Network: Wedgetail Astrostrategy Cyberstrategy Geofinance Geopolitics Geostrategy Global Energy
The gap between a CVE being published and being known-exploited

How long vulnerabilities take to reach the KEV catalog after publication — a distribution, not an average.

0100200300days0–282846–1,1281,692–1,9742,538–2,8203,384–3,6664,230–4,5125,076–5,3585,922–6,204

Source: CISA / NVD · retrieved 17 Sep 2026 · Public domain (US Government)

Download CSV · Embed this chart

An average would hide the story here. The distribution is heavily bimodal: a cluster of vulnerabilities that reach KEV within days of publication, and a long tail of much older CVEs that are added years later because someone finally found them being exploited.

Those two populations mean different things. The fast cluster is exploitation racing disclosure. The long tail is mostly discovery lag on our side, not attacker behaviour — a vulnerability added seven years after publication was very likely exploited long before it was listed.

Where the NVD fetcher has run, publication dates come from NVD; otherwise the CVE year is used, which is coarser but never wrong in the direction that would flatter the chart.

The data behind this chart

Days from CVE publication to KEV listing — Derived from the KEV catalog and NVD publication dates.

Source: CISA / NVD · retrieved 17 Sep 2026 · Public domain (US Government)

Dataset CSV · Dataset JSON · This chart's data

Embed this chart

Free to embed with attribution. Every embed stays live as the data updates.


Related from the Network

How the KEV catalog works
On Cyberstrategy