Skip to content
eastbaycyber
Data

CISA KEV Velocity Dashboard

How fast are actively exploited CVEs accumulating? This dashboard tracks the CISA Known Exploited Vulnerabilities catalog: monthly addition velocity, vendor concentration, and the share of entries tied to known ransomware campaigns. Rebuilt automatically on every site deploy.

Catalog snapshot: 2026-09-08 · 1699 entries · Source: CISA KEV Catalog · By vendor · RSS · JSON feed

Total KEV entries
1,699
Added, last 30 days
37
▲ +12 vs prior period
Added, last 90 days
82
▲ +5 vs prior period
Ransomware-linked
10%
of entries added in the last 12 months

How old are CVEs when exploitation is confirmed?

190
Same year
34
1 year old
28
2-4 years old
34
5+ years old

22% of KEV entries added in the last 12 months are CVEs from 2+ years ago (by CVE ID year): old, unpatched vulnerabilities keep getting exploited long after disclosure.

Additions per month, last 24 months

2024-10: 17 added1724/102024-11: 22 added222024-12: 16 added162025-01: 14 added1425/012025-02: 27 added272025-03: 32 added322025-04: 15 added1525/042025-05: 24 added242025-06: 20 added202025-07: 20 added2025/072025-08: 15 added152025-09: 16 added162025-10: 31 added3125/102025-11: 11 added112025-12: 20 added202026-01: 17 added1726/012026-02: 28 added282026-03: 26 added262026-04: 31 added3126/042026-05: 21 added212026-06: 23 added232026-07: 26 added2626/072026-08: 31 added312026-09: 12 added12

Most-listed vendors, last 12 months

Reading the numbers

A CVE only enters the KEV catalog once CISA confirms active exploitation in the wild, so the monthly addition rate is a floor on real-world exploitation activity, not a count of disclosed vulnerabilities.

Federal agencies must remediate each entry by its CISA due date under BOD 22-01; most organizations treat KEV listing as a patch-now signal regardless of CVSS score.

Vendor concentration reflects both install base and attacker focus. A vendor appearing here repeatedly is a prioritization signal for patch management programs.

Latest 25 KEV additions

CVEVulnerabilityVendor / productAddedRansomware
CVE-2026-75650Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Adobe Commerce and Magento2026-09-08No
CVE-2026-81963Microsoft Windows Link Following VulnerabilityMicrosoft Windows2026-09-08No
CVE-2026-86218N-able N-central Static Code Injection VulnerabilityN-able N-central2026-09-08No
CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow VulnerabilityMicrosoft Windows2026-09-08No
CVE-2026-85046Google Chromium V8 Type Confusion VulnerabilityGoogle Chromium V82026-09-04No
CVE-2026-59822BerriAI LiteLLM Improper Authentication VulnerabilityBerriAI LiteLLM2026-09-02No
CVE-2026-48710Kludex Starlette HTTP Request/Response Smuggling VulnerabilityKludex Starlette2026-09-02No
CVE-2026-49869Kestra OSS OS Command Injection VulnerabilityKestra Kestra OSS2026-09-02No
CVE-2026-82329JFrog Artifactory Improper Authentication VulnerabilityJFrog Artifactory2026-09-02No
CVE-2026-9586Sangoma Switchvox SQL Injection VulnerabilitySangoma Switchvox2026-09-02No
CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWall SMA1000 Appliances2026-09-02No
CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection VulnerabilitySonicWall SMA1000 Appliances2026-09-02No
CVE-2026-82078PaperCut NG/MF Unsafe Reflection VulnerabilityPaperCut NG/MF2026-08-31No
CVE-2026-81578PaperCut NG/MF Missing Authentication for Critical Function VulnerabilityPaperCut NG/MF2026-08-31No
CVE-2023-49105ownCloud Improper Authentication VulnerabilityownCloud ownCloud2026-08-27No
CVE-2026-53362Linux Kernel Unspecified VulnerabilityLinux Kernel2026-08-27No
CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory VulnerabilitJFrog Artifactory2026-08-27No
CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data VulnerabilityAjax.NET Professional Ajax.NET Professional2026-08-26No
CVE-2015-3246Red Hat Libuser Race Condition VulnerabilityRed Hat Libuser2026-08-26No
CVE-2015-5287Red Hat Automatic Bug Reporting Tool Privilege Escalation VulnerabilityRed Hat Automatic Bug Reporting Tool2026-08-26No
CVE-2022-0995Linux Kernel Out-of-Bounds Write VulnerabilityLinux Kernel2026-08-26No
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the BCitrix NetScaler ADC and NetScaler Gateway2026-08-26No
CVE-2019-1068Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft SQL Server2026-08-26No
CVE-2026-60004Gitea Code Injection VulnerabilityGitea Gitea2026-08-25No
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerOracle HTTP Server and Oracle Weblogic Server Proxy Plug-in2026-08-24No

CVE links go to our explainer when one exists, otherwise to the NVD record.

Methodology & reuse

Data is the official CISA Known Exploited Vulnerabilities catalog, fetched at build time; this page regenerates on every deploy (multiple times daily). Charts and figures may be reused with attribution to East Bay Cyber and CISA. Snapshot date: 2026-09-08.