Monthly, counts only

How the exploited list moved this month

Once a month: how many vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalogue, and how many of them sit in components that appear in inventories watched here. Two numbers and a sentence. It is not a list of vulnerabilities, it names no product, and nothing else is ever sent to the address.

Why a count: the reporting duty turns on exploitation of your product, and a catalogue entry is a reason to assess, not a reportable event.Art. 14⁠(1)⁠ What the monthly number tells you is how often the reason arises, which is the fact that decides whether anyone needs to be watching on the day it does.

The monthly digest is not configured on this deployment yet.

Past issues

The first issue is published on the first day of the month after the first full month of counting. Each one is kept here permanently.

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.