  1. CISA Known Exploited Vulnerabilities Catalog — retrieved from the cisagov/kev-data repository, which mirrors the agency’s published JSON and CSV with commit history. Catalog version and dateReleased are recorded with every pull. (CISA’s own web catalog blocks automated retrieval; the agency’s GitHub mirror is the same artifact with a diffable history, which is why we use it.)
  2. CVE Program record — retrieved from CVEProject/cvelistV5, the authoritative CVE record store. This supplies datePublished and the CNA-assigned CVSS metrics.

What is explicitly excluded.

  • Scanner and aggregator severity scores. If the CNA published no CVSS, we publish no CVSS. AXKEV-0006 is currently in that state.
  • Temporal and environmental CVSS scores. We record base scores only. Where a vendor’s vector string carries E:, RL:, or RC: modifiers, we flag it, because the score displayed on that vendor’s own advisory page will not match ours.
  • Exploitation claims from vendor marketing, threat-intel blogs, or news reporting. These may tell us where to look; they never populate a field.
  • Commercial exploitation feeds. Broader datasets exist and are legitimate. They are not CISA, and mixing them would make ECL™ uncomputable.
  • Downdetector-style crowd-sourced signals. Not applicable here, and never a source in any Axis tracker.

Verification flags are published, not suppressed. source_inconsistency means two primary sources disagree and we have documented the disagreement instead of picking a winner. pending_primary means a required field has no primary value yet. temporal_modifiers_present means the CNA vector includes non-base modifiers a reader should know about. Flags clear only when a primary source resolves them.

Corrections. Any factual correction gets a dated note on this page. We do not silently edit a wrong value. Report an error to [email protected].

How Is ECL™ Calculated?

For each entry:

ECL_days = date(KEV dateAdded) − date(CVE Program datePublished)

Calendar days, not business days. Both dates are taken as UTC dates from the source records. The tracker-level baseline is the median ECL™ across all entries in the current window; we publish the mean alongside it purely to expose the skew, never as the headline.

Worked example, AXKEV-0001: CVE-2025-68686 published 2026-02-10, added to KEV 2026-07-27. 2026-07-27 − 2026-02-10 = 167 days.

Methodology version 1.0. If the window definition, the date basis, or the central-tendency choice changes, the version increments and the change is stated here. Historical readings are never rewritten in place.

Stated limitations. ECL™ measures the interval between two administrative timestamps, not between exploitation and detection. A CVE can be exploited before it is published, in which case ECL™ understates the true exposure window — and a zero-day, by definition, produces an ECL™ at or near zero for exactly that reason. ECL™ also inherits CISA’s analyst capacity as a confounder: a longer lag may reflect delayed confirmation rather than delayed attacker interest. It says nothing about installed base, patch availability, or how quickly anyone actually remediated.

Which Vendors Appear in the Current Window?

VendorEntriesMedian ECL™ (days)3-day windowsSource
Cisco202Axis calculation on CISA KEV + CVE Program
N-able222Axis calculation on CISA KEV + CVE Program
Apache11171Axis calculation on CISA KEV + CVE Program
Arista101Axis calculation on CISA KEV + CVE Program
Fortinet11670Axis calculation on CISA KEV + CVE Program
IBM1181Axis calculation on CISA KEV + CVE Program
JetBrains191Axis calculation on CISA KEV + CVE Program
Metabase111Axis calculation on CISA KEV + CVE Program
Microsoft100Axis calculation on CISA KEV + CVE Program
Progress1641Axis calculation on CISA KEV + CVE Program

Twelve entries across ten vendors is too small a sample to rank anyone, and we will not do so until the tracker holds a full quarter. What the window does show is composition: seven of the twelve are network, security, or infrastructure-management products, and the two entries with the longest lags are both appliance software.

For vendor-level pressure scoring across the full 1,665-entry catalog, see the KEV Exposure Pressure Index™ (KEPI™) on our CISA KEV statistics page. ECL™ and KEPI™ are deliberately different instruments: KEPI™ scores accumulated vendor exposure across the whole catalog, ECL™ scores the timing of a single entry.

