Skip to main content
HomeTopicsKEVs

KEVs

Cybersecurity statistics about kevs

Showing 1-12 of 12 results

26.9% of KEVs first seen in 1H-2025 were still awaiting analysis by NIST.

VulnCheck7/30/2025
Vulnerabilities

The top five categories for KEVs in 1H-2025 are: Content Management Systems (CMS): 86 KEVs, with a significant volume attributed to WordPress Plug-ins; Network Edge Devices: 77 KEVs; Server Software: 61 KEVs; Open Source Software: 55 KEVs; and Operating Systems: 38 KEVs.

VulnCheck7/30/2025
Vulnerabilities

Vendors with Highest Number of KEVs in 1H-2025: Microsoft: 32 KEVs, with 26 of these being for Windows; Cisco: 10 KEVs; Apple OS: 6 KEVs; Totolink Networking Devices: 6 KEVs; and VMware: 6 KEVs.

VulnCheck7/30/2025
Vulnerabilities

In 2H-2024, 44 KEVs were attributed to the North Korean cyber group Silent Chollima.

VulnCheck7/30/2025
Vulnerabilities

Reports of KEVs associated with China and North Korea decreased in 1H-2025, while reports associated with Russia and Iran increased.

VulnCheck7/30/2025
Vulnerabilities

In 1H-2025, 29 KEVs were attributed to Iranian threat actors.

VulnCheck7/30/2025
Vulnerabilities

4.4% of KEVs are in a deferred status by NIST, meaning they are no longer maintained or updated

VulnCheck7/30/2025
Vulnerabilities

32.1% of vulnerabilities (Known Exploited Vulnerabilities - KEVs) had exploitation evidence on or before the day of their CVE disclosure, often indicating zero-day exploitation. This marks an 8.5% increase in the percentage of KEVs exploited on or before disclosure compared to 23.6% in 2024.

VulnCheck7/30/2025
VulnerabilitiesCVEs

In 2H-2024, 66 KEVs were attributed to the Chinese threat actor Flax Typhoon (AKA Ethereal Panda).

VulnCheck7/30/2025
Vulnerabilities

75% of organisations have BMS affected by known exploited vulnerabilities (KEVs).

Claroty6/25/2025
Critical industriesBuilding management systems

Within organisations affected by KEVS that are also linked to ransomware and are insecurely connected to the internet, 2% of devices contain the same high level of risk, meaning they are essential to business operations and are operating at the highest level of risk exposure

Claroty6/25/2025
Critical industriesBuilding management systems

Of the organisations affected by KEVs, 51% are affected by KEVs that are also linked to ransomware and are insecurely connected to the internet.

Claroty6/25/2025
Critical industriesBuilding management systems