Microsoft dominates CISA's exploited-vulnerability catalog (22.8% of all entries); the "big vendors are slower to be flagged" pattern is a KEV-launch artifact, not an ongoing trend
CISA KEV catalog x NVD CVE publication dates, checked 2026-09-11
Summary
Microsoft has by far the most actively-exploited vulnerabilities: 388 of the 1,703 entries in CISA's Known Exploited Vulnerabilities (KEV) catalog belong to it, 22.8% of the whole catalog and more than the next four vendors (Cisco, Apple, Adobe, Google) combined. The top 5 vendors account for 43% of all known-exploited CVEs. On the second question, the naive answer is yes — averaged over KEV's full history, CVEs from large vendors take about 1,127 days to be flagged as exploited versus 602 days for smaller vendors (p<0.0001). But that gap is a data artifact of how KEV was built, not an ongoing pattern: CISA launched the catalog in November 2021 by bulk-adding a backlog of old CVEs, disproportionately from long-established, large vendors. Restricting to CVEs published since 2022 (after that backlog effect fades) reverses the picture: large vendors are flagged in a median of 1 day versus 10 days for others, and the mean difference (60 vs 100 days) is no longer statistically significant (p=0.06). If anything, big vendors get flagged faster in recent years, not slower.
Which vendors have the most actively-exploited vulnerabilities
Ranked by count of CVEs in CISA's KEV catalog (1,703 entries across 283 vendors, current snapshot):
| Microsoft | 388 | 22.8% | 117 |
| Cisco | 97 | 5.7% | 6 |
| Apple | 94 | 5.5% | 0 |
| Adobe | 81 | 4.8% | 11 |
| 74 | 4.3% | 0 | |
| Oracle | 46 | 2.7% | 13 |
| Apache | 40 | 2.3% | 8 |
| Ivanti | 35 | 2.1% | 12 |
| Fortinet | 30 | 1.8% | 14 |
| Linux | 28 | 1.6% | 2 |
| Adobe | 81 | 4.8% | 11 |
| Apache | 40 | 2.3% | 8 |
| Apple | 94 | 5.5% | 0 |
| Cisco | 97 | 5.7% | 6 |
| Fortinet | 30 | 1.8% | 14 |
| 74 | 4.3% | 0 | |
| Ivanti | 35 | 2.1% | 12 |
| Linux | 28 | 1.6% | 2 |
| Microsoft | 388 | 22.8% | 117 |
| Oracle | 46 | 2.7% | 13 |
| Microsoft | 388 | 22.8% | 117 |
| Cisco | 97 | 5.7% | 6 |
| Apple | 94 | 5.5% | 0 |
| Adobe | 81 | 4.8% | 11 |
| 74 | 4.3% | 0 | |
| Oracle | 46 | 2.7% | 13 |
| Apache | 40 | 2.3% | 8 |
| Ivanti | 35 | 2.1% | 12 |
| Fortinet | 30 | 1.8% | 14 |
| Linux | 28 | 1.6% | 2 |
| Microsoft | 388 | 22.8% | 117 |
| Cisco | 97 | 5.7% | 6 |
| Apple | 94 | 5.5% | 0 |
| Adobe | 81 | 4.8% | 11 |
| 74 | 4.3% | 0 | |
| Oracle | 46 | 2.7% | 13 |
| Apache | 40 | 2.3% | 8 |
| Ivanti | 35 | 2.1% | 12 |
| Fortinet | 30 | 1.8% | 14 |
| Linux | 28 | 1.6% | 2 |
| Microsoft | 388 | 22.8% | 117 |
| Fortinet | 30 | 1.8% | 14 |
| Oracle | 46 | 2.7% | 13 |
| Ivanti | 35 | 2.1% | 12 |
| Adobe | 81 | 4.8% | 11 |
| Apache | 40 | 2.3% | 8 |
| Cisco | 97 | 5.7% | 6 |
| Linux | 28 | 1.6% | 2 |
| Apple | 94 | 5.5% | 0 |
| 74 | 4.3% | 0 |
Microsoft's dominance largely reflects surface area — it ships the operating system, browser, and productivity/server software on the largest installed base of any vendor, so it is both the biggest target and the biggest source of raw CVE volume. Notably, ransomware-linked exploitation is concentrated in a different set: Fortinet, SonicWall, Oracle, and Ivanti have a higher share of their own KEV entries tied to known ransomware campaigns than Microsoft does, even though Microsoft's absolute ransomware-linked count (117) is highest.
Independent confirmation: a September 2026 CISA-catalog analysis (Cyble/SecurityWeek, reporting on the 2025 KEV additions specifically) found the same ranking order — Microsoft first (with roughly 24% of the catalog at that snapshot), then Apple, Cisco, Adobe, Google — and the same finding that Microsoft leads ransomware-linked KEV entries. The count totals differ slightly from this analysis (their snapshot: 1,484 catalog entries; this analysis: 1,703) because the KEV catalog keeps growing and the two were pulled on different dates, but the ranking and proportions are consistent.
