Statistics
Two views in one place. The current state is this month's ransomware leak-site activity, new Known Exploited Vulnerabilities (KEV) additions, and story volume. The corpus findings are deterministic timing and coverage analyses over the tracker's own data. Leak-site counts are unverified claims.
Current state
This month's ransomware leak-site activity by group and sector, new Known Exploited Vulnerabilities (KEV) additions, and story volume over the last month. Leak-site counts are unverified claims.
Unclassified: no sector signal from the leak site, or below the classifier's confidence threshold.
Ransomware claim data:RansomLook(CC BY 4.0), withransomware.liveas a voluntarily credited failover.
What the corpus says
One question, told in 8 parts, entirely from the tracker's own data: severity does not predict exploitation, the window is short, so what warns you, what attackers actually do, where exploitation concentrates, what acting on a score would have bought, what you cannot patch, and what we cannot see. A part whose data has not cleared the minimum sample size is omitted rather than generalised. Every number is a committed query with its sample size, date range, and sources stated; nothing here is a model output.
Severity does not predict exploitation
Many Common Vulnerabilities and Exposures (CVE) records attackers are actively exploiting carry only a Medium Common Vulnerability Scoring System (CVSS) severity, so a triage on severity alone would deprioritise them.
18.5%936 of 5,062 known-exploited CVEs carry only a Medium CVSS severity18.5% of known-exploited CVEs (936 of 5062) carry only a Medium CVSS severity, so severity alone would under-prioritise them.
How fast exploitation follows disclosure
Once a CVE record publishes, the gap before it is listed as actively exploited is short. A catalog listing lags the first real attack, so the patch-ahead window a defender actually had was shorter still.
37.3%1,885 of 5,055 known-exploited CVEs were listed as exploited within 7 days of CVE publication (median gap 92 days; 33.2% on or before the day the record published)Across 5055 known-exploited CVEs with both dates, the median gap from CVE publication to the first exploited-catalog listing is 92 days. 1885 (37.3%) were listed within 7 days of publication, and 1676 (33.2%) on or before the day the CVE record itself published. A catalog listing lags first in-the-wild use, so the real warning time was shorter.
So what warns you? Here is who sees it first
Across these vulnerability sources, one usually lists a CVE before the others; the lead time is how much warning that source buys you.
NVD publication leads CISA KEVNVD publication leads VulnCheck KEVVulnCheck KEV leads CISA KEVENISA and CISA KEV: same dayThe median EPSS score on file just before CISA added these CVEs to KEV was 1%. Counted only where a snapshot exists within the seven days before the listing; beyond the 90-day daily retention that is a weekly snapshot, so the score can be up to seven days older than the listing.
Here is what attackers actually do
A handful of ATT&CK techniques account for most exploited CVEs, so detections aimed at them cover the most ground.
Among exploited CVEs with a technique mapping, the most common exploitation techniques are: T1190 (Exploit Public-Facing Application) on 154 CVEs, T1068 (Exploitation for Privilege Escalation) on 40 CVEs, T1078 (Valid Accounts) on 34 CVEs.
And where it concentrates
Known exploitation is not spread evenly. The shares below state how much of it sits with a few vendors, and, where the data clears the sample floor, on internet-facing edge products and in known ransomware use.
The top 5 vendors account for 1244 of 5054 known-exploited CVEs with a source-published vendor (24.6%), led by Microsoft (686), Apple (151), Adobe (148). Vendor spellings are folded to one canonical name, so a vendor split across spellings is counted once; rows with no source-published vendor are excluded from the denominator.
178 of 5056 known-exploited CVEs (3.5%) affect a product on the tracker's curated internet-facing crosswalk (firewalls, virtual private network gateways, and edge routers, the same list that gates the exposure axis). The crosswalk is deliberately small and conservative, so an unmatched CVE usually means the product is not curated, not that it is safe.
CISA flags 332 of 1653 KEV entries with an ingested ransomware judgment (20.1%) as known ransomware campaign use. This is CISA's own published flag; 'Unknown' means CISA has not confirmed use, not that none exists.
What acting on a score would have bought
For the exploited CVEs the tracker holds pre-listing Exploit Prediction Scoring System (EPSS) history on, each row states how many an act-at-threshold policy would have flagged before the listing, and what share of the scored corpus that policy marks for action at the latest stored scores.
EPSS at or above 0.01EPSS at or above 0.05EPSS at or above 0.1EPSS at or above 0.2EPSS at or above 0.5CVSS 7.0 or higher (comparison)Across 347 CISA KEV CVEs with an EPSS score on file within the seven days before their listing date, acting at EPSS 0.1 or above would have flagged 31.1% before the listing while marking 20.8% of the 13909 snapshot-scored CVEs for action at the latest stored scores (2026-07-26). The pre-listing score is the last stored snapshot within the seven days before the listing day; beyond the daily retention window that is a weekly snapshot. The CVSS comparison row is measured over the 10580 CVEs with a stored CVSS score, at their current scores (a different denominator, stated on the row). EPSS model versions changed inside this window (v4 on 2025-03-17), shifting scores on the epoch day(s).
Here is what you cannot patch
Some known-exploited CVEs affect products with versions already past end of life, where no patch is coming for those versions.
100%386 of 386 lifecycle-mapped known-exploited CVEs affect a product with past-end-of-life versions; coverage is partial, only 7.6% of known-exploited CVEs map to the crosswalk386 of 386 known-exploited CVEs that map to a lifecycle-tracked product (100.0%) affect a product with release versions now past end of life, where no patch is coming for those versions. This is a product-level signal, not a claim about each CVE's specific version. Coverage is partial: only 386 of 5062 known-exploited CVEs (7.6%) map to a crosswalk entry with a verified, CVE-matchable identity; the rest, including any product tracked display-only, make no lifecycle claim.
And here is what we cannot see
Most tracked CVEs carry no direct ATT&CK technique mapping, so the technique picture above is a floor, not the whole of what attackers do.
3.9%419 of 10,716 tracked CVEs carry a direct MITRE Engenuity CTID technique mapping419 of 10716 tracked CVEs (3.9%) carry a MITRE Engenuity CTID technique mapping; the rest reach ATT&CK context only through an associated actor, if any.