Known exploited

CVEs affecting tracked vendors that appear in the CISA KEV catalog. This is the strongest available signal: confirmed exploitation in the wild, rather than a severity score that predicts it. 62 tracked, 11 with known ransomware campaign use.

28 exploited CVEs

How much warning did customers get?

How many exploited CVEs fell in each window between the CVE record publishing and CISA listing it as exploited. Read this as the outside limit of the defenders' head start, not its measure — the KEV date is when exploitation was documented, which trails when it began by an unknown margin.

Cisco n=9
0 — same day
Fortinet n=8
21 days
Palo Alto Networks n=8
1.5 days
Check Point n=3
Same day1–7 days8–30 days31–90 days91–365 days
median

A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.

Medians this close together, at these counts, are not a ranking — the distributions overlap almost entirely.

Table view
Vendor
VendorSame day1–7 days8–30 days31–90 days91–365 daysTotalMedian
Cisco6110190
Fortinet31013821
Palo Alto Networks4220081.5
Check Point111003

28 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.

By product

Which products attackers actually reach for. A product whose bars pile up in the first bucket is one being exploited the day it is disclosed.

Cisco Adaptive Security Appliance (ASA) n=6
0 — same day
Cisco Firepower Threat Defense (FTD) n=3
Cisco Secure Firewall n=6
0 — same day
FortiOS n=8
21 days
PAN-OS n=8
1.5 days
Quantum Security Gateway n=3
Quantum Spark n=2
Same day1–7 days8–30 days31–90 days91–365 days
median

A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.

Products are listed alphabetically, every one with at least one exploited CVE. Counts sum to more than the vendor total: a CVE affecting five products is a real vulnerability in each of them. Medians are shown from 5 exploited CVEs upward.

Table view
Product
ProductSame day1–7 days8–30 days31–90 days91–365 daysTotalMedian
Cisco Adaptive Security Appliance (ASA)5100060
Cisco Firepower Threat Defense (FTD)210003
Cisco Secure Firewall4010160
FortiOS31013821
PAN-OS4220081.5
Quantum Security Gateway111003
Quantum Spark110002

36 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.

Who found it changes everything

The same CVEs, grouped by how the vulnerability came to light. This is the one cut of the data where the differences are not subtle.

Vendor found it n=7
15 days
Third party n=15
0 — same day
Customer reported n=3
Not disclosed n=3
Same day1–7 days8–30 days31–90 days91–365 days
median

A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.

Vulnerabilities a vendor finds itself reach documented exploitation substantially later than ones reported from outside. Customer-reported bugs cluster at day zero for an unhappy reason: customers tend to report them after being breached. Attribution comes from vendor advisories and CVE credits; see /methodology.

Table view
Discovery channel
Discovery channelSame day1–7 days8–30 days31–90 days91–365 daysTotalMedian
Vendor found it21202715
Third party92112150
Customer reported210003
Not disclosed111003

28 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.

2 of 62 exploited CVEs are not yet mapped to a product, so they carry no vendor or category and appear only when both of those filters are set to all.

Is it getting better or worse?

Share of each year's CVEs exploited within 90 days of publication. Every year is measured over the same 90-day window and counts only CVEs old enough to have been watched for all of it, so these years are comparable in a way that filtering the charts above is not. Whole portfolio, not affected by the filters.

Share of published CVEs exploited within 90 days, by vendor and publication year
Vendor 202420252026
Check Point 20.00% 1/5 0.00% 0/10 10.00% 1/10
Cisco 1.26% 4/317 2.19% 6/274 5.76% 11/191
Fortinet 3.03% 2/66 3.52% 7/199 4.94% 4/81
Palo Alto Networks 10.00% 6/60 2.74% 2/73 3.64% 2/55

Denominator is every CVE we attribute to that vendor that year, not only the exploited ones — the question is what share of what a vendor shipped got weaponised. The newest year's denominator is smaller because CVEs published in the last 90 days are not yet eligible, not because the vendor published less.

Every exploited CVE we track

Newest KEV additions first, narrowed by the same filters. "Days to exploit" is the measure the charts bucket.

