Quarterly Retrospective
What changed each quarter, measured by when it actually happened. Every figure is bucketed by the source-published event date, the date the Cybersecurity and Infrastructure Security Agency (CISA) added a Common Vulnerabilities and Exposures (CVE) record to the Known Exploited Vulnerabilities (KEV) catalog, or the date a breach was disclosed, never the date the tracker ingested the row. The most recent quarter may still be in progress, so compare completed quarters for a trend.
Known Exploited Vulnerabilities added per quarter
New additions to the CISA Known Exploited Vulnerabilities catalog, counted in the quarter CISA listed them.
Quarter by quarter
Known ransomware share is the Cybersecurity and Infrastructure Security Agency's own flag; Unknown means CISA has not confirmed ransomware use, not that none exists. The response window is the median days from a CVE's publication to its KEV listing, an upper bound on defender warning time because a listing lags first in-the-wild use, and it abstains below a five-CVE sample. Ransomware claims are unverified leak-site posts.
| Quarter | KEV added | Known ransomware | Ransomware claims | Confirmed breaches | Response window | Top KEV vendors |
|---|---|---|---|---|---|---|
| 2026 Q3may be partial | 23 | 0 (0%) | 933 | 48 | 8 days (n=23) | Microsoft (5), Fortinet (2), Langflow (2), SonicWall (2), WordPress (2) |
| 2026 Q2 | 75 | 14 (18.7%) | 2050 | 306 | 15 days (n=75) | Microsoft (15), Cisco (7), Adobe (3), Ivanti (3), SimpleHelp (3) |
| 2026 Q1 | 71 | 5 (7%) | 1783 | 360 | 33 days (n=71) | Microsoft (12), Apple (7), Cisco (4), Google (3), SmarterTools (3) |
| 2025 Q4 | 62 | 3 (4.8%) | 0 | 318 | 45.5 days (n=62) | Microsoft (10), Fortinet (3), Gladinet (3), Oracle (3), Adobe (2) |
| 2025 Q3 | 51 | 5 (9.8%) | 0 | 344 | 14 days (n=51) | Cisco (5), Microsoft (5), Citrix (4), D-Link (3), Google (3) |
| 2025 Q2 | 59 | 6 (10.2%) | 0 | 373 | 14 days (n=59) | Microsoft (8), Apple (3), Ivanti (3), Linux (3), Qualcomm (3) |
| 2025 Q1 | 73 | 12 (16.4%) | 0 | 330 | 29 days (n=73) | Microsoft (16), Ivanti (4), Apple (3), Mitel (3), VMware (3) |
| 2024 Q4 | 55 | 13 (23.6%) | 0 | 332 | 36 days (n=55) | Microsoft (8), Palo Alto Networks (6), Ivanti (3), Apple (2), Cisco (2) |
Every metric is bucketed by the source-published event date (the date CISA added a CVE to the Known Exploited Vulnerabilities catalog, or the date a breach was disclosed), never the date the tracker ingested the row, so a late-ingested item lands in the quarter it actually happened. The most recent quarter may still be in progress; compare completed quarters for a trend. The disclosure-to-listing median is an upper bound on defender warning time (a catalog listing lags first in-the-wild use) and abstains below a five-CVE sample. A CISA known-ransomware flag of Unknown means CISA has not confirmed ransomware use, not that none exists. Breaches without a published disclosure date are counted in coverage, not placed in a quarter.