Which publishers revise their records?
2.7%[2.3–3.2%]
Of the 4,812 records microsoft published with CVE ID years 2023–2026 that stated a fix, 132 later raised the stated fix version on the same release branch. The first revision appeared after a median of 28 days.
Ranked by the lower bound of the Wilson 95% interval on the share of records stating a fix whose fix later moved, among publishers with at least 100 such records and at least 5 raised; the bracket is that interval. Each adjacent pair of ranked publishers has overlapping 95% intervals. Interval overlap alone is not a test of whether their rates differ.
Not settled: 2026 is still open, so the newest records have had the least time to be edited. A record can only be seen to move while the catalog keeps watching it, so every rate on this page is a floor rather than a final figure.
Not checked: for some 2023 records the earliest copy anyone can read was written days after the record itself was published. A raised version inside that window is invisible, so 2023 reads low for a measurement reason rather than because its records were more accurate.
Filled and named: ranked. Hollow: too few raised to rank, drawn for the interval alone. Whisker: the 95% interval.
| Publisher, The CVE Numbering Authority that published the record, as the catalog names it. Links to every counted change in its records. | Stating a fix, Records this publisher put out with CVE ID years 2023–2026 which stated a fix version that could be put in order. The denominator of the rate. | Raised, Of those, records whose stated fix later moved to a different version. | Rate [95%], Raised as a share of records stating a fix, with the Wilson 95% interval in brackets. | Median days to revision, For fix moves: median days from publication to the initial value’s first observed replacement, over this publisher's raised records. Same day is under one day. | Events, Distinct correcting commits behind this publisher's counted rows. One commit that re-issued fifty records is one event. | Shape: fix · range · bulk, What changed, in records: a stated fix moved, a last-affected version was raised, and how many of the fix moves sat in a bulk commit of fifty rows or more. The three are not added. | Edits: same day → over a year, Days until the initial value’s first observed replacement, binned same day, within a week, within a month, within a quarter, within a year, over a year. Bar height is the share of the publisher's edits in that bin. | Feed, An RSS feed of every counted change in records this publisher assigned. |
|---|---|---|---|---|---|---|---|---|
| microsoft#1 | 4,812 | 132 | 2.7% [2.3–3.2%] | 28 days | 40 | 132 fix moved·0 range extended·54 in bulk | RSS | |
| CERT-PL#2 | 231 | 8 | 3.5% [1.8–6.7%] | under a day | 3 | 8 fix moved·2 range extended·0 in bulk | RSS | |
| VulnCheck#3 | 2,833 | 13 | 0.46% [0.27–0.78%] | 2 days | 9 | 13 fix moved·10 range extended·0 in bulk | RSS | |
| Linux#4 | 12,537 | 10 | 0.080% [0.043–0.15%] | 22 days | 8 | 10 fix moved·0 range extended·0 in bulk | RSS | |
| Too few to rank: fewer than 5 records raised. Listed for interval overlap alone. This is not a test of whether their rates differ. | ||||||||
| GitHub_P | 103 | 3 | 2.9% [1.00–8.2%] | 38 days | 3 | 3 fix moved·0 range extended·0 in bulk | RSS | |
| palo_alto | 208 | 2 | 0.96% [0.26–3.4%] | 20 days | 2 | 2 fix moved·0 range extended·0 in bulk | RSS | |
| TR-CERT | 467 | 3 | 0.64% [0.22–1.9%] | 17 days | 4 | 3 fix moved·1 range extended·0 in bulk | RSS | |
| GitLab | 727 | 4 | 0.55% [0.21–1.4%] | 20 days | 4 | 4 fix moved·0 range extended·0 in bulk | RSS | |
| dell | 578 | 3 | 0.52% [0.18–1.5%] | 171 days | 3 | 3 fix moved·0 range extended·0 in bulk | RSS | |
| AMZN | 109 | 1 | 0.92% [0.16–5.0%] | 9 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| cisa-cg | 109 | 1 | 0.92% [0.16–5.0%] | 158 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| TPLink | 123 | 1 | 0.81% [0.14–4.5%] | under a day | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| suse | 127 | 1 | 0.79% [0.14–4.3%] | 35 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| Mattermost | 433 | 2 | 0.46% [0.13–1.7%] | 17 days | 2 | 2 fix moved·0 range extended·0 in bulk | RSS | |
| qnap | 437 | 2 | 0.46% [0.13–1.7%] | 7 days | 1 | 2 fix moved·0 range extended·0 in bulk | RSS | |
| Acronis | 144 | 1 | 0.69% [0.12–3.8%] | under a day | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| Go | 172 | 1 | 0.58% [0.10–3.2%] | 65 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| siemens | 548 | 2 | 0.36% [0.10–1.3%] | 141 days | 4 | 2 fix moved·0 range extended·0 in bulk | RSS | |
