Were we right, and were we early?
Any tracker can mirror CISA's KEV catalog after the fact. This page checks whether our own reporting existed before CISA's official confirmation — computed directly from our publish dates against CISA's listing dates, not asserted. The query that generates this page is public; see the methodology note below.
Fastest calls on record
| CVE | Editor | We published | CISA listed KEV | Lead time |
|---|---|---|---|---|
| CVE-2026-88771 | + Patch & Defense | September 27, 2026 | September 27, 2026 | same day |
| CVE-2026-88772 | + Patch & Defense | September 27, 2026 | September 27, 2026 | same day |
| CVE-2026-65660 | + Patch & Defense | September 25, 2026 | September 25, 2026 | same day |
| CVE-2026-67279 | ~ Analysis | September 25, 2026 | September 25, 2026 | same day |
| CVE-2026-5430 | + Patch & Defense | September 24, 2026 | September 24, 2026 | same day |
| CVE-2026-93616 | ~ Analysis | September 22, 2026 | September 22, 2026 | same day |
| CVE-2026-93952 | ~ Analysis | September 22, 2026 | September 22, 2026 | same day |
| CVE-2026-94127 | ~ Analysis | September 22, 2026 | September 22, 2026 | same day |
| CVE-2026-7273 | + Patch & Defense | September 21, 2026 | September 21, 2026 | same day |
| CVE-2025-39682 | + Patch & Defense | September 18, 2026 | September 18, 2026 | same day |
| CVE-2025-39964 | + Patch & Defense | September 18, 2026 | September 18, 2026 | same day |
| CVE-2026-53266 | + Patch & Defense | September 18, 2026 | September 18, 2026 | same day |
| CVE-2026-58704 | + Patch & Defense | September 16, 2026 | September 16, 2026 | same day |
| CVE-2026-76460 | ~ Analysis | September 16, 2026 | September 16, 2026 | same day |
| CVE-2026-76461 | ~ Analysis | September 14, 2026 | September 14, 2026 | same day |
What's counted: only CVE entries a named editor actually wrote, that are currently confirmed KEV or exploited-in-wild, and where we have both our own publish date and CISA's official KEV-listing date (kevDateAdded) to compare.
What's excluded: the roughly 1,600 CVE entries oursync process auto-backfilled directly from CISA's own catalog, to fill out the KEV tracker. Those entries' publish dates are mechanically set to CISA's own listing date — including them would inflate this number for free, so they're not counted.
What "lead time" does and doesn't mean: a large lead-time number sometimes means we happened to cover a CVE for general disclosure reasons long before CISA later confirmed active exploitation on it — not that we predicted the exploitation. Either way, the claim is narrow and literal: our reporting existed, and was accurate, before CISA's official confirmation. Dates are shown in full above so you can judge each one yourself.