← Field notesOne number · 19 Sep 2026

56% of known-exploited CVEs were already old when they were added.

964 of the 1,711 vulnerabilities in CISA's Known Exploited Vulnerabilities catalogue were added in a later year than the year in their CVE number. That is 56%.

369 of them were five years old or more when they were added.

This year alone CISA has added 227 entries. 79 of those carry a CVE number from before 2026. Seven are from 2008 and 2009.

The lesson is not patch faster. It is that a vulnerability does not stop mattering because it is old, and a scanner that only shows you this quarter's CVEs is showing you the wrong list.

Two checks.

  1. Does your scanner report against the full CVE history, or a recent window?
  2. Does your register carry the KEV flag as its own field, so an old finding can jump the queue on the day it is added?

Source: CISA Known Exploited Vulnerabilities catalogue v2026.09.16, year of CVE identifier compared with dateAdded, computed 16 Sep 2026. KEV lists vulnerabilities with confirmed evidence of exploitation. It is not every vulnerability that has ever been exploited.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes