Exposure report
Updated 2026-09-22ยทSource: CISA KEV
What attackers actually used
Most vulnerability coverage counts what was published. This page counts what was *exploited*: every entry CISA added to its Known Exploited Vulnerabilities catalogue in the last 365 days.
| Figure | Value |
|---|---|
| Entries added in the window | 303 |
| Linked to ransomware campaigns | 32 (11%) |
| Distinct vendors affected | 119 |
| Median days CISA gave to fix | 14 |
Vendors attackers exploited most
| Vendor | Confirmed exploited | Ransomware-linked |
|---|---|---|
| Microsoft | 48 | 5 |
| Cisco | 21 | 2 |
| 11 | 0 | |
| Apple | 10 | 0 |
| Fortinet | 10 | 0 |
| Linux | 9 | 0 |
| Adobe | 7 | 0 |
| Oracle | 7 | 3 |
| Synacor | 6 | 0 |
| Ivanti | 5 | 0 |
| SonicWall | 5 | 2 |
| Broadcom | 4 | 1 |
| JFrog | 4 | 0 |
| Langflow | 4 | 0 |
| SolarWinds | 4 | 1 |
Products attackers exploited most
| Product | Confirmed exploited | Ransomware-linked |
|---|---|---|
| Microsoft Windows | 22 | 2 |
| Linux Kernel | 9 | 0 |
| Apple Multiple Products | 8 | 0 |
| Google Chromium V8 | 6 | 0 |
| Cisco Catalyst SD-WAN Manager | 4 | 0 |
| JFrog Artifactory | 4 | 0 |
| Langflow Langflow | 4 | 0 |
| Microsoft Office | 4 | 0 |
| Microsoft SharePoint | 4 | 0 |
| SonicWall SMA1000 Appliances | 4 | 2 |
| Synacor Zimbra Collaboration Suite (ZCS) | 4 | 0 |
| Android Framework | 3 | 0 |
| BerriAI LiteLLM | 3 | 0 |
| Fortinet Multiple Products | 3 | 0 |
| Ivanti Endpoint Manager Mobile (EPMM) | 3 | 0 |
How to read this
A vendor near the top is not necessarily insecure. Widely deployed products attract attention, and a vendor that publishes honestly appears more often than one that stays quiet. What the list tells you is where attacker effort is going, which is a better guide to patching order than a raw CVE count.
Source: CISA Known Exploited Vulnerabilities catalogue, recounted every day. Raw numbers: exposure.json.