Skip to content
MD-5

What 1,728 Exploited Vulnerabilities Say About Patch Priorities

Our analysis of CISA's Known Exploited Vulnerabilities catalog: the vendors, flaw types and devices attackers use, and what it means for patching.

By 8 min read

On this page

Tens of thousands of new CVEs are published every year, and more than 40,000 were published in 2024 alone. Only a small fraction are ever used in real attacks. The most reliable public list of that fraction is the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog (opens in a new tab), and it is free to download.

We analyzed the full catalog as published on 27 September 2026 (catalog version 2026.09.27, 1,728 entries) to answer a practical question: if a small team can only patch or test so much, where should that effort go?

What the KEV catalog is, and isn’t

CISA adds a vulnerability to KEV only when three conditions are met: it has a CVE ID, there is reliable evidence it has been exploited in the wild, and there is clear remediation guidance such as a patch. US federal civilian agencies must fix every KEV entry by a due date under Binding Operational Directive 22-01 (opens in a new tab), issued in November 2021.

Three limits are worth keeping in mind:

  • It lists confirmed exploitation, not all exploitation. A vulnerability can be exploited for months before CISA has the evidence to add it.
  • It leans toward software US agencies run. Microsoft, Cisco and other enterprise vendors are heavily represented partly because that’s what the catalog’s audience uses.
  • Metadata improves over time. Weakness (CWE) mappings are more complete for recent entries, and the “known ransomware use” flag is often set months after an entry is added. We note where that affects the numbers.

Even with those limits, KEV is the best free signal available for separating “published” from “used”.

Finding 1: exploitation concentrates on a few vendors

Five vendors account for 43% of the catalog.

Vendor KEV entries Share of catalog
Microsoft 389 22.5%
Cisco 99 5.7%
Apple 94 5.4%
Adobe 82 4.7%
Google 75 4.3%
All others (278 vendors) 989 57.2%

Windows alone accounts for 172 entries, more than any other single product. This mostly reflects how widely these products are deployed: attackers invest where the targets are. For a small business the takeaway is simple. If your Windows, Office, browser and Apple device patching is not automatic and monitored, that’s the first gap to close, before anything more exotic.

Finding 2: the pace of additions is rising again

Year added New KEV entries
2021 (from November) 311
2022 555
2023 187
2024 186
2025 245
2026 (to 27 September) 244

The 2021 and 2022 figures include CISA loading years of historical exploitation into a new catalog. From 2023 the numbers reflect new evidence, and they are climbing: by late September 2026 the catalog had already added as many entries as in all of 2025.

Most additions are recent flaws. Of the 244 entries added in 2026, 200 (82%) have a CVE from 2025 or 2026. But old bugs have not gone away: 25 entries added in 2026 (10%) are for CVEs at least five years old, including Windows and Office flaws from 2008 and 2009. Attackers keep using what still works, and old, unpatched systems are exactly what still works.

Finding 3: authentication and injection flaws are growing, memory bugs are shrinking

We grouped each entry’s CWE mappings into three families (definitions in the methodology section below) and tracked their share of each year’s additions.

Year added Auth and access control Injection family Memory safety
2022 5% 19% 29%
2023 14% 22% 27%
2024 16% 30% 17%
2025 14% 28% 19%
2026 (to 27 September) 20% 32% 16%

An entry can fall into more than one family, and some have no CWE mapping at all, so rows don’t sum to 100%.

Two trends stand out. Memory-corruption bugs (use-after-free, out-of-bounds writes) are a shrinking share, which matches the industry’s slow shift to memory-safe languages and hardened browsers. Meanwhile the classes that dominate 2026’s additions are authentication and access-control failures (improper authentication, missing authentication for a critical function, authentication bypass) and the injection family (code and command injection, deserialization, path traversal, SSRF, SQL injection).

The most common weaknesses in 2026’s additions, by count:

CWE Weakness 2026 entries
CWE-94 Code injection 18
CWE-287 Improper authentication 16
CWE-78 OS command injection 13
CWE-502 Deserialization of untrusted data 13
CWE-306 Missing authentication for critical function 12
CWE-22 Path traversal 11
CWE-918 Server-side request forgery 9

These are the same classes a web application or network penetration test spends most of its time on. They are also the classes where a single flaw usually gives an attacker direct access from the internet, with no user interaction needed. For how access-control flaws in particular show up in custom applications, see broken access control: IDOR and BOLA.

