Known exploited
CVEs affecting tracked vendors that appear in the CISA KEV catalog. This is the strongest available signal: confirmed exploitation in the wild, rather than a severity score that predicts it. 62 tracked, 11 with known ransomware campaign use.
How much warning did customers get?
How many exploited CVEs fell in each window between the CVE record publishing and CISA listing it as exploited. Read this as the outside limit of the defenders' head start, not its measure — the KEV date is when exploitation was documented, which trails when it began by an unknown margin.
A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.
Medians this close together, at these counts, are not a ranking — the distributions overlap almost entirely.
Table view
| Vendor | Same day | 1–7 days | 8–30 days | 31–90 days | 91–365 days | Total | Median |
|---|---|---|---|---|---|---|---|
| Cisco | 6 | 1 | 1 | 0 | 1 | 9 | 0 |
| Fortinet | 3 | 1 | 0 | 1 | 3 | 8 | 21 |
| Palo Alto Networks | 4 | 2 | 2 | 0 | 0 | 8 | 1.5 |
| Check Point | 1 | 1 | 1 | 0 | 0 | 3 | — |
28 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.
By product
Which products attackers actually reach for. A product whose bars pile up in the first bucket is one being exploited the day it is disclosed.
A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.
Products are listed alphabetically, every one with at least one exploited CVE. Counts sum to more than the vendor total: a CVE affecting five products is a real vulnerability in each of them. Medians are shown from 5 exploited CVEs upward.
Table view
| Product | Same day | 1–7 days | 8–30 days | 31–90 days | 91–365 days | Total | Median |
|---|---|---|---|---|---|---|---|
| Cisco Adaptive Security Appliance (ASA) | 5 | 1 | 0 | 0 | 0 | 6 | 0 |
| Cisco Firepower Threat Defense (FTD) | 2 | 1 | 0 | 0 | 0 | 3 | — |
| Cisco Secure Firewall | 4 | 0 | 1 | 0 | 1 | 6 | 0 |
| FortiOS | 3 | 1 | 0 | 1 | 3 | 8 | 21 |
| PAN-OS | 4 | 2 | 2 | 0 | 0 | 8 | 1.5 |
| Quantum Security Gateway | 1 | 1 | 1 | 0 | 0 | 3 | — |
| Quantum Spark | 1 | 1 | 0 | 0 | 0 | 2 | — |
36 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.
Who found it changes everything
The same CVEs, grouped by how the vulnerability came to light. This is the one cut of the data where the differences are not subtle.
A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.
Vulnerabilities a vendor finds itself reach documented exploitation substantially later than ones reported from outside. Customer-reported bugs cluster at day zero for an unhappy reason: customers tend to report them after being breached. Attribution comes from vendor advisories and CVE credits; see /methodology.
Table view
| Discovery channel | Same day | 1–7 days | 8–30 days | 31–90 days | 91–365 days | Total | Median |
|---|---|---|---|---|---|---|---|
| Vendor found it | 2 | 1 | 2 | 0 | 2 | 7 | 15 |
| Third party | 9 | 2 | 1 | 1 | 2 | 15 | 0 |
| Customer reported | 2 | 1 | 0 | 0 | 0 | 3 | — |
| Not disclosed | 1 | 1 | 1 | 0 | 0 | 3 | — |
28 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.
2 of 62 exploited CVEs are not yet mapped to a product, so they carry no vendor or category and appear only when both of those filters are set to all.
Is it getting better or worse?
Share of each year's CVEs exploited within 90 days of publication. Every year is measured over the same 90-day window and counts only CVEs old enough to have been watched for all of it, so these years are comparable in a way that filtering the charts above is not. Whole portfolio, not affected by the filters.
| Vendor | 2024 | 2025 | 2026 |
|---|---|---|---|
| Check Point | 20.00% 1/5 | 0.00% 0/10 | 10.00% 1/10 |
| Cisco | 1.26% 4/317 | 2.19% 6/274 | 5.76% 11/191 |
| Fortinet | 3.03% 2/66 | 3.52% 7/199 | 4.94% 4/81 |
| Palo Alto Networks | 10.00% 6/60 | 2.74% 2/73 | 3.64% 2/55 |
Denominator is every CVE we attribute to that vendor that year, not only the exploited ones — the question is what share of what a vendor shipped got weaponised. The newest year's denominator is smaller because CVEs published in the last 90 days are not yet eligible, not because the vendor published less.
