/// OUR OWN DATA · UPDATED DAILY
How long before a vulnerability is exploited
18.7% of exploited vulnerabilities were already under attack before the world knew they existed. Not an estimate: a count across 3064 cases where we hold both dates.
3064with both dates
3066in the exploited catalogue
499linked to ransomware
19seen by sensors, 30 days
From disclosure to first exploitation
Newly recorded exploitation, by month
new cases confirmed by sensors
Who gets hit
The vendors appearing most often in the exploited catalogue.
- Microsoft429
- Cisco119
- Apple106
- Adobe90
- Google75
- Apache63
- Oracle58
- D-Link51
- Linux46
- Fortinet40
How to read these numbers
- The exploitation date is when the entry was recorded, not when the attack began. It is an upper bound: the flaw was already being exploited by that date, possibly earlier.
- The population selects itself. These are all vulnerabilities known to be exploited, so these numbers say nothing about vulnerabilities in general.
- The monthly counts cover the last 730 days. Before that threshold the data is incomplete by construction, not because attacks were rarer.
Exploitation data: VulnCheck KEV and the CISA KEV catalogue. Publication dates: NVD.
Citing this data
Updated
You may reuse these figures with attribution. Suggested wording:
CyberWorldOps, «How long before a vulnerability is exploited», Aug 17, 2026. https://cyberworldops.eu/en/cve/analysis
Published under CC BY 4.0: free to reuse, including commercially, with attribution to CyberWorldOps.
Actively exploited vulnerabilities · Exploited, not yet in the CISA catalogue