CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Analysis

Quarterly Retrospective

What changed each quarter, measured by when it actually happened. Every figure is bucketed by the source-published event date, the date the Cybersecurity and Infrastructure Security Agency (CISA) added a Common Vulnerabilities and Exposures (CVE) record to the Known Exploited Vulnerabilities (KEV) catalog, or the date a breach was disclosed, never the date the tracker ingested the row. A current quarter is labeled quarter to date through the tracker data date, so it cannot read like a completed quarter.

Lead finding: 2026 Q2 added the most CISA Known Exploited Vulnerabilities (KEV) catalog entries in this window (75).

CISA Known Exploited Vulnerabilities added per quarter

New additions to the CISA Known Exploited Vulnerabilities catalog, counted in the quarter CISA listed them.

  • 2026 Q3 (Quarter to date through 2026-09-12 21:29 UTC)79
  • 2026 Q275
  • 2026 Q171
  • 2025 Q462
  • 2025 Q351
  • 2025 Q259
  • 2025 Q173
  • 2024 Q455

Quarter by quarter

Known ransomware share is the Cybersecurity and Infrastructure Security Agency's own flag; Unknown means CISA has not confirmed ransomware use, not that none exists. The response window is the median days from a CVE's publication to its CISA KEV listing, an upper bound on defender warning time because a listing lags first in-the-wild use, and it abstains below a five-CVE sample. Ransomware claim counts use unverified leak-site posts from RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.

QuarterCISA KEV addedKnown ransomwareRansomware claimsConfirmed breachesDays to KEV listing (median)Top CISA KEV vendors
2026 Q3Quarter to date through 2026-09-12 21:29 UTC795 (6.3%)2,4932248 days (n=79)Microsoft (11), Cisco (4), Fortinet (4), JFrog (4), SonicWall (4)
2026 Q27515 (20%)2,05232415 days (n=75)Microsoft (15), Cisco (7), Adobe (3), Ivanti (3), SimpleHelp (3)
2026 Q1716 (8.5%)1,78336333 days (n=71)Microsoft (12), Apple (7), Cisco (4), Google (3), SmarterTools (3)
2025 Q4625 (8.1%)not tracked32345.5 days (n=62)Microsoft (10), Fortinet (3), Gladinet (3), Oracle (3), Adobe (2)
2025 Q3516 (11.8%)not tracked35214 days (n=51)Cisco (5), Microsoft (5), Citrix (4), D-Link (3), Google (3)
2025 Q2597 (11.9%)not tracked37314 days (n=59)Microsoft (8), Apple (3), Ivanti (3), Linux (3), Qualcomm (3)
2025 Q17313 (17.8%)not tracked33129 days (n=73)Microsoft (16), Ivanti (4), Apple (3), Mitel (3), VMware (3)
2024 Q45513 (23.6%)not tracked33236 days (n=55)Microsoft (8), Palo Alto Networks (6), Ivanti (3), Apple (2), Cisco (2)

Every metric is bucketed by the source-published event date (the date CISA added a CVE to the Known Exploited Vulnerabilities catalog, or the date a breach was disclosed), never the date the tracker ingested the row, so a late-ingested item lands in the quarter it actually happened. The most recent quarter may still be in progress; compare completed quarters for a trend. The disclosure-to-listing median is an upper bound on defender warning time (a catalog listing lags first in-the-wild use) and abstains below a five-CVE sample. A CISA known-ransomware flag of Unknown means CISA has not confirmed ransomware use, not that none exists. Breaches without a published disclosure date are counted in coverage, not placed in a quarter. This window omits 0 CISA KEV entries and 133 breaches that carry no dated event.

Glossary