main logo icon

Published on

October 1, 2026

|

30 min read

Zero-Day Statistics 2026: Exploited Zero-Days, Time to Exploit and Patch Windows

Zero-day statistics for 2026 from Google Threat Intelligence Group, Project Zero, CISA, Mandiant, VulnCheck, Verizon, Microsoft, ZDI and the Canadian Centre for Cyber Security, with zero-days, KEV additions, time to exploit and time to patch kept apart.

Arafat Afzalzada

Arafat Afzalzada

Founder

AdvisoriesNetwork SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Google Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in the wild in 2025, 48% of them in enterprise products, and its 30 September 2026 analysis puts the January to August 2026 pace at 11 a month against 8 a month in 2025. CISA's Known Exploited Vulnerabilities catalog added 247 entries between 1 January and 1 October 2026, more than the 245 it added in all of 2025, and since BOD 26-04 revoked BOD 22-01 on 10 June 2026, 91 of the 114 new entries carry a three-day remediation deadline. Mandiant estimates the mean time to exploit at minus 7 days in 2025, while the Verizon 2026 Data Breach Investigations Report found a 43-day median to fully remediate KEV vulnerabilities and only 26% of them fully remediated. Microsoft flagged 25 CVEs as exploited in 2025 and 19 more from January to September 2026. The four measurements (zero-days exploited in the wild, KEV additions, time to exploit and time to patch) are kept separate below, each with its source, edition and window.

Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in the wild in 2025, according to its 2025 Zero-Days in Review, published on 5 March 2026, and enterprise products accounted for a record 48% of them. GTIG's 30 September 2026 analysis puts this year's pace at an average of 11 zero-days a month from January to August 2026, against 8 a month in 2025, with 22 in August alone. CISA's Known Exploited Vulnerabilities catalog added 247 entries between 1 January and 1 October 2026, already more than the 245 it added in all of 2025. Attackers keep reaching vulnerabilities earlier in their life. On the defender side, CISA's deadlines are getting shorter while the median time to fully remediate KEV vulnerabilities rose from 32 to 43 days in the Verizon 2026 Data Breach Investigations Report.

Four measurements describe the zero-day problem in 2026, and each has its own headline number. Zero-days exploited in the wild: GTIG's 90 for 2025, including 21 in security and networking products. KEV additions: CISA's 247 so far in 2026, two-thirds of them carrying a CVE ID from the same year. Time to exploit: Mandiant's M-Trends 2026 estimates the mean time to exploit at minus 7 days in 2025, meaning exploitation routinely began before a patch was released. Time to patch: the Verizon 2026 Data Breach Investigations Report found a 43-day median to fully remediate vulnerabilities in CISA's catalog, while CISA has given 91 of the 114 catalog entries added since BOD 26-04 was issued on 10 June 2026 a three-day due date. The tables below are built for CISOs, vulnerability management leads, auditors and journalists in the United States and Canada who need a zero-day number with a source they can cite.

This post is the Stingrai research team's canonical 2026 reference for zero-day statistics. It assembles more than 100 figures from 10 primary publishers: Google Threat Intelligence Group, Mandiant and Google Project Zero (all part of Google), CISA, Microsoft's Security Response Center, VulnCheck, Verizon, CrowdStrike, the TrendAI Zero Day Initiative and the Canadian Centre for Cyber Security. Lead data is full-year 2025 telemetry, the freshest complete year available; primary publishers have not yet released full-year 2026 reports as of October 2026, so partial-year 2026 figures are labeled with their window, and several counts were run by Stingrai directly on CISA's, Microsoft's, Project Zero's and ZDI's own published data. Every stat carries its source, year, and methodology window so any claim can be audited inline.

Key zero-day statistics at a glance (2026)

Key takeaways

  • Zero-day counts are rising slowly; the 2026 surge is in n-days. GTIG counted 90 zero-days in 2025, within the range of 60 to 100 a year it has seen over the previous four years, and its September 2026 analysis puts zero-days at 11 a month in 2026 against 8 in 2025. Exploitation overall grew faster: 141 exploited vulnerabilities from January to August 2026 against 127 in all of 2025, which GTIG attributes to the rapid weaponization of known vulnerabilities "rather than a flood of new zero-days."

  • KEV additions are running at their fastest pace since 2022, and the deadline attached to them has collapsed. CISA added 247 entries by 1 October 2026, more than in all of 2025, and September 2026's 43 additions were the most in a month since June 2022. The typical due date on a new entry fell from 21 days (226 of 245 entries in 2025) to 3 days (91 of 114 entries since BOD 26-04 was issued), after CISA had already moved from 21-day to 14-day deadlines in March 2026.

  • Exploitation now routinely beats the patch, and median KEV remediation time rose to 43 days. Mandiant's average time to exploit fell from 63 days in 2018 to 2019 to an estimated minus 7 days in 2025. The Verizon 2026 Data Breach Investigations Report found the median time to fully remediate a KEV vulnerability rose to 43 days, with between 60% and 70% of KEV vulnerabilities still open at Day 7. CISA's Vulnerability Review, by contrast, found critical infrastructure organizations patching KEVs faster in fiscal 2025 than in fiscal 2024.

  • Edge and security appliances are a prime zero-day target. Enterprise products drew a record 48% of 2025 zero-days, 21 of them in security and networking products (operating systems, at 39, remained the largest category), and state-sponsored espionage groups focused just over half of their attributed zero-day exploitation on edge devices and security appliances. Separately, in its catalog of exploited vulnerabilities (not only zero-days), VulnCheck found that 42.5% of the 181 network edge vulnerabilities it added in 2025 affected end-of-life or likely end-of-life devices.

  • Commercial spyware vendors now lead attributed zero-day use. For the first time GTIG attributed more zero-days to commercial surveillance vendors (15 confirmed, 3 likely) than to traditional state-sponsored espionage groups (12 confirmed, 3 likely). Financially motivated groups used 9, two of them in operations that led to ransomware.

  • Most attack activity in CISA's fiscal 2024 and 2025 data did not involve zero-days. Zero-days were 62% of the distinct vulnerabilities GTIG saw exploited from January to August 2026, but CISA's Vulnerability Review says most fiscal 2024 and 2025 threat activity "was not coordinated threat actor groups leveraging zero-day exploits" but opportunistic criminals scanning for exposed, known vulnerabilities. KEV additions are a separate measure: 44 of CISA's 247 additions in 2026 (17.8%) carry a CVE ID from 2024 or earlier.