Archive

<details> <summary><strong>Entries added before July 27, 2026</strong></summary>

The archive opens with the September 2026 update. Entries added between the catalog’s establishment in November 2021 and July 26, 2026 are covered in aggregate on our CISA KEV statistics page; backfilling them into this tracker at entry level, with per-entry ECL™, is scheduled and will be published in dated batches rather than appearing silently.

Download the Dataset

kev-tracker-august-13-2026.csv — 12 rows, one per tracked KEV entry, CC BY 4.0.

Each row carries entry_id, date_added, cve_id, vendor, product, vulnerability_name, cwe, cvss_base_score, cvss_severity, cvss_vector, cvss_source_cna, cve_published_date, ecl_days, due_date, remediation_window_days, ransomware_use, verification_flag, source_org, source_document, source_url, vendor_advisory_url, retrieved_date, is_primary, axis_calculated, method_note, and license. Values are raw — no symbols, no separators. Dates are ISO 8601. Empty cells mean no primary value exists; they are never zero-filled.

Every figure in this page recomputes from this file. If a number here and a number there disagree, the CSV is authoritative and the page is wrong — tell us.

Cite This Tracker

APA Axis Intelligence Research. (2026). CISA KEV tracker: Every known exploited vulnerability added, with confirmation lag. https://axis-intelligence.com/kev-tracker/

MLA Axis Intelligence Research. “CISA KEV Tracker: Every Known Exploited Vulnerability Added, With Confirmation Lag.” Axis Intelligence, 13 Aug. 2026, axis-intelligence.com/kev-tracker/.

Chicago Axis Intelligence Research. “CISA KEV Tracker: Every Known Exploited Vulnerability Added, With Confirmation Lag.” Axis Intelligence, August 13, 2026. https://axis-intelligence.com/kev-tracker/.

ECL™ attribution: ECL™ (Exploitation Confirmation Lag) is a proprietary metric of Axis Intelligence Research, licensed CC BY 4.0. Cite as: Axis Intelligence Research, ECL™ baseline reading, August 11, 2026, axis-intelligence.com/kev-tracker/.

Frequently Asked Questions

How often is this tracker updated?

Within 24 hours of each CISA KEV catalog release. CISA does not publish on a fixed schedule — 2026 monthly additions have ranged from 9 to 31 — so we poll the version-stamped feed and key on catalogVersion and dateReleased rather than assuming a cadence. Every update bumps dateModified on this page.

Why does this tracker use a GitHub mirror instead of CISA’s website?

CISA’s catalog page blocks automated retrieval. The cisagov/kev-data repository is CISA’s own mirror of the same published JSON and CSV, carrying commit history, which makes diffing consecutive catalog versions substantially more reliable than diffing snapshots we captured ourselves. The artifact is identical; the retrieval path is disclosed.

What does an ECL™ of zero actually mean?

That the CVE record was published and the KEV entry was created on the same calendar date. In practice this is the signature of a coordinated disclosure where exploitation was already known — the vendor advisory, the CVE, and the KEV listing all land together. Four of the twelve current entries fit that pattern.

Why is the mean ECL™ so much higher than the median?

Because the distribution has two clusters and nothing in the middle. Six entries sit at 0 or 1 day; three sit at 64, 117, and 167 days. The mean of 31.7 describes no actual entry in the set. We publish it only so that anyone recomputing from our CSV gets the same answer we did.

Does an entry with a long ECL™ mean the vendor was slow to patch?

No, and the inference runs backwards. In all three long-lag cases here, the vendor had shipped a fix months before CISA confirmed exploitation. A long ECL™ describes how long a patched, published vulnerability circulated before attackers were observed using it — which is a statement about defender patch adoption and attacker timing, not about vendor response.

Why do all twelve entries show “Unknown” for ransomware use?

CISA marks Known only where ransomware campaign use has been observed and attributed. Recent additions almost always start as Unknown because attribution lags exploitation. Reading Unknown as “not used by ransomware” inverts the field’s meaning, and we re-check the flag on every catalog pull.

Can I use this data commercially?

Yes. The CSV is CC BY 4.0 — use, redistribute, and build on it with attribution to Axis Intelligence Research. If you are recomputing ECL™ on the full catalog, the formula and both source feeds are documented above; we would rather you reproduce it than cite us blind.


Related Axis Research

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.