Known exploited

CVEs affecting tracked vendors that appear in the CISA KEV catalog. This is the strongest available signal: confirmed exploitation in the wild, rather than a severity score that predicts it. 64 tracked, 11 with known ransomware campaign use.

25 exploited CVEs

How much warning did customers get?

How many exploited CVEs fell in each window between the CVE record publishing and CISA listing it as exploited. Read this as the outside limit of the defenders' head start, not its measure — the KEV date is when exploitation was documented, which trails when it began by an unknown margin.

Fortinet n=8
21 days
Palo Alto Networks n=8
1.5 days
Cisco n=6
0 — same day
Check Point n=3
—
Same day1–7 days8–30 days31–90 days91–365 days
median

A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.

Medians this close together, at these counts, are not a ranking — the distributions overlap almost entirely.

Table view
Vendor
VendorSame day1–7 days8–30 days31–90 days91–365 daysTotalMedian
Fortinet31013821
Palo Alto Networks4220081.5
Cisco5100060
Check Point111003—

25 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.

By product

Which products attackers actually reach for. A product whose bars pile up in the first bucket is one being exploited the day it is disclosed.

Cisco Adaptive Security Appliance (ASA) n=6
0 — same day
Cisco Firepower Threat Defense (FTD) n=6
0 — same day
FortiOS n=8
21 days
PAN-OS n=8
1.5 days
Quantum Security Gateway n=3
—
Quantum Spark n=2
—
Same day1–7 days8–30 days31–90 days91–365 days
median

A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.

Products are listed alphabetically, every one with at least one exploited CVE. Counts sum to more than the vendor total: a CVE affecting five products is a real vulnerability in each of them. Medians are shown from 5 exploited CVEs upward.

Table view
Product
ProductSame day1–7 days8–30 days31–90 days91–365 daysTotalMedian
Cisco Adaptive Security Appliance (ASA)5100060
Cisco Firepower Threat Defense (FTD)5100060
FortiOS31013821
PAN-OS4220081.5
Quantum Security Gateway111003—
Quantum Spark110002—

33 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.

Who found it changes everything

The same CVEs, grouped by how the vulnerability came to light. This is the one cut of the data where the differences are not subtle.

Vendor found it n=6
11.5 days
Third party n=13
0 — same day
Customer reported n=3
—
Not disclosed n=3
—
Same day1–7 days8–30 days31–90 days91–365 days
median

A dash means the median is withheld: fewer than 5 exploited CVEs, where a median reads as typical behaviour but is a handful of individual cases. The counts themselves are exact.

Vulnerabilities a vendor finds itself reach documented exploitation substantially later than ones reported from outside. Customer-reported bugs cluster at day zero for an unhappy reason: customers tend to report them after being breached. Attribution comes from vendor advisories and CVE credits; see /methodology.

Table view
Discovery channel
Discovery channelSame day1–7 days8–30 days31–90 days91–365 daysTotalMedian
Vendor found it21102611.5
Third party82111130
Customer reported210003—
Not disclosed111003—

25 observations. Buckets are calendar days from the CVE record publishing to CISA listing it as exploited.

2 of 64 exploited CVEs are not yet mapped to a product, so they carry no vendor or category and appear only when both of those filters are set to all.

Is it getting better or worse?

Share of each year's CVEs exploited within 90 days of publication. Every year is measured over the same 90-day window and counts only CVEs old enough to have been watched for all of it, so these years are comparable in a way that filtering the charts above is not. Whole portfolio, not affected by the filters.

Share of published CVEs exploited within 90 days, by vendor and publication year
Vendor 202420252026
Check Point 20.00% 1/5 0.00% 0/10 10.00% 1/10
Cisco 1.26% 4/317 2.19% 6/274 5.53% 11/199
Fortinet 3.03% 2/66 3.52% 7/199 4.94% 4/81
Palo Alto Networks 10.00% 6/60 2.74% 2/73 3.64% 2/55

Denominator is every CVE we attribute to that vendor that year, not only the exploited ones — the question is what share of what a vendor shipped got weaponised. The newest year's denominator is smaller because CVEs published in the last 90 days are not yet eligible, not because the vendor published less.

Every exploited CVE we track

Newest KEV additions first, narrowed by the same filters. "Days to exploit" is the measure the charts bucket.