Known exploited CVEs
CVE Published Added to KEV Days to exploit Severity Vendor Products EPSS
CVE-2026-85102 KEV Sep 9, 2026 Sep 22, 2026 13 days Critical 9.8 check-point check-point-quantum-gateway 0.007
CVE-2026-20079 KEV Mar 4, 2026 Sep 9, 2026 189 days Critical 10 cisco cisco-secure-firewall 0.758
CVE-2025-25249 KEV Jan 13, 2026 Sep 9, 2026 239 days High 7.4 fortinet fortinet-fortios, fortinet-fortiswitch 0.024
CVE-2026-20349 KEV Aug 11, 2026 Aug 11, 2026 0 — same day High 8.6 cisco cisco-asa, cisco-secure-firewall 0.022
CVE-2026-20316 KEV Jul 29, 2026 Jul 29, 2026 RANSOM 0 — same day Medium 5.3 cisco cisco-secure-firewall 0.112
CVE-2025-68686 KEV Feb 10, 2026 Jul 27, 2026 167 days Medium 5.3 fortinet fortinet-fortios 0.296
CVE-2026-50751 KEV Jun 8, 2026 Jun 8, 2026 RANSOM 0 — same day Critical 9.3 check-point check-point-quantum-gateway, check-point-spark 0.838
CVE-2026-0257 KEV May 13, 2026 May 29, 2026 RANSOM 16 days High 7.8 palo-alto palo-alto-pan-os, palo-alto-prisma-access 0.952
CVE-2026-0300 KEV May 6, 2026 May 6, 2026 0 — same day Critical 9.3 palo-alto palo-alto-pan-os 0.317
CVE-2026-20131 KEV Mar 4, 2026 Mar 19, 2026 RANSOM 15 days Critical 10 cisco cisco-secure-firewall 0.334
CVE-2026-24858 KEV Jan 27, 2026 Jan 27, 2026 0 — same day Critical 9.4 fortinet fortinet-fortianalyzer, fortinet-fortimanager, fortinet-fortinac +3 0.861
CVE-2025-59718 KEV Dec 9, 2025 Dec 16, 2025 7 days Critical 9.1 fortinet fortinet-fortios, fortinet-fortiproxy, fortinet-fortiswitch 0.683
CVE-2025-20362 KEV Sep 25, 2025 Sep 25, 2025 0 — same day Medium 6.5 cisco cisco-asa, cisco-secure-firewall 0.871
CVE-2025-20333 KEV Sep 25, 2025 Sep 25, 2025 0 — same day Critical 9.9 cisco cisco-asa, cisco-secure-firewall 0.707
CVE-2025-24472 KEV Feb 11, 2025 Mar 18, 2025 RANSOM 35 days High 8.1 fortinet fortinet-fortios, fortinet-fortiproxy 0.072
CVE-2025-0111 KEV Feb 12, 2025 Feb 20, 2025 8 days High 7.1 palo-alto palo-alto-pan-os 0.020
CVE-2025-0108 KEV Feb 12, 2025 Feb 18, 2025 6 days High 8.8 palo-alto palo-alto-pan-os 0.985
CVE-2024-55591 KEV Jan 14, 2025 Jan 14, 2025 RANSOM 0 — same day Critical 9.6 fortinet fortinet-fortios, fortinet-fortiproxy 0.983
CVE-2024-3393 KEV Dec 27, 2024 Dec 30, 2024 3 days High 8.7 palo-alto palo-alto-pan-os 0.284
CVE-2024-9474 KEV Nov 18, 2024 Nov 18, 2024 RANSOM 0 — same day Medium 6.9 palo-alto palo-alto-pan-os 0.947
CVE-2024-0012 KEV Nov 18, 2024 Nov 18, 2024 RANSOM 0 — same day Critical 9.3 palo-alto palo-alto-pan-os 0.997
CVE-2024-20481 KEV Oct 23, 2024 Oct 24, 2024 1 day Medium 5.8 cisco cisco-asa, cisco-ftd 0.158
CVE-2024-23113 KEV Feb 15, 2024 Oct 9, 2024 237 days Critical 9.8 fortinet fortinet-fortios, fortinet-fortipam, fortinet-fortiproxy +1 0.617
CVE-2024-24919 KEV May 28, 2024 May 30, 2024 RANSOM 2 days High 8.6 check-point check-point-cloudguard, check-point-quantum-gateway, check-point-spark 1.000
CVE-2024-20359 KEV Apr 24, 2024 Apr 24, 2024 0 — same day Medium 6 cisco cisco-asa, cisco-ftd 0.194
CVE-2024-20353 KEV Apr 24, 2024 Apr 24, 2024 0 — same day High 8.6 cisco cisco-asa, cisco-ftd 0.707
CVE-2024-3400 KEV Apr 12, 2024 Apr 12, 2024 RANSOM 0 — same day Critical 10 palo-alto palo-alto-pan-os 1.000
CVE-2024-21762 KEV Feb 9, 2024 Feb 9, 2024 RANSOM 0 — same day Critical 9.6 fortinet fortinet-fortios, fortinet-fortiproxy 0.834