Methodology

Date cutoff: 1 October 2026. Every figure was read from the publisher's own page, dataset or report during a research pass on that date, and figures shown only in charts were read from the rendered chart images. The post keeps four measurements apart because they answer different questions: zero-days exploited in the wild, which GTIG defines as "a vulnerability that was maliciously exploited in the wild before a patch was made publicly available"; KEV additions, which can be vulnerabilities of any age; time to exploit, where Mandiant, VulnCheck and CrowdStrike each measure a different window; and time to patch, split into observed remediation (the Verizon 2026 Data Breach Investigations Report) and policy deadlines (the due dates CISA sets). Vendor fix times appear separately, through ZDI's disclosure deadline. The next section defines each measurement and names its publisher.

Sources used: Google Threat Intelligence Group's 2025 Zero-Days in Review (5 March 2026; zero-days disclosed and detected through 31 December 2025) and its 2024 analysis (29 April 2025; used only to label restated prior-year values); GTIG's Vulnerability Discovery and Exploitation Trends in the AI Era (30 September 2026; vulnerabilities disclosed from 1 January 2025 to 31 August 2026); Google Project Zero's 0day In the Wild tracker (spreadsheet export, read 1 October 2026; latest entry patched 29 September 2026); CISA's Known Exploited Vulnerabilities catalog (JSON feed, catalog version 2026.10.01, released 1 October 2026); CISA BOD 26-04 and its implementation guidance (10 June 2026; guidance updated 25 August 2026), the revoked BOD 22-01 (3 November 2021) and BOD 26-02 (5 February 2026); the CISA Vulnerability Review for fiscal years 2024 and 2025 (26 August 2026); Mandiant's M-Trends 2026 (23 March 2026; investigations from 1 January to 31 December 2025; full report p. 78 for the time-to-exploit series) and its 2023 time-to-exploit analysis (15 October 2024); VulnCheck's State of Exploitation 2026 (21 January 2026; calendar 2025), State of Exploitation 1H 2026 (28 July 2026; first half of 2026) and Exploiting the Network Edge report (23 March 2026; 2025 data); the Verizon 2026 Data Breach Investigations Report (19 May 2026; breach dataset covering October 2024 to November 2025, and KEV remediation figures for calendar 2024 and 2025 from more than 13,000 organizations); Microsoft's Security Update Guide data (21 monthly release documents, January 2025 to September 2026, read through the public CVRF API on 1 October 2026); the TrendAI Zero Day Initiative's published advisories and disclosure policy (read 1 October 2026); CrowdStrike's 2026 Threat Hunting Report (3 August 2026; first half of 2026); and the Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 (October 2024), the joint 2023 Top Routinely Exploited Vulnerabilities advisory (12 November 2024) and its alerts listing (read 1 October 2026).

Stingrai counts and calculations: KEV additions, due dates, vendors, ransomware flags and CVE ID years were counted on CISA's JSON feed; Microsoft "Exploited" and "Publicly Disclosed" flags were counted on Microsoft's monthly release documents; ZDI totals and "(0Day)" titles were counted on ZDI's published advisory tables; Project Zero entries were counted on the tracker's yearly tabs; and Cyber Centre alerts were counted on its alerts listing. Any figure marked as a Stingrai count or calculation is arithmetic on the named primary dataset, as published on the date shown.

Limitations a reader should keep in mind:

  • Prior years get restated. GTIG's March 2026 edition counts 32 zero-days for 2019, 96 for 2021, 100 for 2023 and 78 for 2024, where its April 2025 edition counted 31, 95, 98 and 75; 2020 (31) and 2022 (63) are unchanged. Restated values are labeled.

  • Flags change after release. Microsoft corrected CVE-2026-58644's "Exploited" flag the day after the July 2026 release, and CISA can change a KEV entry's ransomware flag. Counts reflect the state on 1 October 2026.

  • Catalogs differ in scope. VulnCheck's catalog added 884 vulnerabilities in 2025 against CISA's 245, and Project Zero's tracker covers products its researchers study, so it counts fewer zero-days than GTIG.

  • Windows differ. Most lead figures cover calendar 2025; GTIG's 2026 averages run from January to August, VulnCheck's and CrowdStrike's 2026 figures cover the first half, and the Verizon 2026 Data Breach Investigations Report's breach dataset covers October 2024 to November 2025, while its KEV remediation figures are for calendar 2024 and 2025. Figures from different windows are shown side by side, never added together.

  • Dropped figures. A widely shared CrowdStrike "42%" figure on pre-disclosure exploitation was left out because CrowdStrike's press release and findings blog describe it as two different measurements, and no full-year 2026 zero-day total is estimated because no publisher has released one. Stats that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated.

What do zero-day statistics actually measure?

Four numbers dominate zero-day coverage, and each comes from a different publisher, a different definition and a different window. The table puts them side by side without combining them.

Measurement

What it counts

Latest full year

2026 so far

Publisher

Zero-days exploited in the wild

Vulnerabilities exploited before a patch was publicly available

90 (2025)

11 a month on average, January to August

Google Threat Intelligence Group

KEV additions

Vulnerabilities of any age with a CVE ID, reliable evidence of exploitation in the wild and clear remediation or mitigation guidance

245 (2025)

247 (1 January to 1 October)

CISA

Time to exploit

Average time to exploit a vulnerability before or after a patch

Minus 7 days (2025, estimated mean)

Not yet published

Mandiant

Time to patch (observed)

Median days for organizations to fully remediate KEV vulnerabilities

43 days (2025 data)

Not yet published

Verizon 2026 Data Breach Investigations Report

Time to patch (deadline)

Remediation due date CISA sets on each new KEV entry

21 days on 226 of 245 entries (2025)

3 days on 91 of 114 entries since 10 June

CISA (Stingrai count)

The distinction matters in practice. A zero-day count tells you how often attackers had a working exploit before any fix existed. A KEV addition tells you a vulnerability, old or new, has reliable evidence of exploitation in the wild and has remediation or mitigation guidance you can act on; the Verizon 2026 Data Breach Investigations Report puts it plainly: "the CISA KEV is a timestamp and not a timeline." Time to exploit tells you how long a published fix protects you before attackers catch up, and time to patch tells you how long you actually take. Mixing them produces claims the data does not support, such as treating every KEV entry as a zero-day.

How many zero-days were exploited in 2025?