Known exploited CVEs
CVE Published Added to KEV Days to exploit Severity Vendor Products EPSS
CVE-2026-85102 KEV Sep 9, 2026 Sep 22, 2026 13 days Critical 9.8 Remote · no auth check-point check-point-quantum-gateway 0.075
CVE-2025-25249 KEV Jan 13, 2026 Sep 9, 2026 239 days High 7.4 Remote · no auth fortinet fortinet-fortios, fortinet-fortiswitch 0.039
CVE-2026-20349 KEV Aug 11, 2026 Aug 11, 2026 0 — same day High 8.6 Remote · no auth cisco cisco-asa, cisco-ftd 0.010
CVE-2025-68686 KEV Feb 10, 2026 Jul 27, 2026 167 days Medium 5.3 Remote · no auth fortinet fortinet-fortios 0.296
CVE-2026-50751 KEV Jun 8, 2026 Jun 8, 2026 RANSOM 0 — same day Critical 9.3 Remote · no auth check-point check-point-quantum-gateway, check-point-spark 0.063
CVE-2026-0257 KEV May 13, 2026 May 29, 2026 RANSOM 16 days High 7.8 Remote · no auth palo-alto palo-alto-pan-os, palo-alto-prisma-access 0.964
CVE-2026-0300 KEV May 6, 2026 May 6, 2026 0 — same day Critical 9.3 Remote · no auth palo-alto palo-alto-pan-os 0.317
CVE-2026-24858 KEV Jan 27, 2026 Jan 27, 2026 0 — same day Critical 9.4 Remote · no auth fortinet fortinet-fortianalyzer, fortinet-fortimanager, fortinet-fortinac +3 0.858
CVE-2025-59718 KEV Dec 9, 2025 Dec 16, 2025 7 days Critical 9.1 Remote · no auth fortinet fortinet-fortios, fortinet-fortiproxy, fortinet-fortiswitch 0.683
CVE-2025-20362 KEV Sep 25, 2025 Sep 25, 2025 0 — same day Medium 6.5 Remote · no auth cisco cisco-asa, cisco-ftd 0.871
CVE-2025-20333 KEV Sep 25, 2025 Sep 25, 2025 0 — same day Critical 9.9 cisco cisco-asa, cisco-ftd 0.707
CVE-2025-24472 KEV Feb 11, 2025 Mar 18, 2025 RANSOM 35 days High 8.1 Remote · no auth fortinet fortinet-fortios, fortinet-fortiproxy 0.072
CVE-2025-0111 KEV Feb 12, 2025 Feb 20, 2025 8 days High 7.1 palo-alto palo-alto-pan-os 0.020
CVE-2025-0108 KEV Feb 12, 2025 Feb 18, 2025 6 days High 8.8 Remote · no auth palo-alto palo-alto-pan-os 0.985
CVE-2024-55591 KEV Jan 14, 2025 Jan 14, 2025 RANSOM 0 — same day Critical 9.6 Remote · no auth fortinet fortinet-fortios, fortinet-fortiproxy 0.941
CVE-2024-3393 KEV Dec 27, 2024 Dec 30, 2024 3 days High 8.7 Remote · no auth palo-alto palo-alto-pan-os 0.291
CVE-2024-9474 KEV Nov 18, 2024 Nov 18, 2024 RANSOM 0 — same day Medium 6.9 palo-alto palo-alto-pan-os 0.948
CVE-2024-0012 KEV Nov 18, 2024 Nov 18, 2024 RANSOM 0 — same day Critical 9.3 Remote · no auth palo-alto palo-alto-pan-os 0.999
CVE-2024-20481 KEV Oct 23, 2024 Oct 24, 2024 1 day Medium 5.8 Remote · no auth cisco cisco-asa, cisco-ftd 0.158
CVE-2024-23113 KEV Feb 15, 2024 Oct 9, 2024 237 days Critical 9.8 Remote · no auth fortinet fortinet-fortios, fortinet-fortipam, fortinet-fortiproxy +1 0.617
CVE-2024-24919 KEV May 28, 2024 May 30, 2024 RANSOM 2 days High 8.6 Remote · no auth check-point check-point-cloudguard, check-point-quantum-gateway, check-point-spark 1.000
CVE-2024-20359 KEV Apr 24, 2024 Apr 24, 2024 0 — same day Medium 6 cisco cisco-asa, cisco-ftd 0.194
CVE-2024-20353 KEV Apr 24, 2024 Apr 24, 2024 0 — same day High 8.6 Remote · no auth cisco cisco-asa, cisco-ftd 0.707
CVE-2024-3400 KEV Apr 12, 2024 Apr 12, 2024 RANSOM 0 — same day Critical 10 Remote · no auth palo-alto palo-alto-pan-os 1.000
CVE-2024-21762 KEV Feb 9, 2024 Feb 9, 2024 RANSOM 0 — same day Critical 9.6 Remote · no auth fortinet fortinet-fortios, fortinet-fortiproxy 0.834