Exposure report

Updated 2026-09-22ยทSource: CISA KEV

What attackers actually used

Most vulnerability coverage counts what was published. This page counts what was *exploited*: every entry CISA added to its Known Exploited Vulnerabilities catalogue in the last 365 days.

FigureValue
Entries added in the window303
Linked to ransomware campaigns32 (11%)
Distinct vendors affected119
Median days CISA gave to fix14

Vendors attackers exploited most

VendorConfirmed exploitedRansomware-linked
Microsoft485
Cisco212
Google110
Apple100
Fortinet100
Linux90
Adobe70
Oracle73
Synacor60
Ivanti50
SonicWall52
Broadcom41
JFrog40
Langflow40
SolarWinds41

Products attackers exploited most

ProductConfirmed exploitedRansomware-linked
Microsoft Windows222
Linux Kernel90
Apple Multiple Products80
Google Chromium V860
Cisco Catalyst SD-WAN Manager40
JFrog Artifactory40
Langflow Langflow40
Microsoft Office40
Microsoft SharePoint40
SonicWall SMA1000 Appliances42
Synacor Zimbra Collaboration Suite (ZCS)40
Android Framework30
BerriAI LiteLLM30
Fortinet Multiple Products30
Ivanti Endpoint Manager Mobile (EPMM)30

How to read this

A vendor near the top is not necessarily insecure. Widely deployed products attract attention, and a vendor that publishes honestly appears more often than one that stays quiet. What the list tells you is where attacker effort is going, which is a better guide to patching order than a raw CVE count.

Source: CISA Known Exploited Vulnerabilities catalogue, recounted every day. Raw numbers: exposure.json.