Are big vendors slower to be flagged as exploited? — the full-history number is misleading
Method: for every CVE in KEV with a match in NVD's vulnerability table, this analysis computed the gap in days between the CVE's original NVD publication date and the date CISA added it to KEV. Both timing queries below apply the filter v.published IS NOT NULL AND k.date_added IS NOT NULL: of the 1,161 total KEV entries for the 25-vendor comparison set, 24 rows (2%) were excluded because they lacked a matching NVD publication date or a KEV date_added value, leaving 1,137 CVE-KEV pairs in the full-history comparison and 483 pairs in the since-2022 comparison (a further subset of those 1,137, restricted by publication date). This exclusion removes a small, essentially random sliver of the data (missing dates, not a systematic vendor bias) and does not change the direction or size of either result in a way that would alter the conclusion.
"Big vendor" is operationalized here as a set of ten large-cap, broadly recognized technology firms — Microsoft, Apple, Google, Oracle, Cisco, Adobe, SAP, Samsung, Qualcomm, VMware — compared against a set of 15 smaller/more specialized vendors also common in KEV (Apache, Ivanti, Fortinet, Linux, D-Link, Citrix, Synacor, SonicWall, Android, Palo Alto Networks, Atlassian, Mozilla, Zyxel, Trend Micro, SolarWinds). This is a size/prominence proxy, not an official classification, and a reader could reasonably draw the line differently.
Over KEV's entire history (1,137 matched CVE-KEV pairs across these 25 vendors), big vendors show a much longer average and median time-to-flag: mean 1,127 days (median 431) versus 602 days (median 159) for the smaller set. A Welch's t-test on this split is highly significant (t=-7.04, p<0.0001, n=1,137).
That looks like a clean answer, but it is confounded by a known artifact: CISA launched KEV in November 2021 and, at launch, bulk-added a backlog of vulnerabilities that had already been under active exploitation for years — some CVEs from as far back as the 1990s-2000s. Legacy enterprise vendors with decades of software still in production (Microsoft, Cisco, Oracle) are disproportionately represented in that backlog, which mechanically inflates their "time to flag" even though CISA didn't actually take years to notice — the catalog itself didn't exist yet.
Restricting to CVEs published in 2022 or later (i.e., after CVEs could plausibly have been added to KEV promptly, removing the launch-backlog effect) reverses the finding: big vendors' median time-to-flag is 1 day versus 10 days for the smaller vendor set (n=483: 311 big, 172 other), and the mean gap (60 vs 100 days) is not statistically significant (Welch's t=1.87, p=0.062). If anything the point estimate now favors big vendors being flagged faster, plausibly because Microsoft, Google, and Apple run bug-bounty and telemetry programs (and disclose actively-exploited zero-days in their own advisories) that feed CISA a signal almost immediately, while a niche vendor's exploitation may take longer to surface through security-researcher or law-enforcement channels.
Independent literature corroborates the general order of magnitude: outside research (Barracuda, cited via web search) finds a catalog-wide median of about 9 days from CVE publication to KEV addition for vulnerabilities published since 2022 — consistent with this analysis's post-2022 medians of 1 and 10 days for the two vendor groups, and far below the multi-hundred-day full-history figures that are driven by the 2021 launch backlog.
Bottom line on the second question: no, big vendors are not durably slower to be flagged once the KEV-launch artifact is removed — the honest answer is "not significantly different, with a slight edge toward big vendors being faster," not the seemingly definitive "yes, much slower" that the naive full-history comparison implies.
Every query behind this report
12 warehouse calls ran in this session, in order. Each is reproducible against the same snapshot.
query — 25 rows — 2432 ms
SELECT vendor_project, COUNT(*) AS n_kev, SUM(CASE WHEN known_ransomware_use='Known' THEN 1 ELSE 0 END) AS n_ransomware
FROM cyber_vuln.kev_catalog
GROUP BY vendor_project
ORDER BY n_kev DESC
FETCH FIRST 25 ROWS ONLYquery — 1 rows — 1015 ms
SELECT COUNT(*) AS total_kev, COUNT(DISTINCT vendor_project) AS n_vendors FROM cyber_vuln.kev_catalogquery — 1649 rows — 48411 ms
SELECT k.vendor_project, k.cve_id, v.published, k.date_added
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULLquery — 25 rows — 84742 ms
SELECT k.vendor_project,
COUNT(*) AS n,
AVG(CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT)) AS avg_days_to_flag,
median(CAST(CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT) AS DOUBLE)) AS median_days
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULL
AND k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')
GROUP BY k.vendor_project
ORDER BY n DESCquery — 1137 rows — 83400 ms
SELECT k.vendor_project,
CASE WHEN k.vendor_project IN ('Microsoft','Apple','Google','Oracle','Cisco','Adobe','SAP','Samsung','Qualcomm','IBM','Broadcom','VMware') THEN 1 ELSE 0 END AS is_big_vendor,
CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT) AS days_to_flag
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULL
AND k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')hypothesis_test — 87156 ms
SELECT
CASE WHEN k.vendor_project IN ('Microsoft','Apple','Google','Oracle','Cisco','Adobe','SAP','Samsung','Qualcomm','VMware') THEN 'big' ELSE 'other' END AS vendor_size,
CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT) AS days_to_flag
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULL
AND k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')query — 2 rows — 83878 ms
WITH pairs AS (
SELECT
CASE WHEN k.vendor_project IN ('Microsoft','Apple','Google','Oracle','Cisco','Adobe','SAP','Samsung','Qualcomm','VMware') THEN 'big' ELSE 'other' END AS vendor_size,
CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT) AS days_to_flag
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULL
AND k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')
)
SELECT vendor_size, COUNT(*) AS n, AVG(CAST(days_to_flag AS DOUBLE)) AS avg_days, median(CAST(days_to_flag AS DOUBLE)) AS median_days
FROM pairs GROUP BY vendor_sizequery — 1 rows — 1275 ms
SELECT COUNT(*) AS total_kev_25vendors
FROM cyber_vuln.kev_catalog k
WHERE k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')query — 2 rows — 86666 ms
WITH pairs AS (
SELECT
CASE WHEN k.vendor_project IN ('Microsoft','Apple','Google','Oracle','Cisco','Adobe','SAP','Samsung','Qualcomm','VMware') THEN 'big' ELSE 'other' END AS vendor_size,
CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT) AS days_to_flag
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULL
AND CAST(SUBSTRING(v.published,1,10) AS DATE) >= DATE '2022-01-01'
AND k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')
)
SELECT vendor_size, COUNT(*) AS n, AVG(CAST(days_to_flag AS DOUBLE)) AS avg_days, median(CAST(days_to_flag AS DOUBLE)) AS median_days
FROM pairs GROUP BY vendor_sizehypothesis_test — 87952 ms
SELECT
CASE WHEN k.vendor_project IN ('Microsoft','Apple','Google','Oracle','Cisco','Adobe','SAP','Samsung','Qualcomm','VMware') THEN 'big' ELSE 'other' END AS vendor_size,
CAST((CAST(k.date_added AS DATE) - CAST(SUBSTRING(v.published,1,10) AS DATE)) DAY AS BIGINT) AS days_to_flag
FROM cyber_vuln.kev_catalog k
JOIN cyber_vuln.vulnerabilities v ON k.cve_id = v.cve_id
WHERE v.published IS NOT NULL AND k.date_added IS NOT NULL
AND CAST(SUBSTRING(v.published,1,10) AS DATE) >= DATE '2022-01-01'
AND k.vendor_project IN ('Microsoft','Cisco','Apple','Adobe','Google','Oracle','Apache','Ivanti','Fortinet','Linux','VMware','D-Link','Citrix','Synacor','SonicWall','Android','Samsung','Palo Alto Networks','SAP','Atlassian','Mozilla','Zyxel','Trend Micro','Qualcomm','SolarWinds')query — 60 rows — 1039 ms
SELECT vendor_project, COUNT(*) AS n FROM cyber_vuln.kev_catalog GROUP BY vendor_project ORDER BY n DESC FETCH FIRST 60 ROWS ONLYsubgroup_contribution — 1297 ms
SELECT vendor_project, COUNT(*) AS n FROM cyber_vuln.kev_catalog GROUP BY vendor_projectSources
- CISA KEV catalog — Loaded into cyber_vuln.kev_catalog
- NVD CVE 2.0 records — Loaded into cyber_vuln.vulnerabilities, joined on cve_id
- Vendor KEV-count ranking (top 10)
Show SQL
SELECT vendor_project, COUNT(*) AS n_kev FROM cyber_vuln.kev_catalog GROUP BY vendor_project ORDER BY n_kev DESC FETCH FIRST 10 ROWS ONLY - Full-history time-to-flag, big vs other vendors (Welch t-test)
Show tool call
hypothesis_test(test="t_test", group_col="vendor_size", value_col="days_to_flag") - Since-2022 time-to-flag, big vs other vendors (Welch t-test)
Show tool call
hypothesis_test(test="t_test", group_col="vendor_size", value_col="days_to_flag") - Microsoft's 22.8% share of the KEV catalog
Show tool call
subgroup_contribution(value_col="n", group_col="vendor_project") - 2025 CISA KEV catalog vendor analysis (Cyble) — Independent confirmation of vendor ranking and ransomware-linked leadership
- The KEV gap: how fast do exploited bugs get flagged? (Barracuda) — Independent ~9-day median CVE-publication-to-KEV figure for post-2022 CVEs