Skip to content
Appaloosa Scout

Threat observatory

Threat observatory

A multi-year read of the vulnerabilities in the apps and OSes Scout tracks (iOS, Android, macOS, Windows). We lead with the share of CVEs actually exploited (CISA KEV), a signal robust to NVD coverage effects, then add volume context and attack vectors.

Key metric · KEV share

2,5 % of CVEs published in 2025 were added to the CISA KEV catalog (exploited in the wild).

+0,4 pts vs 2024

KEV share is used as the hero metric: unlike raw CVE volume, it does not depend on NVD coverage in any given year. A rise signals more frequent exploitation, not just more publications.

Share of CVEs that became KEV

Percentage of CVEs published in the year that were later added to the catalog of actively exploited vulnerabilities (CISA KEV).

Share of CVEs that became KEV0%1.8%3.6%5.4%7.3%2021 — KEV share 4.6%2022 — KEV share 6.6%2023 — KEV share 2.8%2024 — KEV share 2.1%2025 — KEV share 2.5%2026* — KEV share 1.6%202120222023202420252026*
KEV share (%) of published CVEs, by year
YearKEV share
20214.6%
20226.6%
20232.8%
20242.1%
20252.5%
2026*1.6%

CVE volume over time

CVEs published per year, split between those linked to a tracked app and those linked to an OS release.

CVE volume over time0542.81085.51628.32171Tracked appsOS releases2021 — Tracked apps 117, OS releases 9832022 — Tracked apps 164, OS releases 11152023 — Tracked apps 191, OS releases 11912024 — Tracked apps 172, OS releases 16512025 — Tracked apps 192, OS releases 19792026* — Tracked apps 206, OS releases 875202120222023202420252026*
CVEs published per year, split apps vs OS
YearTracked appsOS releases
2021117983
20221641115
20231911191
20241721651
20251921979
2026*206875

Tracked apps OS releases

Raw volume is a context indicator, not a risk measure: it also reflects changes in NVD coverage and growth of the Scout catalog. Read it alongside KEV share.

Attack vectors

CVEs broken down by CVSS attack vector: remote (network), adjacent network, local access, or physical access.

Attack vectors051.5103154.52062021 — Network (remote) 972021 — Adjacent network 12021 — Local access 192022 — Network (remote) 1382022 — Local access 242022 — Physical access 22023 — Network (remote) 1512023 — Adjacent network 32023 — Local access 372024 — Network (remote) 1402024 — Local access 302024 — Physical access 22025 — Network (remote) 1492025 — Local access 432026* — Network (remote) 1842026* — Adjacent network 12026* — Local access 21202120222023202420252026*
CVEs by CVSS attack vector, by year
YearNetwork (remote)Adjacent networkLocal accessPhysical access
2021971190
20221380242
20231513370
20241400302
20251490430
2026*1841210

Network (remote) Adjacent network Local access Physical access

91% of 2025 CVEs have no CVSS vector recorded (Tier 1 stubs, incomplete NVD) and are excluded from this chart, which shows the mix of known vectors.

2025 in review (latest complete year)

The current year is excluded from comparisons: its figures are not yet consolidated.

KEV share
2,5 %
CVEs published
2 165
KEV added
55
Apps affected
6

Breakdown by platform · 2025

A cross-platform CVE is counted for each platform it affects: this is a breakdown, not a partition.

iOS

353

9 in KEV

Android

508

11 in KEV

macOS

635

8 in KEV

Windows

970

30 in KEV

Methodology

  • Sources: NVD (NIST) for CVEs and CVSS scoring, CISA KEV for the "actively exploited" status. Scope: apps tracked by Scout (iOS, Android, macOS, Windows) and documented OS releases.
  • KEV share: number of CVEs published in the year and present in the CISA KEV catalog, divided by the total number of CVEs published in the year (Scope: Scout).
  • Dates: CVEs are counted by NVD publication year; KEV by year added to the CISA catalog. We never count a present "open" status; a time series relies on immutable event dates.
  • Limitation (coverage): CVE volume depends on NVD coverage and the size of the Scout catalog, both of which change over time. Raw volume is context, not a risk measure.
  • Current year: marked with an asterisk (*) and excluded from year-over-year comparisons: its figures are not yet consolidated.

Data recomputed on 2026-06-05 22:41 UTC.