90. Google Threat Intelligence Group tracked 90 vulnerabilities disclosed in 2025 and exploited as zero-days, with a cutoff date of 31 December 2025, according to its 2025 Zero-Days in Review. GTIG notes the annual total has stayed between 60 and 100 for the previous four years and describes "a trend toward stabilization at these levels." The count covers detected and disclosed zero-days only, so it is a floor rather than a census.

Year

Zero-days exploited (GTIG, March 2026 edition)

Earlier GTIG edition

2019

32

31 (April 2025 edition)

2020

31

31 (April 2025 edition)

2021

96

95 (April 2025 edition)

2022

63

63 (April 2025 edition)

2023

100

98 (April 2025 edition)

2024

78

75 (April 2025 edition)

2025

90

First published March 2026

Two-panel bar chart of GTIG zero-days exploited per year from 2019 to 2025 and the 2025 split by product category

Figure 1: Zero-days exploited in the wild per year as counted in GTIG's March 2026 edition (left), and the 2025 total by product category (right). GTIG's April 2025 edition had counted 31 for 2019, 95 for 2021, 98 for 2023 and 75 for 2024. Source: Google Threat Intelligence Group, Look What You Made Us Patch: 2025 Zero-Days in Review, 5 March 2026.

Enterprise products drew a record share

Enterprise software and appliances accounted for 43 zero-days (48%) in 2025, up from 36 (46%) in 2024 as counted in the same edition, and both the count and the share are GTIG's all-time highs. Security and networking products made up about half of them, 21, and GTIG identified 14 zero-days affecting edge devices, a figure it says "likely underrepresents the true scale of activity due to inhibited detection capabilities." End-user platforms took the other 47 (52%).

2025 zero-days by category (GTIG)

Count

Share of 90

Enterprise: security and networking products

21

23%

Enterprise: other software and appliances

22

24%

End user: desktop operating systems

24

27%

End user: mobile

15

17%

End user: browsers

8

9%

Operating systems, desktop and mobile together, were the most exploited category at 39 zero-days (44%), up from 31 (40%) in 2024 and 33 (33%) in 2023. Mobile zero-days rebounded to 15 from 9 in 2024 (17 in 2023), which GTIG partly attributes to longer exploit chains and more complete chains being found. Browsers fell below 10% of the total, which GTIG reads as a sign that browser hardening is working, while noting that better attacker operational security may also hide some activity. Memory safety flaws, mainly use-after-free and out-of-bounds write bugs, accounted for roughly 35% of the year's zero-days, while command injection, deserialization and authentication bypass flaws were common in enterprise appliances.

Which vendors and products had the most zero-days?

Microsoft led 2025 with 25 zero-days, followed by Google (11), Apple (8), Cisco and Fortinet (4 each), and Ivanti and VMware (3 each), according to GTIG's vendor chart. Six more vendors had two zero-days each and twenty had one each, which makes 33 vendors in total (Stingrai count from GTIG's chart). GTIG notes that "big tech" vendors see the most exploitation because they dominate operating systems, browsers and phones, with security vendors "following directly behind."

Vendor

Zero-days exploited in 2025 (GTIG)

Microsoft

25

Google

11

Apple

8

Cisco

4

Fortinet

4

Ivanti

3

VMware

3

Six other vendors

2 each

Twenty other vendors

1 each

Project Zero's 0day In the Wild tracker gives a separate view with a narrower scope: it generally covers products Project Zero researches and leaves out vulnerabilities "opportunistically exploited" in the gap between public disclosure and a patch. Its 2025 tab lists 43 zero-days with 2025 CVE IDs (Stingrai count); counted by patch date, 47 were patched in 2025. Memory corruption accounted for 31 of the 43 entries in the 2025 tab.

Who exploits zero-days?

GTIG could attribute a motivation for 42 of 2025's 90 zero-days. For the first time since it began tracking, it attributed more zero-day exploitation to commercial surveillance vendors (CSVs) and their customers than to traditional state-sponsored espionage groups. One zero-day was exploited by two separate groups, so the attributions below total 43.

Attributed exploitation, 2025 (GTIG)

Zero-days

Share of attributions

Commercial surveillance vendors

15

34.9%

Likely commercial surveillance vendors

3

7%

State-sponsored espionage (PRC-nexus 7, unknown location 3, Russia 1, UAE 1)

12

27.9%

Likely state-sponsored espionage (PRC-nexus)

3

7%

Cyber crime (financially motivated)

9

20.9%

Dual cyber crime and espionage motivations

1

2.3%

  • China-nexus groups remain the most prolific state users. GTIG attributed at least 10 zero-days to PRC-nexus espionage groups, double its 2024 figure but below the 12 it attributed in 2023, with continued focus on edge and networking devices.

  • North Korea dropped out. GTIG attributed five zero-days to North Korean groups in 2024 and none in 2025.

  • Financially motivated use nearly matched its record. Nine zero-days went to likely or confirmed financially motivated groups, against 5 in 2024 and 10 in 2023, including two used in operations that led to ransomware deployment. In one campaign, Oracle E-Business Suite flaws were exploited as zero-days "as early as Aug. 9, 2025, weeks before a patch was available."

  • Espionage concentrates on the edge. GTIG says "just over half" of attributed zero-day exploitation by state-sponsored espionage groups focused on edge devices and security appliances.

How many zero-days have been exploited in 2026?

No publisher has released a full-year 2026 count. The partial-year data points one way: zero-day exploitation is rising modestly while exploitation of already-disclosed vulnerabilities grows faster. GTIG's 30 September 2026 analysis, which covers vulnerabilities disclosed from 1 January 2025 to 31 August 2026, reports:

  • Zero-days averaged 11 a month from January to August 2026, up from 8 a month in 2025. Monthly counts stayed between 8 and 12 through mid-2026, then jumped to 22 in August.

  • Zero-days made up 62% of all exploited vulnerabilities GTIG observed from January to August 2026.

  • All exploitation grew faster than zero-days: GTIG recorded 141 vulnerabilities disclosed and exploited from January to August 2026, more than the 127 exploited in all of 2025, or 18 a month against 10.5.

  • Exploitation remains rare relative to disclosure: 0.23% of the vulnerabilities disclosed in 2026, roughly 1 in 431, were observed in active exploitation, while monthly disclosures more than doubled, from 5,045 in January to 10,740 in August.

  • Edge and security appliances accounted for 14% of the vulnerabilities exploited from January to August 2026, and over 65% of the exploited edge flaws carried a High or Critical GTIG risk rating.