Every exploited CVE we track
Newest KEV additions first, narrowed by the same filters. "Days to exploit" is the measure the charts bucket.
| CVE | Published | Added to KEV | Days to exploit | Severity | Vendor | Products | EPSS |
|---|---|---|---|---|---|---|---|
| CVE-2026-93616 KEV | Sep 22, 2026 | Sep 22, 2026 | 0 — same day | Critical 9.8 | check-point | check-point-security-management | 0.024 |
| CVE-2026-85102 KEV | Sep 9, 2026 | Sep 22, 2026 | 13 days | Critical 9.8 | check-point | check-point-quantum-gateway | 0.007 |
| CVE-2026-76460 KEV | Sep 16, 2026 | Sep 16, 2026 | 0 — same day | Critical 10 | cisco | cisco-ise, cisco-ise-pic | 0.008 |
| CVE-2026-76461 KEV | Sep 14, 2026 | Sep 14, 2026 | 0 — same day | Critical 9.8 | cisco | cisco-secure-email | 0.020 |
| CVE-2026-20079 KEV | Mar 4, 2026 | Sep 9, 2026 | 189 days | Critical 10 | cisco | cisco-secure-firewall | 0.758 |
| CVE-2025-25249 KEV | Jan 13, 2026 | Sep 9, 2026 | 239 days | High 7.4 | fortinet | fortinet-fortios, fortinet-fortiswitch | 0.024 |
| CVE-2026-20349 KEV | Aug 11, 2026 | Aug 11, 2026 | 0 — same day | High 8.6 | cisco | cisco-asa, cisco-secure-firewall | 0.022 |
| CVE-2026-20316 KEV | Jul 29, 2026 | Jul 29, 2026 RANSOM | 0 — same day | Medium 5.3 | cisco | cisco-secure-firewall | 0.112 |
| CVE-2025-68686 KEV | Feb 10, 2026 | Jul 27, 2026 | 167 days | Medium 5.3 | fortinet | fortinet-fortios | 0.296 |
| CVE-2026-16232 KEV | Jul 22, 2026 | Jul 22, 2026 | 0 — same day | Critical 9.3 | check-point | check-point-multi-domain-management, check-point-security-management | 0.721 |
| CVE-2026-39808 KEV | Apr 14, 2026 | Jul 16, 2026 | 93 days | Critical 9.1 | fortinet | fortinet-fortisandbox | 0.928 |
| CVE-2026-25089 KEV | Jun 9, 2026 | Jul 16, 2026 | 37 days | Critical 9.1 | fortinet | fortinet-fortisandbox | 0.761 |
| CVE-2026-20230 KEV | Jun 3, 2026 | Jun 25, 2026 | 22 days | High 8.6 | cisco | cisco-ucm | 0.882 |
| CVE-2026-20253 KEV | Jun 10, 2026 | Jun 18, 2026 | 8 days | Critical 9.8 | cisco | splunk-enterprise | 0.969 |
| CVE-2026-20262 KEV | Jun 15, 2026 | Jun 15, 2026 | 0 — same day | Medium 6.5 | cisco | cisco-sd-wan-manager | 0.282 |
| CVE-2026-20245 KEV | Jun 4, 2026 | Jun 9, 2026 | 5 days | High 7.8 | cisco | cisco-sd-wan-manager | 0.253 |
| CVE-2026-50751 KEV | Jun 8, 2026 | Jun 8, 2026 RANSOM | 0 — same day | Critical 9.3 | check-point | check-point-quantum-gateway, check-point-spark | 0.838 |
| CVE-2026-0257 KEV | May 13, 2026 | May 29, 2026 RANSOM | 16 days | High 7.8 | palo-alto | palo-alto-pan-os, palo-alto-prisma-access | 0.952 |
| CVE-2026-20182 KEV | May 14, 2026 | May 14, 2026 | 0 — same day | Critical 10 | cisco | cisco-sd-wan-manager | 0.915 |
