← All open predictions

Will CISA add at least two new Microsoft, Cisco, or Fortinet vulnerabilities to KEV by 15 October 2026?

probability 81% deadline 2026-10-15 (5d left) Security

Posted 2026-09-06 — 39 days before the deadline, stated before the outcome.

The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerabilities (KEV) catalog to list flaws actively used in the wild. This question concerns whether specific vulnerabilities in products from major vendors will be added to that list within a defined period.

The claim

CISA adds at least two new vulnerabilities affecting Microsoft, Cisco, or Fortinet products to the KEV catalog between 2026-09-07 and 2026-10-15.

Reasoning trace

  1. Ongoing vulnerability disclosures
  2. Active exploitation observed
  3. CISA verification
  4. KEV catalog update

Evidence so far

6 confirming · 0 denying signals · 6 verified · 0 broken assumptions. The evidence itself is part of the full dossier.

Probability history

Updated 27 times since mint (last on 2026-10-09) — 24% at mint → 81% today.

What to watch

  • leading indicator CISA publishes a public advisory or blog post identifying a specific Microsoft vulnerability as being actively exploited in the wild observed
  • precondition The specific Microsoft vulnerability is assigned a CVE ID by a recognized CNA (e.g., MITRE or Microsoft) and published in the CVE database observed

The full dossier behind this prediction — the evidence trail, the risk analysis, the monetization scenarios — is available on request: [email protected].

Probabilities are calibrated against the system's own resolved history; after the deadline the outcome is resolved and audited — including the calls we get wrong. Nothing on this page is investment advice.