Open dataset

How much of CISA KEV actually hits a SaaS catalog?

Most KEV rows are appliances, OS, and browsers. This dataset measures the slice that matches a curated list of SaaS and platform vendors — plus parent, cloud-host, and identity edges. Cite it. Republish with attribution.

0%

KEV rows that match the catalog

0

Matched / 0 KEV ingested

90

Vendors in the catalog

0

Supplier matches (0 direct)

Last matched published date: n/a · Retrieved 2026-08-30. Machine-readable: JSON.

Methodology

Ingest pulls CISA’s Known Exploited Vulnerabilities JSON and recent critical NVD CVEs. Each row is matched with phrase rules against vendor names, slugs, aliases, and CPE vendor strings, then fanned out through a hand-built graph (parent, cloud_host, identity). A “match” is at least one edge to the catalog. Match rate is matched KEV rows divided by ingested KEV rows — not divided by CISA’s full historical catalog if ingest has not yet walked every entry.

This is a floor on SaaS relevance, not a claim that unmatched KEV is unimportant. Network appliances still ruin weekends. The point of the number is that a CIO who only watches “the internet’s CVE feed” is mostly watching someone else’s hardware.

How to cite

ZeroDayTracker. (2026). SaaS catalog KEV match rate. https://zerodaytracker.ai/research/saas-kev

Live tracker: zerodaytracker.ai/kev. License: CC BY 4.0 for the statistics on this page. Underlying CVE text remains CISA/NVD.