| CVE-2026-0300 KEV | May 6, 2026 | May 6, 2026 | 0 — same day | Critical 9.3 | palo-alto | palo-alto-pan-os | 0.317 |
| CVE-2026-20133 KEV | Feb 25, 2026 | Apr 20, 2026 | 54 days | Medium 6.5 | cisco | cisco-sd-wan-manager | 0.314 |
| CVE-2026-20128 KEV | Feb 25, 2026 | Apr 20, 2026 | 54 days | High 7.5 | cisco | cisco-sd-wan-manager | 0.077 |
| CVE-2026-20122 KEV | Feb 25, 2026 | Apr 20, 2026 | 54 days | Medium 5.4 | cisco | cisco-sd-wan-manager | 0.246 |
| CVE-2026-21643 KEV | Feb 6, 2026 | Apr 13, 2026 | 66 days | Critical 9.1 | fortinet | fortinet-forticlient | 0.941 |
| CVE-2026-35616 KEV | Apr 4, 2026 | Apr 6, 2026 | 2 days | Critical 9.1 | fortinet | fortinet-forticlient | 0.907 |
| CVE-2026-3502 KEV | Mar 30, 2026 | Apr 2, 2026 | 3 days | High 7.8 | 0.057 | ||
| CVE-2026-20131 KEV | Mar 4, 2026 | Mar 19, 2026 RANSOM | 15 days | Critical 10 | cisco | cisco-secure-firewall | 0.334 |
| CVE-2026-20127 KEV | Feb 25, 2026 | Feb 25, 2026 | 0 — same day | Critical 10 | cisco | cisco-sd-wan-manager | 0.882 |
| CVE-2026-24858 KEV | Jan 27, 2026 | Jan 27, 2026 | 0 — same day | Critical 9.4 | fortinet | fortinet-fortianalyzer, fortinet-fortimanager, fortinet-fortinac +3 | 0.861 |
| CVE-2026-20045 KEV | Jan 21, 2026 | Jan 21, 2026 | 0 — same day | High 8.2 | cisco | cisco-ucm, cisco-unity-connection | 0.045 |
| CVE-2025-20393 KEV | Dec 17, 2025 | Dec 17, 2025 | 0 — same day | Critical 10 | cisco | cisco-secure-email | 0.299 |
| CVE-2025-59718 KEV | Dec 9, 2025 | Dec 16, 2025 | 7 days | Critical 9.1 | fortinet | fortinet-fortios, fortinet-fortiproxy, fortinet-fortiswitch | 0.683 |
| CVE-2025-58034 KEV | Nov 18, 2025 | Nov 18, 2025 | 0 — same day | Medium 6.7 | fortinet | fortinet-fortiweb | 0.556 |
| CVE-2025-64446 KEV | Nov 14, 2025 | Nov 14, 2025 | 0 — same day | Critical 9.4 | fortinet | fortinet-fortiweb | 0.918 |
| CVE-2025-20352 KEV | Sep 24, 2025 | Sep 29, 2025 | 5 days | High 7.7 | cisco | cisco-ios, cisco-ios-xe | 0.394 |
| CVE-2025-20362 KEV | Sep 25, 2025 | Sep 25, 2025 | 0 — same day | Medium 6.5 | cisco | cisco-asa, cisco-secure-firewall | 0.871 |
| CVE-2025-20333 KEV | Sep 25, 2025 | Sep 25, 2025 | 0 — same day | Critical 9.9 | cisco | cisco-asa, cisco-secure-firewall | 0.707 |
| CVE-2025-20337 KEV | Jul 16, 2025 | Jul 28, 2025 | 12 days | Critical 10 | cisco | cisco-ise, cisco-ise-pic | 0.676 |
| CVE-2025-20281 KEV | Jun 25, 2025 | Jul 28, 2025 | 33 days | Critical 10 | cisco | cisco-ise | 0.972 |
| CVE-2025-25257 KEV | Jul 17, 2025 | Jul 18, 2025 | 1 day | Critical 9.6 | fortinet | fortinet-fortiweb | 0.998 |
| CVE-2025-32433 KEV | Apr 16, 2025 | Jun 9, 2025 | 54 days | Critical 10 | 0.988 | ||
