logo

CISA Known Exploited Vulnerabilities Soared 20% in 2025

ID: 197a086f-40ba-51af-bcbd-cfb2ac500e34

STIX ID: report--197a086f-40ba-51af-bcbd-cfb2ac500e34

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-01-05

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Cyble's analysis of CISA's 2025 KEV catalog found a re-acceleration in known exploited vulnerabilities with 245 additions in 2025 (≈20% growth), an increase in older flaws added, 24 entries linked to ransomware actors, Microsoft as the top vendor by additions, and recurring high-risk CWEs such as OS command injection (CWE-78), deserialization (CWE-502), and path traversal (CWE-22).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.