Quarterly Retrospective
What changed each quarter, measured by when it actually happened. Every figure is bucketed by the source-published event date, the date the Cybersecurity and Infrastructure Security Agency (CISA) added a Common Vulnerabilities and Exposures (CVE) record to the Known Exploited Vulnerabilities (KEV) catalog, or the date a breach was disclosed, never the date the tracker ingested the row. A current quarter is labeled quarter to date through the tracker data date, so it cannot read like a completed quarter.
Lead finding: 2026 Q2 added the most CISA Known Exploited Vulnerabilities (KEV) catalog entries in this window (75).
CISA Known Exploited Vulnerabilities added per quarter
New additions to the CISA Known Exploited Vulnerabilities catalog, counted in the quarter CISA listed them.
Quarter by quarter
Known ransomware share is the Cybersecurity and Infrastructure Security Agency's own flag; Unknown means CISA has not confirmed ransomware use, not that none exists. The response window is the median days from a CVE's publication to its CISA KEV listing, an upper bound on defender warning time because a listing lags first in-the-wild use, and it abstains below a five-CVE sample. Ransomware claim counts use unverified leak-site posts from RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.
| Quarter | CISA KEV added | Known ransomware | Ransomware claims | Confirmed breaches | Days to KEV listing (median) | Top CISA KEV vendors |
|---|---|---|---|---|---|---|
| 2026 Q3Quarter to date through 2026-09-12 21:29 UTC | 79 | 5 (6.3%) | 2,493 | 224 | 8 days (n=79) | Microsoft (11), Cisco (4), Fortinet (4), JFrog (4), SonicWall (4) |
| 2026 Q2 | 75 | 15 (20%) | 2,052 | 324 | 15 days (n=75) | Microsoft (15), Cisco (7), Adobe (3), Ivanti (3), SimpleHelp (3) |
| 2026 Q1 | 71 | 6 (8.5%) | 1,783 | 363 | 33 days (n=71) | Microsoft (12), Apple (7), Cisco (4), Google (3), SmarterTools (3) |
| 2025 Q4 | 62 | 5 (8.1%) | not tracked | 323 | 45.5 days (n=62) | Microsoft (10), Fortinet (3), Gladinet (3), Oracle (3), Adobe (2) |
| 2025 Q3 | 51 | 6 (11.8%) | not tracked | 352 | 14 days (n=51) | Cisco (5), Microsoft (5), Citrix (4), D-Link (3), Google (3) |
| 2025 Q2 | 59 | 7 (11.9%) | not tracked | 373 | 14 days (n=59) | Microsoft (8), Apple (3), Ivanti (3), Linux (3), Qualcomm (3) |
| 2025 Q1 | 73 | 13 (17.8%) | not tracked | 331 | 29 days (n=73) | Microsoft (16), Ivanti (4), Apple (3), Mitel (3), VMware (3) |
| 2024 Q4 | 55 | 13 (23.6%) | not tracked | 332 | 36 days (n=55) | Microsoft (8), Palo Alto Networks (6), Ivanti (3), Apple (2), Cisco (2) |
Every metric is bucketed by the source-published event date (the date CISA added a CVE to the Known Exploited Vulnerabilities catalog, or the date a breach was disclosed), never the date the tracker ingested the row, so a late-ingested item lands in the quarter it actually happened. The most recent quarter may still be in progress; compare completed quarters for a trend. The disclosure-to-listing median is an upper bound on defender warning time (a catalog listing lags first in-the-wild use) and abstains below a five-CVE sample. A CISA known-ransomware flag of Unknown means CISA has not confirmed ransomware use, not that none exists. Breaches without a published disclosure date are counted in coverage, not placed in a quarter. This window omits 0 CISA KEV entries and 133 breaches that carry no dated event.