| CVE-2025-32756 KEV | May 13, 2025 | May 14, 2025 | 1 day | Critical 9.6 | fortinet | fortinet-forticamera, fortinet-fortimail, fortinet-fortindr +2 | 0.298 |
| CVE-2024-20439 KEV | Sep 4, 2024 | Mar 31, 2025 | 208 days | Critical 9.8 | cisco | cisco-smart-license-utility | 0.921 |
| CVE-2025-24472 KEV | Feb 11, 2025 | Mar 18, 2025 RANSOM | 35 days | High 8.1 | fortinet | fortinet-fortios, fortinet-fortiproxy | 0.072 |
| CVE-2025-0111 KEV | Feb 12, 2025 | Feb 20, 2025 | 8 days | High 7.1 | palo-alto | palo-alto-pan-os | 0.020 |
| CVE-2025-0108 KEV | Feb 12, 2025 | Feb 18, 2025 | 6 days | High 8.8 | palo-alto | palo-alto-pan-os | 0.985 |
| CVE-2024-55591 KEV | Jan 14, 2025 | Jan 14, 2025 RANSOM | 0 — same day | Critical 9.6 | fortinet | fortinet-fortios, fortinet-fortiproxy | 0.983 |
| CVE-2024-3393 KEV | Dec 27, 2024 | Dec 30, 2024 | 3 days | High 8.7 | palo-alto | palo-alto-pan-os | 0.284 |
| CVE-2024-9474 KEV | Nov 18, 2024 | Nov 18, 2024 RANSOM | 0 — same day | Medium 6.9 | palo-alto | palo-alto-pan-os | 0.947 |
| CVE-2024-0012 KEV | Nov 18, 2024 | Nov 18, 2024 RANSOM | 0 — same day | Critical 9.3 | palo-alto | palo-alto-pan-os | 0.997 |
| CVE-2024-9465 KEV | Oct 9, 2024 | Nov 14, 2024 | 36 days | Critical 9.2 | palo-alto | palo-alto-expedition | 0.996 |
| CVE-2024-9463 KEV | Oct 9, 2024 | Nov 14, 2024 | 36 days | Critical 9.9 | palo-alto | palo-alto-expedition | 0.985 |
| CVE-2024-5910 KEV | Jul 10, 2024 | Nov 7, 2024 | 120 days | Critical 9.3 | palo-alto | palo-alto-expedition | 0.918 |
| CVE-2024-20481 KEV | Oct 23, 2024 | Oct 24, 2024 | 1 day | Medium 5.8 | cisco | cisco-asa, cisco-ftd | 0.158 |
| CVE-2024-47575 KEV | Oct 23, 2024 | Oct 23, 2024 | 0 — same day | Critical 9.8 | fortinet | fortinet-fortimanager | 0.951 |
| CVE-2024-23113 KEV | Feb 15, 2024 | Oct 9, 2024 | 237 days | Critical 9.8 | fortinet | fortinet-fortios, fortinet-fortipam, fortinet-fortiproxy +1 | 0.617 |
| CVE-2024-20399 KEV | Jul 1, 2024 | Jul 2, 2024 | 1 day | Medium 6 | cisco | cisco-nx-os | 0.043 |
| CVE-2024-24919 KEV | May 28, 2024 | May 30, 2024 RANSOM | 2 days | High 8.6 | check-point | check-point-cloudguard, check-point-quantum-gateway, check-point-spark | 1.000 |
| CVE-2024-20359 KEV | Apr 24, 2024 | Apr 24, 2024 | 0 — same day | Medium 6 | cisco | cisco-asa, cisco-ftd | 0.194 |
| CVE-2024-20353 KEV | Apr 24, 2024 | Apr 24, 2024 | 0 — same day | High 8.6 | cisco | cisco-asa, cisco-ftd | 0.707 |
| CVE-2024-3400 KEV | Apr 12, 2024 | Apr 12, 2024 RANSOM | 0 — same day | Critical 10 | palo-alto | palo-alto-pan-os | 1.000 |
| CVE-2024-21762 KEV | Feb 9, 2024 | Feb 9, 2024 RANSOM | 0 — same day | Critical 9.6 | fortinet | fortinet-fortios, fortinet-fortiproxy | 0.834 |
No exploited CVEs match these filters.