Project Zero's tracker lists 24 zero-days patched between 13 January and 29 September 2026 (Stingrai count): 13 Microsoft, 7 Google, 2 Apple, 1 Qualcomm and 1 Adobe. That is its narrower scope again, so the comparable figure is the 43 zero-days in its 2025 tab, not GTIG's 90. Microsoft's own data, covered below, flags 19 CVEs as exploited across its January to September 2026 releases.

Is AI changing the zero-day numbers?

Not yet in the counts. GTIG states that "zero-day exploitation of AI infrastructure has not yet been observed," even as threat actors exploit newly disclosed flaws in exposed AI middleware, and it describes 2026's growth as driven by weaponized known vulnerabilities "rather than a flood of new zero-days." VulnCheck's July 2026 update found that only 14 of 1,061 vulnerabilities attributed to AI-assisted discovery, or 1.3%, had been confirmed as exploited in the wild, roughly matching the overall exploitation rate in the first half of 2026.

The risk profile is shifting, though. GTIG reports that half of the vulnerabilities it identified as AI-discovered lead to remote code execution, against 26% across the broader CVE ecosystem. One AI-discovered remote access flaw, CVE-2026-1731, was exploited by a threat cluster within four days of public disclosure and by five more clusters within seven days. GTIG also reported the first known case of a threat actor holding a zero-day exploit script developed with generative AI, intercepted before it was used. CISA's BOD 26-04 cites the same concern, warning that attackers' use of AI "may further narrow the time defenders have to react."

How many zero-days did Microsoft patch on Patch Tuesday?

Microsoft's Security Update Guide marks each CVE with two flags that map onto zero-day definitions: "Exploited," marked yes "when the vulnerability has been exploited before the release of the security update," and "Publicly Disclosed," marked yes when it was publicly disclosed before that release. Counting those flags across Microsoft's monthly release documents gives 25 CVEs flagged as exploited in 2025 and 19 from January to September 2026 (Stingrai count). A further 20 CVEs in 2025 were publicly disclosed but not exploited, so 45 carried at least one of the two flags; in 2026 the figure is 33, with 5 CVEs carrying both.

Monthly release

2025: flagged Exploited

2025: flagged Publicly Disclosed

2026: flagged Exploited

2026: flagged Publicly Disclosed

January

3

5

2

2

February

3

2

6

3

March

6

1

0

2

April

1

0

2

1

May

5

2

3

3

June

1

1

0

4

July

1

1

3

1

August

0

1

1

3

September

0

2

2

0

October

3

3

Not yet released

Not yet released

November

1

0

Not yet released

Not yet released

December

1

2

Not yet released

Not yet released

Total

25

20

19

19

Three details matter when comparing these counts with others. First, 23 of 2025's 25 exploited CVEs shipped on the Patch Tuesday date and 2 shipped out of band, including the July 2025 SharePoint fix (CVE-2025-53770); in 2026, 15 of 19 shipped on Patch Tuesday. Second, flags change: Microsoft corrected CVE-2026-58644's "Exploited flag" the day after the July 2026 release, so counts published on release day can differ from today's data. Third, this is Microsoft's own dataset, and 1 of its 25 exploited CVEs for 2025 was assigned by MITRE for a third-party component. GTIG also counts 25 Microsoft zero-days for 2025, but it does not publish its list, so the two cannot be matched CVE by CVE.

How many vulnerabilities did CISA add to the KEV catalog?

CISA added 245 vulnerabilities to its Known Exploited Vulnerabilities catalog in 2025 and 247 between 1 January and 1 October 2026, for a total of 1,731 entries in catalog version 2026.10.01 (Stingrai count on CISA's JSON feed). Through 30 September, 2026 additions stood at 246 against 183 at the same point in 2025, a 34% increase, and September 2026's 43 additions were the most in a single month since June 2022.

Year

KEV additions

Cumulative catalog total at year end

2021 (catalog launched 3 November)

311

311

2022

555

866

2023

187

1,053

2024

186

1,239

2025

245

1,484

2026 (1 January to 1 October)

247

1,731 (on 1 October)

Not every KEV addition is a zero-day. A vulnerability of any age may qualify for inclusion once it has an assigned CVE ID, "reliable evidence of active exploitation in the wild", clear remediation guidance and significant risk to federal systems, and CISA's guidance says an addition "does not necessarily indicate that CISA is currently observing active exploitation." In 2025, 151 of the 245 additions (61.6%) carried a CVE-2025 ID and 55 (22.4%) carried an ID from 2023 or earlier. In 2026, 166 of 247 (67.2%) carry a CVE-2026 ID and 44 (17.8%) an ID from 2024 or earlier. Of the 2025 additions, 31 are currently flagged as known to be used in ransomware campaigns, and 27 of the 2026 additions are.

Vendor

KEV additions in 2025

KEV additions in 2026 (to 1 October)

Microsoft

39

39

Cisco

8

18

Apple

9

9

Fortinet

8

8

Google

7

8

Linux

7

8

Ivanti

7

5

Citrix

5

5

Adobe

3

6

Oracle

5

4

SonicWall

5

4

Synacor (Zimbra)

4

5

D-Link

5

1

Note: the catalog lists Android as a separate vendor from Google, with 3 Android additions in 2025 and 1 in 2026 (Stingrai count).

CISA's catalog is the conservative end of the range. VulnCheck, which runs a broader catalog, identified 884 vulnerabilities with first-time exploitation evidence in 2025 across 518 vendors and 672 products, against CISA's 245 across 99 vendors and 146 products, and 495 more in the first half of 2026, according to its State of Exploitation 2026 and 1H 2026 reports. VulnCheck notes that its ratio of new known exploited vulnerabilities to new CVEs fell from a peak of 2.7% in the second half of 2023 to 1.4% in the first half of 2026, because CVE volume grew much faster than exploitation. For CVE volume and NVD backlog figures, see our companion vulnerability statistics for 2026.

Two-panel chart of cumulative CISA KEV additions by month for 2024 to 2026 and the remediation due dates set on new KEV entries from January 2025 to September 2026

Figure 2: Left, cumulative CISA KEV additions by month: 2026 reached 246 by 30 September against 245 for all of 2025. Right, the remediation due date CISA set on each new entry, by month added, January 2025 to September 2026; BOD 26-04 was issued on 10 June 2026. The June 2026 bar includes 10 entries added before the directive was issued. Source: CISA Known Exploited Vulnerabilities catalog, version 2026.10.01; Stingrai count.

How fast are vulnerabilities exploited after disclosure?

