{"as_of":"2026-09-12T13:32:20.234Z","catalog_version":"2026.09.11","catalog_size":1709,"window_days":90,"added_in_window":90,"ransomware_linked_total":360,"ransomware_share_pct":21.1,"past_due_total":1692,"top_vendors_all_time":[{"key":"Microsoft","count":388},{"key":"Cisco","count":97},{"key":"Apple","count":94},{"key":"Adobe","count":81},{"key":"Google","count":74},{"key":"Oracle","count":46},{"key":"Apache","count":40},{"key":"Ivanti","count":35},{"key":"Fortinet","count":30},{"key":"Linux","count":28}],"top_vendors_in_window":[{"key":"Microsoft","count":11},{"key":"Cisco","count":6},{"key":"JFrog","count":4},{"key":"Fortinet","count":4},{"key":"SonicWall","count":4},{"key":"N-able","count":3},{"key":"Ubiquiti","count":3},{"key":"MikroTik","count":2},{"key":"Citrix","count":2},{"key":"Google","count":2}],"additions_by_month":[{"key":"2024-10","count":17},{"key":"2024-11","count":22},{"key":"2024-12","count":16},{"key":"2025-01","count":14},{"key":"2025-02","count":27},{"key":"2025-03","count":32},{"key":"2025-04","count":15},{"key":"2025-05","count":24},{"key":"2025-06","count":20},{"key":"2025-07","count":20},{"key":"2025-08","count":15},{"key":"2025-09","count":16},{"key":"2025-10","count":31},{"key":"2025-11","count":11},{"key":"2025-12","count":20},{"key":"2026-01","count":17},{"key":"2026-02","count":28},{"key":"2026-03","count":26},{"key":"2026-04","count":31},{"key":"2026-05","count":21},{"key":"2026-06","count":23},{"key":"2026-07","count":26},{"key":"2026-08","count":31},{"key":"2026-09","count":22}],"top_cwes":[{"key":"CWE-20","count":118},{"key":"CWE-78","count":110},{"key":"CWE-787","count":103},{"key":"CWE-416","count":93},{"key":"CWE-119","count":85},{"key":"CWE-22","count":78},{"key":"CWE-502","count":71},{"key":"CWE-94","count":70},{"key":"CWE-287","count":47},{"key":"CWE-306","count":42}],"note":"Counts are AnswerPool aggregates over the CISA catalog: which vendors' products are most often found exploited, how additions are trending, and how much of the catalog is ransomware-linked. Counts reflect what CISA has catalogued, which is a floor on real exploitation, not a census.","source":"CISA Known Exploited Vulnerabilities catalog","disclaimer":"Source data from CISA (US federal public domain), retrieved at as_of; groupings and day-counts are computed by AnswerPool. CVE description text is authored by the MITRE CVE Program and is deliberately not redistributed here — follow cve_url for it. Not security advice; KEV inclusion means known exploitation, not that you are exposed."}