Finding 4: edge devices are over-represented in ransomware

361 entries (21%) are flagged by CISA as known to be used in ransomware campaigns.

We then looked at 209 entries for network edge products: VPN gateways, firewalls and remote-access appliances from vendors such as Fortinet, Ivanti, Citrix, Palo Alto Networks, SonicWall, F5, Juniper and Zyxel, plus Cisco’s ASA, Firepower and IOS XE lines. 30% of those carry the ransomware flag, against 21% for the catalog as a whole.

That fits what incident responders have reported for years: the device that sits on the internet to let staff in is also the easiest way for an attacker to get in. These appliances are often patched less promptly than servers, logged less thoroughly, and exempt from endpoint security tools because nothing can be installed on them.

The ransomware flag lags. Only 27 of 2026’s 244 additions carry it so far, compared with 84 of 2021’s 311. That gap reflects slow attribution, not a sudden drop in ransomware use, so treat recent years’ ransomware figures as a floor.

Finding 5: the clock is short

CISA’s due dates show how fast it expects fixes. For entries added under BOD 22-01, the standard window is 21 days (1,025 entries), with 14 days for 277 entries and 3 or 7 days for the most urgent (139 entries). The 249 entries given roughly six months were older CVEs loaded when the catalog launched.

Three weeks is a useful benchmark for any organization. If a KEV-listed flaw affects a system you run and it’s still unpatched after 21 days, you are slower than the US government expects of its own agencies.

What to do with this

  1. Subscribe to KEV and match it against your inventory. CISA publishes the catalog as JSON and CSV feeds (opens in a new tab). Any match with software you run jumps to the top of the patch queue, above CVSS score.
  2. Treat internet-facing edge devices as tier-one assets. Patch VPNs and firewalls within days, not at the next maintenance window. Put their logs somewhere central, and know how to take them offline quickly.
  3. Automate the boring patching. Most of the catalog is operating systems, browsers and office software. Automatic updates with a report of what failed beat any manual process.
  4. Don’t ignore old systems. One in ten 2026 additions is at least five years old. Unsupported systems need to be isolated or retired, not left on the network with a note.
  5. Test your own code for the same classes. KEV covers commercial products, but the flaw types it’s full of (authentication bypass, command injection, path traversal, SSRF) are exactly what turns up in custom web applications and APIs. No catalog will ever list the bugs in your code.

A vulnerability assessment checks your internet-facing estate against known-exploited vulnerabilities and validates each match. A network penetration test goes further and shows what an attacker could reach through them.

Methodology

We downloaded CISA’s KEV JSON feed on 29 September 2026 (catalog version 2026.09.27, released 27 September 2026, 1,728 entries) and counted entries by the vendorProject, product, dateAdded, dueDate, knownRansomwareCampaignUse and cwes fields.

  • Year added is the year of dateAdded. 2026 figures cover 1 January to 27 September.
  • CVE age compares the year in the CVE ID with the year added. CVE IDs are assigned when a flaw is reserved, so this slightly overstates age for some entries.
  • Auth and access control is any of CWE-284, 285, 287, 288, 290, 294, 306, 639, 798, 862, 863 or 1390.
  • Injection family is any of CWE-22, 77, 78, 89, 94, 434, 502 or 918.
  • Memory safety is any of CWE-119, 120, 121, 122, 125, 190, 401, 415, 416, 476, 787, 843 or 908.
  • Edge devices are all entries from Fortinet, Ivanti, Pulse Secure, Citrix, Palo Alto Networks, SonicWall, F5, Juniper, Zyxel, Check Point and Array Networks, plus Cisco entries for ASA, Firepower, IOS XE and small-business routers. This is a vendor-level approximation: a few entries from these vendors are for non-edge products.

Entries with no CWE mapping (175 overall, 9 in 2026) are excluded from the weakness shares but included in totals. The analysis is descriptive: it shows what CISA has confirmed as exploited, not the full population of exploitation.

Sources

Published by

· Certified cybersecurity services

Articles are researched and written in-house and link to their primary sources (standards, advisories, papers and public datasets) so you can check every claim. Spotted an error? Email [email protected] and we’ll correct it.