Mandiant's time-to-exploit metric, "the average time taken to exploit a vulnerability before or after a patch is released," has fallen in each of its public analyses. It averaged 63 days in 2018 to 2019, 44 days from 2020 to early 2021 and 32 days across 2021 and 2022, then 5 days in 2023, according to Mandiant's 2023 time-to-exploit analysis. M-Trends 2026 puts the 2025 mean at an estimated minus 7 days, "meaning exploitation is routinely occurring before a patch is even released." The full M-Trends 2026 report gives minus 1 day for 2024.

Period

Mandiant average time to exploit

2018 to 2019

63 days

2020 to early 2021

44 days

2021 to 2022

32 days

2023

5 days (47 days with 15 statistical outliers included)

2024

Minus 1 day

2025

Minus 7 days (estimated mean)

Bar chart of Mandiant's average time to exploit from 63 days in 2018 to 2019 to an estimated minus 7 days in 2025

Figure 3: Mandiant's average time to exploit by analysis period. The 2023 average excludes 15 outliers; with them it is 47 days. Sources: Mandiant, How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends, 15 October 2024; Mandiant, M-Trends 2026, 23 March 2026 (blog; full report p. 78 for 2024).

The 2023 analysis also explains part of the decline: zero-days, exploited before any patch existed, made up most of the sample. Of 138 vulnerabilities disclosed in 2023 and exploited, Mandiant counted 97 zero-days (70%) and 41 n-days (30%). Among the n-days, 12% were exploited within one day of a patch, 29% within a week and 56% within a month.

Other publishers measure narrower windows, and their numbers are not interchangeable with Mandiant's:

  • On or before CVE publication day: VulnCheck's January 2026 report found that 28.96% of the vulnerabilities it added to its catalog in 2025 showed exploitation on or before the day the CVE was published, up from 23.6% in its 2024 report. Its July 2026 update restated the 2025 share as 28.93% and measured 23.43% for the first half of 2026, while the median time from CVE publication to catalog entry fell from 120 days to 80 days. VulnCheck cautions that "Not all KEVs being exploited on the same day of CVE issuance are Zero Days."

  • After a public proof of concept: in the first half of 2026, 88% of the exploitation CrowdStrike observed against vulnerabilities with a proof of concept happened within 48 hours of its release, and China-nexus actors exploited critical vulnerabilities within 24 hours, according to the CrowdStrike 2026 Threat Hunting Report.

  • After disclosure, in Canada's assessment: the Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 says exploitation time "continues to decrease, with attacks starting within days after their disclosure."

How fast do organizations patch exploited vulnerabilities?

Slower than the deadlines now allow. Two kinds of number describe time to patch: the deadline a policy sets and the time organizations actually take.

The deadline: from 21 days to 3

BOD 26-04, issued on 10 June 2026, "supersedes and hereby revokes" BOD 22-01, the 2021 directive that created the KEV catalog, and BOD 19-02. BOD 22-01's default was two weeks for CVE IDs assigned from 2021 onward and six months for older ones, though in practice CISA gave 226 of the 245 entries it added in 2025 a 21-day due date. BOD 26-04 replaces that with a timeline driven by four questions: is the asset publicly exposed, is the vulnerability in the KEV catalog, can an adversary automate the exploit, and does exploitation give partial or total control. CISA had already moved from 21-day to 14-day KEV deadlines in March 2026, before BOD 26-04: the last 21-day entry was added on 5 March and the first 14-day entry of 2026 on 9 March.

Directive

Status

Remediation deadline for KEV vulnerabilities

BOD 22-01 (3 November 2021)

Revoked on 10 June 2026

Two weeks by default for CVE IDs from 2021 on, six months for older IDs

BOD 26-04 (10 June 2026)

In force; Table 1 timelines required within 180 days of issuance

3 or 14 days by exposure, exploit automation and technical impact, with forensic triage added to 3-day cases where an exploit gives total control

For vulnerabilities outside the catalog, BOD 26-04's Table 1 sets 3, 14 or 60 days, or a fix at the next system upgrade. CISA's guidance explains, for example, that the due date on a KEV entry reflects a 3-day deadline when it finds the vulnerability in a publicly exposed asset with total technical impact and automatable exploitation. The effect is visible in the catalog: of the 114 entries added between 10 June and 1 October 2026, 91 (79.8%) carry a 3-day due date and 23 carry 14 days, and the median due window on a 2026 addition is 3 days against 21 in 2025 (Stingrai count). Our analysis of what BOD 26-04 changes for remediation SLAs and retest windows covers the directive in depth. BOD 26-04 binds US federal civilian agencies, not private companies, but agencies must review their contracts for the changes it requires, and CISA's guidance says FedRAMP will require mandatory adoption of new vulnerability rules aligned with BOD 26-04 by 7 December 2026.

The reality: a 43-day median

The Verizon 2026 Data Breach Investigations Report tracked remediation of CISA KEV vulnerabilities across more than 13,000 organizations, counting any vulnerability found by scanners in an organization's environment that was in the catalog by the end of 2025.

KEV remediation measure, Verizon 2026 Data Breach Investigations Report

2025 data

2024 data

Fully remediated

26%

38%

Unremediated

16%

12%

Median days to full remediation

43

32

Median KEV vulnerabilities to patch per organization

16

11

Still open at day 28

35%

27%

Vulnerability instances remediated before entering the KEV catalog

12%

17%

The survival analysis in the Verizon 2026 Data Breach Investigations Report adds the number that matters most against a three-day deadline: "somewhere between 60% and 70% of KEV vulnerabilities remain open" at Day 7, "regardless of year, volume or organizational maturity." CISA's own Vulnerability Review, published on 26 August 2026, found critical infrastructure organizations patching KEVs faster in fiscal 2025 than in 2024 but concluded that "Most organizations continue to miss CISA's recommended remediation timelines."

The vendor side: fixes that miss the deadline

The TrendAI Zero Day Initiative (ZDI), a vendor-agnostic vulnerability disclosure program established in 2005, gives vendors 120 days to fix a reported vulnerability. When the deadline passes and the vendor is unresponsive or cannot explain why the flaw is unfixed, ZDI publishes "a limited advisory including mitigation"; it also publishes cases the vendor declines to fix. ZDI usually tells the vendor beforehand that it intends to "publish the case as a 0-day advisory", titled "(0Day)", and these advisories make the flaw public before a vendor fix is available. This is a disclosure measure, not evidence of exploitation in the wild.

