CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Analysis

Quarterly Retrospective

What changed each quarter, measured by when it actually happened. Every figure is bucketed by the source-published event date, the date the Cybersecurity and Infrastructure Security Agency (CISA) added a Common Vulnerabilities and Exposures (CVE) record to the Known Exploited Vulnerabilities (KEV) catalog, or the date a breach was disclosed, never the date the tracker ingested the row. The most recent quarter may still be in progress, so compare completed quarters for a trend.

Known Exploited Vulnerabilities added per quarter

New additions to the CISA Known Exploited Vulnerabilities catalog, counted in the quarter CISA listed them.

  • 2026 Q3 (may be partial)23
  • 2026 Q275
  • 2026 Q171
  • 2025 Q462
  • 2025 Q351
  • 2025 Q259
  • 2025 Q173
  • 2024 Q455

Quarter by quarter

Known ransomware share is the Cybersecurity and Infrastructure Security Agency's own flag; Unknown means CISA has not confirmed ransomware use, not that none exists. The response window is the median days from a CVE's publication to its KEV listing, an upper bound on defender warning time because a listing lags first in-the-wild use, and it abstains below a five-CVE sample. Ransomware claims are unverified leak-site posts.

QuarterKEV addedKnown ransomwareRansomware claimsConfirmed breachesResponse windowTop KEV vendors
2026 Q3may be partial230 (0%)933488 days (n=23)Microsoft (5), Fortinet (2), Langflow (2), SonicWall (2), WordPress (2)
2026 Q27514 (18.7%)205030615 days (n=75)Microsoft (15), Cisco (7), Adobe (3), Ivanti (3), SimpleHelp (3)
2026 Q1715 (7%)178336033 days (n=71)Microsoft (12), Apple (7), Cisco (4), Google (3), SmarterTools (3)
2025 Q4623 (4.8%)031845.5 days (n=62)Microsoft (10), Fortinet (3), Gladinet (3), Oracle (3), Adobe (2)
2025 Q3515 (9.8%)034414 days (n=51)Cisco (5), Microsoft (5), Citrix (4), D-Link (3), Google (3)
2025 Q2596 (10.2%)037314 days (n=59)Microsoft (8), Apple (3), Ivanti (3), Linux (3), Qualcomm (3)
2025 Q17312 (16.4%)033029 days (n=73)Microsoft (16), Ivanti (4), Apple (3), Mitel (3), VMware (3)
2024 Q45513 (23.6%)033236 days (n=55)Microsoft (8), Palo Alto Networks (6), Ivanti (3), Apple (2), Cisco (2)

Every metric is bucketed by the source-published event date (the date CISA added a CVE to the Known Exploited Vulnerabilities catalog, or the date a breach was disclosed), never the date the tracker ingested the row, so a late-ingested item lands in the quarter it actually happened. The most recent quarter may still be in progress; compare completed quarters for a trend. The disclosure-to-listing median is an upper bound on defender warning time (a catalog listing lags first in-the-wild use) and abstains below a five-CVE sample. A CISA known-ransomware flag of Unknown means CISA has not confirmed ransomware use, not that none exists. Breaches without a published disclosure date are counted in coverage, not placed in a quarter.