| vmware | 182 | 1 | 0.55% [0.097–3.0%] | 15 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| mitre | 592 | 2 | 0.34% [0.093–1.2%] | 4 days | 5 | 2 fix moved·3 range extended·0 in bulk | RSS | |
| f5 | 262 | 1 | 0.38% [0.067–2.1%] | 140 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| JetBrains | 286 | 1 | 0.35% [0.062–2.0%] | 2 days | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| drupal | 307 | 1 | 0.33% [0.057–1.8%] | under a day | 1 | 1 fix moved·0 range extended·0 in bulk | RSS | |
| apple | 2,274 | 3 | 0.13% [0.045–0.39%] | 8 days | 3 | 3 fix moved·0 range extended·0 in bulk | RSS | |
| WPScan | 2,252 | 2 | 0.089% [0.024–0.32%] | 10 days | 16 | 2 fix moved·18 range extended·0 in bulk | RSS | |
| Patchstack | 7,176 | 4 | 0.056% [0.022–0.14%] | 3 days | 52 | 4 fix moved·647 range extended·1 in bulk | RSS | |
The rate divides by the records that stated a fix version at all, never by everything a publisher put out: a publisher whose versions are rarely comparable would otherwise read low for that reason rather than for accuracy. Records, not rows, in every column: a record that raised the fix for four products is one record here and four rows in the change list.
Shape, in records: fix is records whose stated fix moved, range is records whose last-affected version was raised, and bulk is how many of the fix moves sat in one commit of fifty rows or more. The three are never added. Events are distinct correcting commits.
A high rate is not bad practice. A publisher that finds its first patch incomplete should raise the version; what this measures is that nobody downstream is told.
All years All years uses the engine's pooled publisher population, including quiet years and years below the annual listing floor. Display and ranking floors are applied after pooling. Each record belongs to one CVE ID year; these are not calendar publication-year cohorts.
Data sources and quality
The organisation that publishes a CVE record is its CNA, a CVE Numbering Authority: a vendor, a research team or a national CERT that writes the record and can edit it afterwards. A rate here is the share of its records that stated a fix version whose fix later moved. It ranks one of the 15 kinds of change this site watches, and it is not a quality score.
We compare each record as it read on the day it was published against the same record today. The older copies come from the catalog's public git history, where a commit is one dated save; the first commit is the earliest copy anyone can read, and “backfilled” means a file was added to that history in a batch, later than the day the record itself went out. “Days”, for fix moves, measures from publication to the initial value’s first observed replacement. It does not date when a value became wrong.
These figures are concentrated. One publisher, microsoft, accounts for 132 of the 228 records raised with CVE ID years 2023–2026. The 4 ranked publishers published 23,787 of the 169,256 records compared and hold 163 of the raised ones, so the catalog's pooled rate is an average over all of them, not a typical publisher.
Records this site refused as false positives, product lines renumbered rather than a fix raised, are counted in no figure on this page. They are listed, marked, under every change so the filter can be checked; that list counts rows, this page counts records, so the same filter reads as two different numbers on the two pages. 1,430 refused with CVE ID years 2023–2026.
Not listed: a publisher with fewer than 100 records stating a fix version with CVE ID years 2023–2026, or none whose fix moved, is absent from this page (14 such publishers had a raised record with CVE ID years 2023–2026). Below that floor a single record swings the rate by a whole point. Absence here is not a clean record.
Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, so no publisher is credited or blamed for one. Left-censoring: where the first commit lands more than 7 days after the record's own datePublished, the catalog backfilled it, so the blob we call 'state at publication' already contains whatever was amended in between. Moves inside that window are invisible and are not estimated. This is part of why the earliest in-scope year reads low; the larger part is that the 2026 bulk re-edits by a few publishers fell on 2024-2025 records.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
Shipped snapshot computed 2026-09-07 from catalog commit 1f78fd2580c1. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.