The Cybersecurity and Infrastructure Security Agency (CISA) added 39 flaws to its Known Exploited Vulnerabilities (KEV) catalogue from 10 June to 29 July 2026. Thirty-four carried a remediation window of three days or less, up from 12 of 31 entries in the prior seven weeks.
Median time allowed fell from 14 days to three, while the pace of additions barely moved, holding near 0.78 entries daily.
