Cybersecurity statistics,
with the sources attached

Every number on this page is computed directly from the organisation that published it, at the moment this page was built. No vendor surveys, no recycled figures, no statistic whose origin nobody can find.

Last rebuilt August 10, 2026  ·  sources CISA and NIST

1,662
vulnerabilities CISA has confirmed are being exploited
Catalogue version 2026.08.10, the full cumulative list since 2021.
20.4%
of those are linked to a known ransomware campaign
339 of 1,662 entries carry a confirmed ransomware association.
10,220
new vulnerabilities published in the last 30 days
About 341 every day, including weekends.
25
of those reached CISA’s exploited list in the same period
The gap between what exists and what is actually being used against you.
0.36%
of 2026 vulnerabilities are known to be exploited
178 KEV additions against 49,769 CVEs published year to date.
23.0%
of the exploited catalogue is Microsoft alone
382 of 1,662 entries. Concentration, not coincidence.

What the numbers actually say

Short enough to quote, sourced enough to defend.

Exploited vulnerabilities added per year

CISA Known Exploited Vulnerabilities catalogue, by the year each entry was added.

YearAdded
2021311
2022555
2023187
2024186
2025245
2026178

Where exploited vulnerabilities concentrate

Top vendors by number of entries in the exploited catalogue.

VendorEntriesShare
Microsoft38223.0%
Cisco955.7%
Apple935.6%
Adobe804.8%
Google724.3%
Oracle452.7%
Apache402.4%
Ivanti352.1%

Method

Sources. The CISA Known Exploited Vulnerabilities catalogue, catalogue version 2026.08.10, and the NIST National Vulnerability Database via CVE API 2.0. Both are the originating authority for their figures.

Freshness. This page is rebuilt from the live sources. If a source cannot be reached, the build fails and the page is left alone rather than republished with an updated date and unchanged numbers.

One caveat, stated plainly. The KEV catalogue is cumulative since 2021. NVD counts are period-bound. Where the two are compared, the comparison is restricted to the same calendar year and labelled as such. Most published vulnerability statistics quietly mix the two and produce a number that means nothing.

Reuse. Cite it, quote it, screenshot it. A link back to marklynd.com/stats is appreciated.