ZDI published advisories

2025

2026 (1 January to 1 October)

Advisories published

1,202

751

Published as "(0Day)", with no vendor fix at publication

255

78

Share

21.2%

10.4%

Source: TrendAI Zero Day Initiative published advisories, 2025 and 2026 lists, read 1 October 2026; Stingrai count.

Why are edge devices a prime zero-day target?

Because several of the measurements above meet there: edge devices draw a large share of zero-days, they topped VulnCheck's 2025 list of exploited technologies, and they are hard to monitor. GTIG counted 21 security and networking zero-days in 2025 and 14 affecting edge devices, and noted that "the absence of EDR technology on most edge devices" can leave defenders blind. VulnCheck ranked network edge devices, including firewalls, VPNs and proxies, as the most frequently targeted technologies in its 2025 data, though its first-half 2026 report found content management systems the most targeted category, at one-third of new entries. Mandiant's M-Trends 2026 describes espionage clusters that "deliberately target edge and core network devices" lacking endpoint detection telemetry. In 2026, edge and security appliances accounted for 14% of the vulnerabilities GTIG saw exploited from January to August.

Many of those devices are past their support life. Of the 181 network edge vulnerabilities VulnCheck added to its catalog in 2025, 42.5% affected end-of-life or likely end-of-life devices and another 4.4% affected devices at end of sale, and only 43 (23.7%) also appeared in CISA's catalog, according to VulnCheck's network edge report. Thirty-five of the 181 were targeted by botnets, and 65% of botnet-exploited vulnerabilities affected end-of-life or likely end-of-life devices. CISA's BOD 26-02, issued on 5 February 2026, gives federal agencies three months to inventory listed end-of-support edge devices, 12 months to decommission them, 18 months to remove all end-of-support edge devices and 24 months to set up continuous discovery.

What does the Canadian Centre for Cyber Security report?

The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026, published in October 2024 and still the newest edition, says threat actors very likely target edge devices because "network defenses may have limited capability to monitor and detect malware activity on them." It records that in early 2024 Canada and its allies detected that a state-sponsored actor had stolen data by exploiting "2 newly discovered vulnerabilities in VPN devices" used by government and critical infrastructure networks.

The Cyber Centre co-authored the most recent edition of the Five Eyes 2023 Top Routinely Exploited Vulnerabilities advisory, released on 12 November 2024. It found that in 2023 "the majority of the most frequently exploited vulnerabilities were initially exploited as a zero-day," up from less than half in 2022, and that attackers "continue to have the most success exploiting vulnerabilities within two years after public disclosure." At least three of that year's top 15 were discovered when an end user or an EDR system reported suspicious activity.

The Cyber Centre's own alerts track the same pattern. It issued 21 alerts in 2025 (AL25-001 to AL25-021) and 24 in 2026 through 27 September (AL26-001 to AL26-024), by a Stingrai count of its alerts listing. Fortinet products appear in 3 of the 2025 alerts, Citrix NetScaler in 2, and Cisco and Microsoft SharePoint in 1 each; in the 2026 alerts so far, Citrix NetScaler, Microsoft SharePoint and Cisco products appear in 4 each and Fortinet in 2 (Stingrai count from alert titles). In AL26-005, on a SharePoint flaw, the Cyber Centre wrote that it "has observed exploitation of this vulnerability, and organizations are urged to take immediate action."

What this means for defenders

  • Report the four numbers separately. Track zero-day exposure (do you run the products and versions in Project Zero's 0day In the Wild tracker or among the CVEs Microsoft flags as exploited), KEV exposure (open catalog entries in your environment), time to exploit (plan around 48 hours from a public proof of concept, and assume exploitation can start before a patch exists), and time to patch (your median days to remediate KEV entries against the 3-day and 14-day BOD 26-04 clocks). A single blended "risk score" hides the gap between the last two.

  • Inventory and test the edge first. Security and networking devices drew 21 of 2025's zero-days, and 42.5% of the edge vulnerabilities VulnCheck catalogued in 2025 affected end-of-life or likely end-of-life devices. External network penetration testing finds the exposed management interfaces, forgotten appliances and unsupported devices that BOD 26-02 tells federal agencies to remove.

  • Plan for the zero-day you cannot patch. With a mean time to exploit of minus 7 days, plan as if an edge device could be exploited before a fix exists. Segment edge devices away from domain controllers, send their logs to a central system, and test whether your SOC sees post-exploitation activity; our red team detection benchmarks show what good looks like.

  • Prioritize by exposure and exploitation, not severity alone. BOD 26-04's four questions (exposure, KEV status, exploit automation and technical impact) work as well in a private-sector SLA as in a federal one, and they put an exposed, exploited, automatable flaw on a 3-day clock.

  • Verify the fix, then look for compromise. The Verizon 2026 Data Breach Investigations Report found between 60% and 70% of KEV vulnerabilities still open at Day 7, and BOD 26-04 adds a forensic triage requirement to its most urgent cases to establish whether the system was already compromised. Retest emergency patches and check the device for signs of earlier access, because a patch does not remove an attacker who got in first.

  • Test continuously as well as annually. CISA added 43 vulnerabilities to its catalog in September 2026 alone. An annual test shows where you stand; a continuous program catches the new exposure in between, as our comparison of continuous red teaming and the annual pentest explains.

How Stingrai tests the exposure behind these numbers

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

Zero-day exposure is an attack surface question first. A penetration test cannot patch a vendor's zero-day, but it can show which of your internet-facing systems an attacker reaches first, what an exploited edge device leads to inside your network, and whether your monitoring notices. Stingrai's external and internal network penetration testing covers the kinds of systems behind GTIG's 21 security and networking zero-days in 2025: VPN gateways, firewalls, remote access and file transfer appliances, and management interfaces that should never face the internet. Internal network and Active Directory testing starts from the position an attacker holds after an edge exploit and follows misconfigurations, ACL abuse, and Kerberos and delegation attack paths toward domain admin. Red teaming and purple teaming test whether your SOC detects post-exploitation activity on devices that run no EDR. Web application penetration testing covers the flaws in your own code that no vendor patch will fix, with authenticated testing across every user role for business logic, broken authorization and IDOR.

Each human-led engagement is run by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, whose research has produced 18 published CVEs, and Stingrai is rated 5.0 on Clutch from 20 reviews. Findings are posted to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, so remediation can start before the report is delivered. Retesting of remediated findings is included, human-led and hybrid engagements include an attestation letter, and the reports give you pentest evidence for SOC 2, ISO 27001, PCI DSS, HIPAA and CMMC programs. Engagements run as one-time annual tests or as continuous programs that test every release.

