Skip to content
Appaloosa Scout
Language selector
fr en

Multi-year analysis

Threat observatory

A multi-year read of the vulnerabilities in the apps and OSes Scout tracks (iOS, Android, macOS, Windows). We lead with the share of CVEs actually exploited (CISA KEV), a signal robust to NVD coverage effects, then add volume context and attack vectors.

In 2025, 2,485 vulnerabilities hit the perimeter Scout tracks. 2.6 % of them were exploited in the wild, 1.1 points below 2021: the volume grows while exploitation gets rarer. 81 % of that volume came from the OS, not from apps.

CVEs published
2,485

published in 2025

KEV share
2.6 %

-1.1 pts vs 2021

OS share of volume
81 %

vs apps, same year

Key metric · KEV share

2.6 % of CVEs published in 2025 were added to the CISA KEV catalog (exploited in the wild).

+0.4 pts vs 2024

KEV share is used as the hero metric: unlike raw CVE volume, it does not depend on NVD coverage in any given year. A rise signals more frequent exploitation, not just more publications.

Share of CVEs that became KEV

Percentage of CVEs published in the year that were later added to the catalog of actively exploited vulnerabilities (CISA KEV).

Share of CVEs that became KEV0%1%2%3%4%2021 — KEV share 3.7%2022 — KEV share 2%2023 — KEV share 2.9%2024 — KEV share 2.2%2025 — KEV share 2.6%2026* — KEV share 0.4%202120222023202420252026*
KEV share (%) of published CVEs, by year
YearKEV share
20213.7%
20222%
20232.9%
20242.2%
20252.6%
2026*0.4%

CVE volume over time

CVEs published per year, split between those linked to a tracked app and those linked to an OS release.

CVE volume over time05000100001500020000Tracked appsOS releases2021 — Tracked apps 543, OS releases 9832022 — Tracked apps 532, OS releases 11172023 — Tracked apps 484, OS releases 11962024 — Tracked apps 468, OS releases 15882025 — Tracked apps 478, OS releases 20232026* — Tracked apps 3428, OS releases 2997→ 8,750 projected202120222023202420252026*
CVEs published per year, split apps vs OS
YearTracked appsOS releases
2021543983
20225321117
20234841196
20244681588
20254782023
2026*34282997

Tracked apps OS releases

Raw volume is a context indicator, not a risk measure: it also reflects changes in NVD coverage and growth of the Scout catalog. Read it alongside KEV share.

Attack vectors

CVEs broken down by CVSS attack vector: remote (network), adjacent network, local access, or physical access.

Attack vectors020004000600080002021 — Network (remote) 5362021 — Adjacent network 72021 — Local access 2212021 — Physical access 62022 — Network (remote) 5072022 — Local access 712022 — Physical access 62023 — Network (remote) 4842023 — Adjacent network 62023 — Local access 702023 — Physical access 22024 — Network (remote) 5572024 — Adjacent network 62024 — Local access 4582024 — Physical access 322025 — Network (remote) 6122025 — Adjacent network 132025 — Local access 5442025 — Physical access 262026* — Network (remote) 39032026* — Adjacent network 912026* — Local access 18662026* — Physical access 69202120222023202420252026*
CVEs by CVSS attack vector, by year
YearNetwork (remote)Adjacent networkLocal accessPhysical access
202153672216
20225070716
20234846702
2024557645832
20256121354426
2026*390391186669

Network (remote) Adjacent network Local access Physical access

52% of 2025 CVEs have no CVSS vector recorded (Tier 1 stubs, incomplete NVD) and are excluded from this chart, which shows the mix of known vectors.

Breakdown by platform · 2025

A cross-platform CVE is counted for each platform it affects: this is a breakdown, not a partition.

iOS

375

11 in KEV

Android

513

11 in KEV

macOS

972

15 in KEV

Windows

1,262

36 in KEV

Methodology

  • Sources: NVD (NIST) for CVEs and CVSS scoring, CISA KEV for the "actively exploited" status. Scope: apps tracked by Scout (iOS, Android, macOS, Windows) and documented OS releases.
  • KEV share: number of CVEs published in the year and present in the CISA KEV catalog, divided by the total number of CVEs published in the year (Scope: Scout).
  • Dates: CVEs are counted by NVD publication year; KEV by year added to the CISA catalog. We never count a present "open" status; a time series relies on immutable event dates.
  • Limitation (coverage): CVE volume depends on NVD coverage and the size of the Scout catalog, both of which change over time. Raw volume is context, not a risk measure.
  • Current year: marked with an asterisk (*) and excluded from year-over-year comparisons: its figures are not yet consolidated.

Data recomputed on 2026-09-25 04:08 UTC.