CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Stats

Stats

Two views in one place. The current state covers ransomware leak-site activity, new Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) additions, and story volume for the stated period. The corpus findings are deterministic timing and coverage analyses over the tracker's own data. Ransomware leak-site activity is based on unverified claims.

Jump to corpus findings

Headline statistics

Monthly totals compare the month to date with the previous calendar month. Stories today compares the same calendar date one month earlier. No value is projected.

Current state

Ransomware leak-site activity for Month to date through 2026-09-12 21:20 UTC is based on unverified claims. This view also includes new CISA Known Exploited Vulnerabilities (KEV) additions for Month to date through 2026-09-12 21:20 UTC and story volume for 2026-08-13T21:20:58Z through 2026-09-12T21:20:58Z UTC.

7 additional claims without a disclosure date

Leak-site claims by groupMonth to date through 2026-09-12 21:20 UTC
  • 01KryBit27
  • 02The Gentlemen25
  • 03Qilin19
  • 04Direwolf17
  • 05Akira15
  • 06INC Ransom12
  • 07Storm12
  • 08Vexy Ransomware11
  • 09Safepay11
  • 10Auditteam10
  • 11Silentransomgroup8
  • 12Panzer8
Claims by sectorMonth to date through 2026-09-12 21:20 UTC
  • Manufacturing51
  • Business & Professional Services36
  • Technology30
  • Healthcare26
  • Retail23
  • Government14
  • Financial Services14
  • Transportation & Logistics13
  • Unclassified20

Unclassified: no sector signal from the leak site, or below the classifier's confidence threshold. Both are re-checked automatically.

CISA KEV additions by month22 additions, Month to date through 2026-09-12 21:20 UTC
  • 2026-0922
  • 2026-0831
  • 2026-0726
  • 2026-0623
  • 2026-0521
  • 2026-0431
  • 2026-0326
  • 2026-0228
  • 2026-0117
  • 2025-1220
  • 2025-1111
  • 2025-1031
Story volumepeak 120/day, 2026-08-13T21:20:58Z through 2026-09-12T21:20:58Z UTC
Daily story volume grouped by UTC calendar day.
2026-08-132026-09-12

Ransomware claim data is unverified:RansomLook(CC BY 4.0), withransomware.liveas a voluntarily credited failover.

What the corpus says

One question, told in 8 parts, entirely from the tracker's own data: severity does not predict exploitation, the window is short, so what warns you, what attackers actually do, where exploitation concentrates, what acting on a score would have bought, where patching may not be an option, and what we cannot see. A part whose data has not cleared the minimum sample size is omitted rather than generalised. Every number is a committed query with its sample size, date range, and sources stated; nothing here is a model output.

  1. Severity does not predict exploitation

    Many Common Vulnerabilities and Exposures (CVE) records attackers are actively exploiting carry only a Medium Common Vulnerability Scoring System (CVSS) severity, so a triage on severity alone would deprioritise them.

    18.4%
    966 of 5,256 known-exploited CVEs with a known CVSS severity carry only Medium

    18.4% of known-exploited CVEs with a known CVSS severity (966 of 5256) carry only a Medium CVSS severity, so severity alone would under-prioritise them.

    Sample: 5,256 CVEs · sources: CISA KEV, VulnCheck KEV, ENISA, NVD CVSS

  2. Time from disclosure to exploitation

    Once a CVE record publishes, the gap before it is listed as actively exploited is short. A catalog listing lags the first real attack, so the patch-ahead window a defender actually had was shorter still.

    37.6%
    1,981 of 5,263 known-exploited CVEs were listed as exploited within 7 days of CVE publication (median gap 84 days; 33.4% on or before the day the record published)

    Across 5263 known-exploited CVEs with both dates, the median gap from CVE publication to the first exploited-catalog listing is 84 days. 1981 (37.6%) were listed within 7 days of publication, and 1756 (33.4%) on or before the day the CVE record itself published. A catalog listing lags first in-the-wild use, so the real warning time was shorter.

    Sample: 5,263 CVEs · 1997-07-01 to 2026-09-12 · sources: NVD, CVEList, CISA KEV, VulnCheck KEV, ENISA

  3. Which source lists a CVE first

    Across these vulnerability sources, one usually lists a CVE before the others; the lead time is how much warning that source buys you.

    CVE published before CISA KEV listing (NVD publication)
    252 days
    CVE published before VulnCheck KEV listing (NVD publication)
    84 days
    VulnCheck KEV leads CISA KEV
    16 days
    ENISA and CISA KEV: same day
    same day

    The median EPSS score on file just before CISA added these CVEs to KEV was 1%. Counted only where a snapshot exists within the seven days before the listing; beyond the 90-day daily retention that is a weekly snapshot, so the score can be up to seven days older than the listing.

    Sample: 363 CVEs · 2024-09-17 to 2026-09-11 · sources: EPSS, CISA KEV

    10,397 pairwise observations across 4 source pairs (a CVE can appear in more than one pair, so this is not a distinct-CVE count) · sources: VulnCheck KEV, CISA KEV, NVD publication, ENISA

  4. Attacker techniques

    A handful of ATT&CK techniques account for most exploited CVEs, so detections aimed at them cover the most ground.

