Skip to content
feed: live
>_0dayNews
$ track-record

Were we right, and were we early?

Any tracker can mirror CISA's KEV catalog after the fact. This page checks whether our own reporting existed before CISA's official confirmation — computed directly from our publish dates against CISA's listing dates, not asserted. The query that generates this page is public; see the methodology note below.

97%
of qualifying CVEs covered before or on CISA's KEV date
69
hand-written CVE entries now confirmed KEV

Fastest calls on record

CVEEditorWe publishedCISA listed KEVLead time
CVE-2026-20349+ Patch & DefenseAugust 11, 2026August 11, 2026same day
CVE-2026-68820+ Patch & DefenseAugust 11, 2026August 11, 2026same day
CVE-2026-20316+ Patch & DefenseJuly 29, 2026July 29, 2026same day
CVE-2026-16812+ Patch & DefenseJuly 27, 2026July 27, 2026same day
CVE-2026-16232+ Patch & DefenseJuly 22, 2026July 22, 2026same day
CVE-2026-25089+ Patch & DefenseJuly 16, 2026July 16, 2026same day
CVE-2026-46817+ Patch & DefenseJuly 15, 2026July 15, 2026same day
CVE-2026-15409+ Patch & DefenseJuly 14, 2026July 14, 2026same day
CVE-2026-15410+ Patch & DefenseJuly 14, 2026July 14, 2026same day
CVE-2026-56155+ Patch & DefenseJuly 14, 2026July 14, 2026same day
CVE-2026-56164+ Patch & DefenseJuly 14, 2026July 14, 2026same day
CVE-2026-48908+ Patch & DefenseJuly 7, 2026July 7, 2026same day
CVE-2026-55255+ Patch & DefenseJuly 7, 2026July 7, 2026same day
CVE-2026-56290+ Patch & DefenseJuly 7, 2026July 7, 2026same day
CVE-2026-48558+ Patch & DefenseJune 29, 2026June 29, 2026same day
~/track-record --methodology

What's counted: only CVE entries a named editor actually wrote, that are currently confirmed KEV or exploited-in-wild, and where we have both our own publish date and CISA's official KEV-listing date (kevDateAdded) to compare.

What's excluded: the roughly 1,600 CVE entries oursync process auto-backfilled directly from CISA's own catalog, to fill out the KEV tracker. Those entries' publish dates are mechanically set to CISA's own listing date — including them would inflate this number for free, so they're not counted.

What "lead time" does and doesn't mean: a large lead-time number sometimes means we happened to cover a CVE for general disclosure reasons long before CISA later confirmed active exploitation on it — not that we predicted the exploitation. Either way, the claim is narrow and literal: our reporting existed, and was accurate, before CISA's official confirmation. Dates are shown in full above so you can judge each one yourself.