LiveActive security incident?Get immediate response
Reproducible vulnerability research

CISA KEV exposure brief

Current product, severity, and update signals from source-normalized Known Exploited Vulnerability records.

1,654published KEV records in the searchable library
100most recent records in this reproducible view
32critical records in the current sample
7.8median available CVSS in the current sample

What the current sample shows

Known exploitation is the primary signal: CVSS helps explain technical severity but should not replace CISA remediation due dates, asset exposure, compensating controls, or business criticality.

  • high: 56 records
  • critical: 32 records
  • medium: 12 records

Most frequently represented vendors

  1. Microsoft — 675 affected-product references
  2. n/a — 16 affected-product references
  3. QNAP Systems Inc. — 15 affected-product references
  4. Cisco — 5 affected-product references
  5. VMware — 5 affected-product references
  6. Apache Software Foundation — 3 affected-product references
  7. Fortinet — 2 affected-product references
  8. Linux — 2 affected-product references
  9. SonicWall — 2 affected-product references
  10. Apple — 1 affected-product references

Counts describe source records, not installed assets or vendor risk. Product naming differences can split or combine labels.

Recently updated KEV records

Methodology and limitations

  1. Select published records carrying a normalized CISA KEV signal.
  2. Order the public query by the library's current relevance and recency behavior and cap the visible aggregate at 100 records.
  3. Count only explicit normalized severity and affected-vendor fields; missing values are not inferred.
  4. Link every surfaced record to its source-attributed detail page and preserve CISA/CVE citations.

This brief is not an asset-specific remediation list. Validate affected versions, vendor advisories, CISA due dates, exposure, and compensating controls before prioritizing work.