    • T1190 Exploit Public-Facing Application154
    • T1068 Exploitation for Privilege Escalation40
    • T1078 Valid Accounts34
    • T1203 Exploitation for Client Execution32
    • T1204.002 Malicious File31

    Among exploited CVEs with a technique mapping, the most common exploitation techniques are: T1190 (Exploit Public-Facing Application) on 154 CVEs, T1068 (Exploitation for Privilege Escalation) on 40 CVEs, T1078 (Valid Accounts) on 34 CVEs.

    Sample: 291 CVEs · sources: MITRE Engenuity CTID KEV mappings, MITRE ATT&CK

  5. Where exploitation concentrates

    Known exploitation is not spread evenly. The shares below state how much of it sits with a few vendors, and, where the data clears the sample floor, on internet-facing edge products and in known ransomware use.

    • Microsoft693
    • Apple153
    • Adobe151
    • Cisco134
    • Apache129

    The top 5 vendors account for 1260 of 5212 known-exploited CVEs with a source-published vendor (24.2%), led by Microsoft (693), Apple (153), Adobe (151). Vendor spellings are folded to one canonical name, so a vendor split across spellings is counted once; rows with no source-published vendor are excluded from the denominator.

    191 of 5214 known-exploited CVEs (3.7%) affect a product on the tracker's curated internet-facing crosswalk (firewalls, virtual private network gateways, and edge routers, the same list that gates the exposure axis). The crosswalk is deliberately small and conservative, so an unmatched CVE usually means the product is not curated, not that it is safe.

    Sample: 5,214 CVEs · sources: CISA KEV, VulnCheck KEV, ENISA, curated internet-facing crosswalk

    CISA flags 360 of 1709 CISA KEV entries with an ingested ransomware judgment (21.1%) as known ransomware campaign use. This is CISA's own published flag; 'Unknown' means CISA has not confirmed use, not that none exists.

    Sample: 1,709 CVEs · sources: CISA KEV

    Sample: 5,212 CVEs · sources: CISA KEV, VulnCheck KEV, ENISA, NVD

  6. Score thresholds: coverage and workload

    For the exploited CVEs the tracker holds pre-listing Exploit Prediction Scoring System (EPSS) history on, each row states how many an act-at-threshold policy would have flagged before the listing, and what share of the scored corpus that policy marks for action at the latest stored scores.

    Read: a higher first bar is better, and a lower second bar is less work.

    EPSS at or above 0.01
    would have caught 46.3% of KEV entries before listing
    puts 23.3% of all scored CVEs on the action list
    EPSS at or above 0.05
    would have caught 34.4% of KEV entries before listing
    puts 14.9% of all scored CVEs on the action list
    EPSS at or above 0.1
    would have caught 30.3% of KEV entries before listing
    puts 12.7% of all scored CVEs on the action list
    EPSS at or above 0.2
    would have caught 25.3% of KEV entries before listing
    puts 10.5% of all scored CVEs on the action list
    EPSS at or above 0.5
    would have caught 18.5% of KEV entries before listing
    puts 7.1% of all scored CVEs on the action list
    CVSS 7.0 or higher (comparison)
    would have caught 88.4% of KEV entries before listing
    puts 82.8% of all CVSS-scored CVEs on the action list

    Across 363 CISA KEV CVEs with an EPSS score on file within the seven days before their listing date, acting at EPSS 0.1 or above would have flagged 30.3% before the listing while marking 12.7% of the 23283 snapshot-scored CVEs for action at the latest stored scores (2026-09-12). The pre-listing score is the last stored snapshot within the seven days before the listing day; beyond the daily retention window that is a weekly snapshot. The CVSS comparison row is measured over the 18170 CVEs with a stored CVSS score, at their current scores (a different denominator, stated on the row). EPSS model versions changed inside this window (v4 on 2025-03-17), shifting scores on the epoch day(s).

    Sample: 363 CVEs · 2024-09-17 to 2026-09-11 · sources: EPSS (FIRST.org), CISA KEV, NVD CVSS

  7. Products past end of life

    Some known-exploited CVEs affect products with versions already past end of life, where no patch is coming for those versions.

    393
    Known-exploited CVEs linked to lifecycle-mapped products with past-end-of-life versions. This is a product-level signal, not proof that each CVE's affected version is past end of life. Mapping coverage is partial: 393 CVEs, 7.5% of known-exploited CVEs, map to the crosswalk

    Sample: 393 CVEs · sources: endoflife.date, CISA KEV, VulnCheck KEV, ENISA

  8. What the data cannot show

    Most tracked CVEs carry no direct ATT&CK technique mapping, so the technique picture above is a floor, not the whole of what attackers do.

    2.3%
    419 of 18,542 tracked CVEs carry a direct MITRE Engenuity CTID technique mapping

    419 of 18542 tracked CVEs (2.3%) carry a MITRE Engenuity CTID technique mapping; the rest reach ATT&CK context only through an associated actor, if any.

    Sample: 18,542 CVEs · sources: MITRE Engenuity CTID KEV mappings

Glossary