CISA KEV Velocity Dashboard
How fast are actively exploited CVEs accumulating? This dashboard tracks the CISA Known Exploited Vulnerabilities catalog: monthly addition velocity, vendor concentration, and the share of entries tied to known ransomware campaigns. Rebuilt automatically on every site deploy.
Catalog snapshot: 2026-09-08 · 1699 entries · Source: CISA KEV Catalog · By vendor · RSS · JSON feed
How old are CVEs when exploitation is confirmed?
22% of KEV entries added in the last 12 months are CVEs from 2+ years ago (by CVE ID year): old, unpatched vulnerabilities keep getting exploited long after disclosure.
Additions per month, last 24 months
Most-listed vendors, last 12 months
Reading the numbers
A CVE only enters the KEV catalog once CISA confirms active exploitation in the wild, so the monthly addition rate is a floor on real-world exploitation activity, not a count of disclosed vulnerabilities.
Federal agencies must remediate each entry by its CISA due date under BOD 22-01; most organizations treat KEV listing as a patch-now signal regardless of CVSS score.
Vendor concentration reflects both install base and attacker focus. A vendor appearing here repeatedly is a prioritization signal for patch management programs.
Latest 25 KEV additions
| CVE | Vulnerability | Vendor / product | Added | Ransomware |
|---|---|---|---|---|
| CVE-2026-75650 | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template | Adobe Commerce and Magento | 2026-09-08 | No |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | Microsoft Windows | 2026-09-08 | No |
| CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability | N-able N-central | 2026-09-08 | No |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Microsoft Windows | 2026-09-08 | No |
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | Google Chromium V8 | 2026-09-04 | No |
| CVE-2026-59822 | BerriAI LiteLLM Improper Authentication Vulnerability | BerriAI LiteLLM | 2026-09-02 | No |
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | Kludex Starlette | 2026-09-02 | No |
| CVE-2026-49869 | Kestra OSS OS Command Injection Vulnerability | Kestra Kestra OSS | 2026-09-02 | No |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | JFrog Artifactory | 2026-09-02 | No |
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability | Sangoma Switchvox | 2026-09-02 | No |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall SMA1000 Appliances | 2026-09-02 | No |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | SonicWall SMA1000 Appliances | 2026-09-02 | No |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | PaperCut NG/MF | 2026-08-31 | No |
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | PaperCut NG/MF | 2026-08-31 | No |
| CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | ownCloud ownCloud | 2026-08-27 | No |
| CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | Linux Kernel | 2026-08-27 | No |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerabilit | JFrog Artifactory | 2026-08-27 | No |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | Ajax.NET Professional Ajax.NET Professional | 2026-08-26 | No |
| CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | Red Hat Libuser | 2026-08-26 | No |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | Red Hat Automatic Bug Reporting Tool | 2026-08-26 | No |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | Linux Kernel | 2026-08-26 | No |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the B | Citrix NetScaler ADC and NetScaler Gateway | 2026-08-26 | No |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft SQL Server | 2026-08-26 | No |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | Gitea Gitea | 2026-08-25 | No |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulner | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | 2026-08-24 | No |
CVE links go to our explainer when one exists, otherwise to the NVD record.
Methodology & reuse
Data is the official CISA Known Exploited Vulnerabilities catalog, fetched at build time; this page regenerates on every deploy (multiple times daily). Charts and figures may be reused with attribution to East Bay Cyber and CISA. Snapshot date: 2026-09-08.