Skip to content

Velinor AI Ltd · Company 15700539 · Reviewed October 2026

← Field notesOne number · 3 Oct 2026

283 vendors appear in the KEV catalogue. 77% of entries are not Microsoft.

CISA's Known Exploited Vulnerabilities catalogue lists 1,721 vulnerabilities across 283 vendors and 725 products.

Microsoft has the most, 388 entries. That is 23%. The other 77% is spread across 282 vendors, and 146 of them appear exactly once.

This year alone 93 different vendors have had at least one entry added.

What that means in practice. A vulnerability programme organised around the monthly Microsoft cycle is covering less than a quarter of the list. The rest arrives from vendors you may run in one corner of the estate, on no fixed schedule.

The reliable defence is knowing what you run. A software inventory with vendor and version, matched against the catalogue every day, turns a list of 283 names into the handful that apply to you.

Source: CISA Known Exploited Vulnerabilities catalogue v2026.09.23, distinct vendorProject and product values, computed 24 Sep 2026.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes