Stats
Two views in one place. The current state covers ransomware leak-site activity, new Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) additions, and story volume for the stated period. The corpus findings are deterministic timing and coverage analyses over the tracker's own data. Ransomware leak-site activity is based on unverified claims.
Jump to corpus findingsHeadline statistics
- This month's leak-site claims276Unverified claimsDown from 1,137 last month
- Top group this monthKryBit27 unverified claimsDown from 38 last month
- CISA KEV additions this month22Catalog additionsDown from 31 last month
- Stories today142026-09-12 UTCDown from 72 last month
Monthly totals compare the month to date with the previous calendar month. Stories today compares the same calendar date one month earlier. No value is projected.
Current state
Ransomware leak-site activity for Month to date through 2026-09-12 21:20 UTC is based on unverified claims. This view also includes new CISA Known Exploited Vulnerabilities (KEV) additions for Month to date through 2026-09-12 21:20 UTC and story volume for 2026-08-13T21:20:58Z through 2026-09-12T21:20:58Z UTC.
7 additional claims without a disclosure date
Unclassified: no sector signal from the leak site, or below the classifier's confidence threshold. Both are re-checked automatically.
Ransomware claim data is unverified:RansomLook(CC BY 4.0), withransomware.liveas a voluntarily credited failover.
What the corpus says
One question, told in 8 parts, entirely from the tracker's own data: severity does not predict exploitation, the window is short, so what warns you, what attackers actually do, where exploitation concentrates, what acting on a score would have bought, where patching may not be an option, and what we cannot see. A part whose data has not cleared the minimum sample size is omitted rather than generalised. Every number is a committed query with its sample size, date range, and sources stated; nothing here is a model output.
Severity does not predict exploitation
Many Common Vulnerabilities and Exposures (CVE) records attackers are actively exploiting carry only a Medium Common Vulnerability Scoring System (CVSS) severity, so a triage on severity alone would deprioritise them.
18.4%966 of 5,256 known-exploited CVEs with a known CVSS severity carry only Medium18.4% of known-exploited CVEs with a known CVSS severity (966 of 5256) carry only a Medium CVSS severity, so severity alone would under-prioritise them.
Time from disclosure to exploitation
Once a CVE record publishes, the gap before it is listed as actively exploited is short. A catalog listing lags the first real attack, so the patch-ahead window a defender actually had was shorter still.
37.6%1,981 of 5,263 known-exploited CVEs were listed as exploited within 7 days of CVE publication (median gap 84 days; 33.4% on or before the day the record published)Across 5263 known-exploited CVEs with both dates, the median gap from CVE publication to the first exploited-catalog listing is 84 days. 1981 (37.6%) were listed within 7 days of publication, and 1756 (33.4%) on or before the day the CVE record itself published. A catalog listing lags first in-the-wild use, so the real warning time was shorter.
Which source lists a CVE first
Across these vulnerability sources, one usually lists a CVE before the others; the lead time is how much warning that source buys you.
CVE published before CISA KEV listing (NVD publication)CVE published before VulnCheck KEV listing (NVD publication)VulnCheck KEV leads CISA KEVENISA and CISA KEV: same dayThe median EPSS score on file just before CISA added these CVEs to KEV was 1%. Counted only where a snapshot exists within the seven days before the listing; beyond the 90-day daily retention that is a weekly snapshot, so the score can be up to seven days older than the listing.
Attacker techniques
A handful of ATT&CK techniques account for most exploited CVEs, so detections aimed at them cover the most ground.
Among exploited CVEs with a technique mapping, the most common exploitation techniques are: T1190 (Exploit Public-Facing Application) on 154 CVEs, T1068 (Exploitation for Privilege Escalation) on 40 CVEs, T1078 (Valid Accounts) on 34 CVEs.
Where exploitation concentrates
Known exploitation is not spread evenly. The shares below state how much of it sits with a few vendors, and, where the data clears the sample floor, on internet-facing edge products and in known ransomware use.
The top 5 vendors account for 1260 of 5212 known-exploited CVEs with a source-published vendor (24.2%), led by Microsoft (693), Apple (153), Adobe (151). Vendor spellings are folded to one canonical name, so a vendor split across spellings is counted once; rows with no source-published vendor are excluded from the denominator.
191 of 5214 known-exploited CVEs (3.7%) affect a product on the tracker's curated internet-facing crosswalk (firewalls, virtual private network gateways, and edge routers, the same list that gates the exposure axis). The crosswalk is deliberately small and conservative, so an unmatched CVE usually means the product is not curated, not that it is safe.
CISA flags 360 of 1709 CISA KEV entries with an ingested ransomware judgment (21.1%) as known ransomware campaign use. This is CISA's own published flag; 'Unknown' means CISA has not confirmed use, not that none exists.
Score thresholds: coverage and workload
For the exploited CVEs the tracker holds pre-listing Exploit Prediction Scoring System (EPSS) history on, each row states how many an act-at-threshold policy would have flagged before the listing, and what share of the scored corpus that policy marks for action at the latest stored scores.
Read: a higher first bar is better, and a lower second bar is less work.
EPSS at or above 0.01EPSS at or above 0.05EPSS at or above 0.1EPSS at or above 0.2EPSS at or above 0.5CVSS 7.0 or higher (comparison)Across 363 CISA KEV CVEs with an EPSS score on file within the seven days before their listing date, acting at EPSS 0.1 or above would have flagged 30.3% before the listing while marking 12.7% of the 23283 snapshot-scored CVEs for action at the latest stored scores (2026-09-12). The pre-listing score is the last stored snapshot within the seven days before the listing day; beyond the daily retention window that is a weekly snapshot. The CVSS comparison row is measured over the 18170 CVEs with a stored CVSS score, at their current scores (a different denominator, stated on the row). EPSS model versions changed inside this window (v4 on 2025-03-17), shifting scores on the epoch day(s).
Products past end of life
Some known-exploited CVEs affect products with versions already past end of life, where no patch is coming for those versions.
393Known-exploited CVEs linked to lifecycle-mapped products with past-end-of-life versions. This is a product-level signal, not proof that each CVE's affected version is past end of life. Mapping coverage is partial: 393 CVEs, 7.5% of known-exploited CVEs, map to the crosswalkWhat the data cannot show
Most tracked CVEs carry no direct ATT&CK technique mapping, so the technique picture above is a floor, not the whole of what attackers do.
2.3%419 of 18,542 tracked CVEs carry a direct MITRE Engenuity CTID technique mapping419 of 18542 tracked CVEs (2.3%) carry a MITRE Engenuity CTID technique mapping; the rest reach ATT&CK context only through an associated actor, if any.