Network, Active Directory, cloud and red team scopes are quoted through the quote form. For a single web application and its APIs, published prices are US$3,000 per assessment or US$650 per month for the Autonomous Pentest by Snipe, Stingrai's AI agent for web applications and APIs, which carries the No High or Critical Finding = Don't Pay guarantee, and US$6,800 per assessment or US$1,275 per month for the Hybrid Pentest, in which Snipe and penetration testers test together; the monthly prices are for 12-month continuous plans (pricing).

Frequently Asked Questions

How many zero-day vulnerabilities were exploited in 2025?

Google Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in the wild in 2025, according to its 2025 Zero-Days in Review published on 5 March 2026. That is below the 2023 record of 100 and above 2024's 78, as counted in the same edition (the April 2025 edition had counted 98 and 75). Enterprise products accounted for 43 of the 90 (48%), an all-time high, and Microsoft led vendors with 25. Source: GTIG, 2025 Zero-Days in Review.

How many zero-days have been exploited in 2026 so far?

No publisher has released a full-year 2026 count. Google Threat Intelligence Group's 30 September 2026 analysis reports an average of 11 zero-days exploited a month from January to August 2026, up from 8 a month in 2025, with 22 in August alone, and zero-days made up 62% of the exploited vulnerabilities it observed in that window. Google Project Zero's narrower tracker lists 24 zero-days patched between 13 January and 29 September 2026 (Stingrai count). Source: GTIG, Vulnerability Discovery and Exploitation Trends in the AI Era.

Is every vulnerability in CISA's KEV catalog a zero-day?

No. CISA adds a vulnerability of any age once it has an assigned CVE ID, reliable evidence of active exploitation, clear remediation guidance and significant risk to US government systems, so the catalog mixes zero-days with n-days that were exploited after a fix existed. Of the 245 entries CISA added in 2025, 55 carried a CVE ID from 2023 or earlier. VulnCheck also cautions that "Not all KEVs being exploited on the same day of CVE issuance are Zero Days." Source: CISA Known Exploited Vulnerabilities catalog.

How many vulnerabilities did CISA add to the KEV catalog in 2025 and 2026?

CISA added 245 vulnerabilities to its Known Exploited Vulnerabilities catalog in 2025 and 247 between 1 January and 1 October 2026, bringing the catalog to 1,731 entries in version 2026.10.01, according to a Stingrai count on CISA's JSON feed. September 2026's 43 additions were the most in a single month since June 2022. Microsoft had the most additions in both years, with 39 each. Source: CISA Known Exploited Vulnerabilities catalog.

What is the average time to exploit a vulnerability in 2026?

No 2026 average has been published. Mandiant's M-Trends 2026 estimates the mean time to exploit at minus 7 days for 2025, meaning exploitation routinely began before a patch was released. Mandiant's series puts the average at 63 days in 2018 to 2019, 32 days in 2021 to 2022, 5 days in 2023 and minus 1 day in 2024. CrowdStrike measures a different window: in the first half of 2026, 88% of the exploitation CrowdStrike observed against vulnerabilities with a public proof of concept happened within 48 hours of its release. Source: Mandiant, M-Trends 2026.

How long do organizations take to patch known exploited vulnerabilities?

The Verizon 2026 Data Breach Investigations Report found a median of 43 days to fully remediate vulnerabilities in CISA's KEV catalog, up from 32 days a year earlier, across more than 13,000 organizations. Only 26% of KEV vulnerabilities were fully remediated, down from 38%, and between 60% and 70% were still open at Day 7. Source: Verizon 2026 Data Breach Investigations Report.

What is the KEV remediation deadline under BOD 26-04?

BOD 26-04, issued by CISA on 10 June 2026, revoked BOD 22-01 and sets 3-day or 14-day remediation deadlines for vulnerabilities in the KEV catalog, depending on whether the asset is publicly exposed, whether exploitation can be automated and whether it gives partial or total control, with forensic triage added to 3-day cases where an exploit gives total control. Of the 114 entries CISA added between 10 June and 1 October 2026, 91 carry a 3-day due date. The directive binds US federal civilian agencies. Source: CISA, BOD 26-04.

How many zero-days did Microsoft fix on Patch Tuesday in 2025 and 2026?

Microsoft's Security Update Guide data flags 25 CVEs released in 2025 as exploited before their fix, 23 of them on a Patch Tuesday date, plus 20 that were publicly disclosed but not exploited, for 45 CVEs carrying at least one of the two flags. Across its January to September 2026 releases, 19 CVEs are flagged as exploited, 15 of them on a Patch Tuesday date, and 33 carry at least one flag. These are Stingrai counts on Microsoft's monthly release data as of 1 October 2026; Microsoft can update a flag after release. Source: Microsoft Security Update Guide.

Who exploits zero-day vulnerabilities?

Of the 42 zero-days from 2025 that Google Threat Intelligence Group could attribute, commercial surveillance vendors and their customers accounted for 15, plus 3 likely, more than traditional state-sponsored espionage groups with 12, plus 3 likely, for the first time. Financially motivated groups used 9, two of them in operations that led to ransomware, and China-nexus espionage groups used at least 10. Source: GTIG, 2025 Zero-Days in Review.

References

  1. Google Threat Intelligence Group. Look What You Made Us Patch: 2025 Zero-Days in Review. 5 March 2026. https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review. Annual count of zero-days exploited in the wild in 2025, by product category, vendor and attributed actor.

  2. Google Threat Intelligence Group. Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis. 29 April 2025. https://cloud.google.com/blog/topics/threat-intelligence/2024-zero-day-trends. Prior edition, used here only to label restated 2019, 2021, 2023 and 2024 counts.

  3. Google Threat Intelligence Group. Vulnerability Discovery and Exploitation Trends in the AI Era. 30 September 2026. https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era. Monthly zero-day and n-day exploitation for vulnerabilities disclosed from January 2025 to August 2026.

  4. Google Project Zero. 0day "In the Wild" tracker. Read 1 October 2026. https://googleprojectzero.blogspot.com/p/0day.html. Public spreadsheet of detected in-the-wild zero-days since July 2014, by year.

  5. Cybersecurity and Infrastructure Security Agency. Known Exploited Vulnerabilities Catalog (catalog version 2026.10.01). 1 October 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog. Every KEV entry with its date added, due date, vendor and ransomware flag.

