Research and Data

Stable statistics, methodology, and citation-ready reports for journalists, vendors, vulnerability-management teams, and academic researchers.

Total KEVs

2,693

Beyond CISA KEV

1,037

In CISA KEV

1,656

Sensor KEVs (7d)

78

Reports

Monthly known exploited vulnerability reports publish automatically after each month ends, starting June 2026. Older months stay published — we do not replace report pages in place.

  • Known Exploited Vulnerabilities Report: June 2026

    A monthly snapshot of known exploited vulnerabilities tracked by KEVIntel during June 2026 — beyond-CISA coverage, sensor-observed exploitation, and vendor concentration — for journalists, vulnerability-management teams, and researchers.

    Published 1 Jul 2026

Methodology

How KEVIntel observes, attests, scores, enriches, and delivers exploited-vulnerability intelligence — including accepted evidence sources and confidence scoring.

Attribution and Citation

Preferred attribution: “Source: KEVIntel (kevintel.com)”

Deep links: When discussing a specific CVE or sensor-observed exploitation, link the relevant CVE page, Exploitation Signals, or methodology rather than only the homepage.

Citation example: KEVIntel. (2026). Known Exploited Vulnerabilities. Retrieved 30 July 2026, from https://kevintel.com/feed

Press Contact

Media and research enquiries: [email protected].

Founder

Ryan Dewhurst, Founder of KEVIntel. Cybersecurity researcher since 2009, creator of DVWA and founder of WPScan.

Embeddable Charts and Live Data

Use these stable product pages for charts and tables (link or screenshot with attribution):

Media Link Guidance

If you already cover KEVIntel, prefer deep links that match the story: sensor-observed exploitation → the CVE or Exploitation Signals; catalog/list stories → the feed; methodology or “what is a KEV” → methodology or glossary; press packs and stats → this Research and Data page. Homepage-only links are fine for brand mentions, but deep links help readers and improve topical relevance.