The list in numbers

As of , CISA has added 251 vulnerabilities to its list of exploited vulnerabilities in 2026 and 1,737 since it began in November 2021.

Added each year

2004006002021: 31131120212022: 55555520222023: 18718720232024: 18618620242025: 24724720252026: 2512512026
Entries CISA added to its list each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
2021311
2022555
2023187
2024186
2025247
2026251

Most exploited vendors in 2026

  1. Microsoft40
  2. Cisco18
  3. Apple9
  4. Fortinet8
  5. Google8
  6. Linux8
  7. Adobe6
  8. Citrix6
  9. Ivanti5
  10. Synacor5
  11. Check Point4
  12. JFrog4
  13. Langflow4
  14. Oracle4
  15. SolarWinds4
Entries CISA added in 2026, by vendor. Source: CISA KEV.

Year by year

Ransomware: entries CISA knows ransomware campaigns use, as flagged today. Days to listing: the median time from the CVE record's publication to CISA's listing, for the entries whose record we hold.
YearAddedUsed in ransomwareMedian days to listing
202625127 (11%)14 days
202524732 (13%)26 days
202418644 (24%)22 days
202318743 (23%)12 days
2022555132 (24%)1,436 days
202131184 (27%)446 days