17 of the 90 KEV Entries We Can Actually Measure Were Already Weaponized Before CISA Listed Them. One by 85 Days.
- Patrick Duggan
- 59 minutes ago
- 4 min read
We re-ran our weaponization-latency measurement this morning. It correlates three dates for every CVE in CISA's Known Exploited Vulnerabilities catalogue: the day CISA listed it, the day we first saw a public proof-of-concept for it, and the day we first observed something probing our own edge for it.
The headline number is that seventeen KEV entries had a working public PoC in circulation before CISA added them to the catalogue. The worst gap is CVE-2026-34486 in Apache Tomcat, where a public PoC preceded the KEV listing by eighty-five days. Nearly three months during which the exploit was public, the vulnerability was not on the federal must-patch list, and any organisation using KEV as its prioritisation trigger had no reason to act.
The denominator, before the number
The single most important thing on this page is the denominator, so it goes before the findings rather than in a footnote.
CISA's KEV catalogue currently holds 1,661 entries. Our exploit watch has seen PoC activity for 497 CVEs. The overlap — KEV entries where we have an actual PoC sighting date to compare against — is 90. That 90 is the real denominator. Seventeen out of ninety is what we are claiming, and it is a claim about the subset we can measure, not about KEV as a whole.
For the other 1,571 KEV entries we have no PoC record. That does not mean they were never weaponized. It means we did not see it, and "we didn't see it" is an unknown, not a zero. Any vendor who tells you what percentage of the whole catalogue was armed early is extrapolating from a sample they have not shown you. We are showing you ours because a metric with no denominator reads as success by default, and "found nothing" and "never looked" produce identical-looking reports.
The median gap for the ninety we can measure is 54 days from KEV listing to first PoC sighting. That is the normal case and it is the reassuring one: usually CISA is ahead of the public exploit. The seventeen are the exceptions, and exceptions are where the operational risk lives.
The seventeen, and the pattern in them
The largest negative gaps, in days between public PoC and KEV listing:
Apache Tomcat, CVE-2026-34486, 85 days early. Langflow, CVE-2026-0770, 58 days. Fortinet FortiSandbox appears twice — CVE-2026-25089 at 36 days and CVE-2026-39808 at 27. Ubiquiti UniFi OS, CVE-2026-34908, 17 days. JoomShaper SP Page Builder, CVE-2026-48908, 15 days. IBM Langflow, CVE-2026-9198, and Oracle E-Business Suite, CVE-2026-46817, both 14 days. Cisco Unified Communications Manager, CVE-2026-20230, 12 days. The remainder cluster in the one-to-seven day range, which is close enough to be a reporting artifact rather than a real window.
Two things stand out. Langflow shows up twice under two different vendor strings, and it is the same AI-orchestration component both times — a reminder that the AI tooling layer is now generating KEV entries with early public exploitation, not just think-pieces. And enterprise security appliances are over-represented: FortiSandbox twice, plus SonicWall and Check Point elsewhere in the dataset. The devices bought to watch the perimeter keep turning up as the thing being exploited across it.
The number that changes how you prioritise
Eighty-five KEV entries have a public PoC and zero probes observed against our edge.
We watch a live surface. When a commodity mass-scanning campaign spins up against a vulnerability, we see it — WordPress drew 22,403 probes and Laravel 19,655 in this window, which is what indiscriminate opportunistic scanning looks like in the data. Git, GraphQL, Spring, phpMyAdmin, WebLogic and Jenkins trail far behind in the hundreds and tens.
So when a vulnerability has a working public exploit and generates no background scanning noise at all, the reasonable inference is that it is not being used opportunistically. Somebody may still be using it — deliberately, against selected targets, without spraying the internet first. That is the profile of targeted exploitation, and it is exactly the class that a defender tuned to "is this being mass-scanned yet?" will rank last.
That inversion is the practical takeaway. Absence of scanning noise is routinely read as absence of risk. On these eighty-five, it may be the opposite signal.
What this is not
It is not a criticism of CISA. KEV is an evidence-of-exploitation catalogue, not an exploit-availability catalogue — it lists things being exploited in the wild, which is deliberately a higher bar than "a PoC exists." A gap between public PoC and KEV listing is the system working as designed, not failing. The problem is not the catalogue; it is organisations using KEV as their only trigger and thereby inheriting that bar without deciding to.
It is also not a prediction. We are not saying the eighty-five will be exploited against you. We are saying they carry a different risk shape than their probe volume implies, and that a prioritisation model driven by observed scanning will systematically deprioritise them.
And our PoC-sighting dates are first-sighting-by-us, not first-existence. A PoC could have circulated privately well before our watch caught it, which would make every gap in this post an understatement rather than an overstatement. That direction of error is worth knowing.
What to do with it
If you use KEV as a patch trigger, add a second trigger: public PoC availability for anything in your estate, independent of catalogue status. The Tomcat case is the argument — eighty-five days is long enough to matter and KEV was not going to tell you.
If you prioritise by observed scanning volume, carve out an exception for high-severity issues with a public PoC and no scanning. Low noise on an armed vulnerability deserves a second look rather than a lower rank.
If you run Langflow, FortiSandbox, UniFi OS, Oracle E-Business Suite or Cisco Unified Communications Manager, the specific CVEs are named above and each one was armed before it was listed.
We guarantee five percent of what we publish is wrong. Here the honest disclosure is the denominator: this is seventeen out of the ninety KEV entries we can actually measure, our PoC dates are first-seen-by-us rather than first-existence, and the 1,571 entries with no PoC record are unknown rather than clean. We would rather hand you a smaller number we can defend than a bigger one we cannot.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.
