← Field notesOne number · 27 Sep 2026

One in five known-exploited vulnerabilities has fed ransomware.

361 of the 1,721 entries in CISA's Known Exploited Vulnerabilities catalogue are marked as known to have been used in ransomware campaigns. That is 21%, roughly one in five.

The flag is worth understanding before you use it.

  1. Known means CISA has evidence the vulnerability was used by a ransomware operation.
  2. Unknown does not mean no. It means CISA cannot confirm it either way, and the field can change after an entry is added. 27 of this year's 237 additions are marked Known so far.
  3. It is a field in a free, public file. You do not need a subscription to read it.

How to use it. If a finding in your estate is on the KEV list and carries the ransomware flag, it belongs at the very top of the queue. The decision to leave it open should be seen by whoever owns the business risk, not only whoever owns the server. Ransomware is a business continuity event, so leaving one open is a business decision.

Source: CISA Known Exploited Vulnerabilities catalogue v2026.09.23, knownRansomwareCampaignUse field, computed 24 Sep 2026.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes