The KEV catalog is the closest thing to a public record of which vulnerabilities are actually being used against people, as opposed to which ones score highly in the abstract. Its cadence is therefore a rough proxy for the tempo of exploitation that reaches US federal visibility.
Two caveats belong on the face of it. The catalog reflects what CISA can confirm and choose to publish, so it undercounts. And its rate is partly an artefact of CISA's own capacity and process changes, not only of attacker behaviour.
The current month is always partial and is marked as such.