  6. Cybersecurity and Infrastructure Security Agency. BOD 26-04: Prioritizing Security Updates Based on Risk. 10 June 2026. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk. Directive that revoked BOD 22-01 and BOD 19-02 and set risk-based remediation timelines.

  7. Cybersecurity and Infrastructure Security Agency. BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk. 10 June 2026, updated 25 August 2026. https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk. KEV inclusion criteria, due-date calculation and forensic triage steps.

  8. Cybersecurity and Infrastructure Security Agency. BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities (revoked). 3 November 2021. https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01. The directive that created the KEV catalog and its original default deadlines.

  9. Cybersecurity and Infrastructure Security Agency. BOD 26-02: Mitigating Risk From End-of-Support Edge Devices. 5 February 2026. https://www.cisa.gov/news-events/directives/bod-26-02-mitigating-risk-end-support-edge-devices. Inventory and decommissioning timelines for unsupported edge devices.

  10. Cybersecurity and Infrastructure Security Agency. CISA Vulnerability Review: Fiscal Years 2024 and 2025. 26 August 2026. https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review. Baseline of exploited vulnerabilities, root causes and KEV remediation across critical infrastructure.

  11. Mandiant (Google Cloud). M-Trends 2026: Data, Insights, and Strategies From the Frontlines. 23 March 2026. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026. Incident response metrics for 2025, including the estimated mean time to exploit.

  12. Mandiant (Google Cloud). M-Trends 2026 Executive Edition. March 2026. https://services.google.com/fh/files/misc/m-trends-2026-executive-edition-en.pdf. Data window and summary metrics for investigations from 1 January to 31 December 2025.

  13. Mandiant (Google Cloud). Special Report: M-Trends 2026 (full report). March 2026. https://www.gstatic.com/security-marketing/m-trends-2026-en.pdf. Time-to-exploit series, including minus 1 day in 2024 (p. 78).

  14. Mandiant (Google Cloud). How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends. 15 October 2024. https://cloud.google.com/blog/topics/threat-intelligence/time-to-exploit-trends-2023. Time-to-exploit series from 2018 to 2023 and the 2023 zero-day and n-day split.

  15. VulnCheck. VulnCheck State of Exploitation 2026. 21 January 2026. https://www.vulncheck.com/blog/state-of-exploitation-2026. First-time exploitation evidence for 884 vulnerabilities in 2025 and its timing against CVE publication.

  16. VulnCheck. VulnCheck State of Exploitation 1H-2026. 28 July 2026. https://www.vulncheck.com/blog/state-of-exploitation-1h-2026. Exploitation timing, volume and AI-assisted discovery for the first half of 2026.

  17. VulnCheck. 2026 State of Exploitation: Exploiting The Network Edge. 23 March 2026. https://www.vulncheck.com/blog/network-edge-device-report-2026; full report: https://wwv.vulncheck.com/hubfs/Research/Exploring-Network-Edge-Devices-VulnCheck-State-of-Exploitation-2026.pdf. End-of-life status and CISA KEV coverage of 181 exploited network edge vulnerabilities from 2025.

  18. Verizon. 2026 Data Breach Investigations Report. 19 May 2026. https://www.verizon.com/dbir. Breach patterns from more than 22,000 confirmed breaches and KEV remediation data from more than 13,000 organizations.

  19. Microsoft Security Response Center. Security Update Guide and monthly release data (CVRF API). Read 1 October 2026. https://msrc.microsoft.com/update-guide. Exploited and Publicly Disclosed flags for each CVE in Microsoft's monthly releases.

  20. Microsoft Security Response Center. Security Update Guide FAQs. Read 1 October 2026. https://www.microsoft.com/en-us/msrc/faqs-security-update-guide. Definitions of the Exploited and Publicly Disclosed flags.

  21. TrendAI Zero Day Initiative. Published Advisories (2025 and 2026). Read 1 October 2026. https://www.zerodayinitiative.com/advisories/published/2025/; https://www.zerodayinitiative.com/advisories/published/. Every ZDI advisory with its publication date, including those published as 0-days.

  22. TrendAI Zero Day Initiative. Disclosure Policy. Read 1 October 2026. https://www.zerodayinitiative.com/advisories/disclosure_policy/. The 120-day vendor deadline and the tiered timeline for faulty patches.

  23. CrowdStrike. CrowdStrike 2026 Threat Hunting Report (press release). 3 August 2026. https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-threat-hunting-report/. Exploitation timing after proof-of-concept release in the first half of 2026.

  24. Canadian Centre for Cyber Security. National Cyber Threat Assessment 2025-2026. October 2024. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026. Canada's assessment of threat trends, including edge device targeting and exploitation timelines.

  25. Canadian Centre for Cyber Security. Joint advisory on the 2023 top routinely exploited vulnerabilities. November 2024. https://www.cyber.gc.ca/en/joint-advisory-2023-top-routinely-exploited-vulnerabilities. Five Eyes advisory on the most exploited vulnerabilities of 2023 and their zero-day origins.

  26. Cybersecurity and Infrastructure Security Agency and partners. 2023 Top Routinely Exploited Vulnerabilities (AA24-317A). 12 November 2024. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a. Full text of the joint advisory, including the top 15 list.

  27. Canadian Centre for Cyber Security. Alerts and advisories. Read 1 October 2026. https://www.cyber.gc.ca/en/alerts-advisories. The Cyber Centre's numbered alerts, used for the 2025 and 2026 alert counts.

0 views

0

X

Related reading

Password Statistics 2026: Breaches, Credential Stuffing, and Passkey Adoption
Network SecurityWeb App Security

Password Statistics 2026: Breaches, Credential Stuffing, and Passkey Adoption

6B malware-stolen passwords surfaced in 2025 (Specops) and 22% of breaches start with stolen credentials (Verizon). Every 2026 password statistic is sourced.

25 min read

Malware Attack Statistics 2026: The Verified Numbers
Network SecurityWeb App Security

Malware Attack Statistics 2026: The Verified Numbers

Malware library hit 1.56B samples (AV-TEST). 79% of intrusions are now malware-free (CrowdStrike). All 2026 malware statistics with named primary sources.

24 min read

Top Industries Targeted by Hackers 2026: Manufacturing, Healthcare, and Finance
Network SecurityWeb App Security

Top Industries Targeted by Hackers 2026: Manufacturing, Healthcare, and Finance

Manufacturing held #1 for the 4th year (IBM X-Force, 26%). Healthcare leads breach cost at US$7.42M (IBM 2025). Verified industry-targeting stats.

26 min read

Contents

X