Skip to content

Which publishers revise their records?

Publication yearas of the 2026-09-07 snapshot

2.7%[2.3–3.2%]

Of the 4,812 records microsoft published with CVE ID years 2023–2026 that stated a fix, 132 later raised the stated fix version on the same release branch. The first revision appeared after a median of 28 days.

Ranked by the lower bound of the Wilson 95% interval on the share of records stating a fix whose fix later moved, among publishers with at least 100 such records and at least 5 raised; the bracket is that interval. Each adjacent pair of ranked publishers has overlapping 95% intervals. Interval overlap alone is not a test of whether their rates differ.

Not settled: 2026 is still open, so the newest records have had the least time to be edited. A record can only be seen to move while the catalog keeps watching it, so every rate on this page is a floor rather than a final figure.

Not checked: for some 2023 records the earliest copy anyone can read was written days after the record itself was published. A raised version inside that window is invisible, so 2023 reads low for a measurement reason rather than because its records were more accurate.

How often, and time to the first recorded revision26 publishers · disc area is records published
same day7 d30 d90 d1 year0%2.5%5%7.5%10%Share of records stating a fix whose fix later moved, with 95% intervalDays to first revision (median, log scale)mitre: 0.34% [0.093–1.2%] of 592 records stating a fix; median time to revision 4 days; 19,066 records published; too few raised to rankPatchstack: 0.056% [0.022–0.14%] of 7,176 records stating a fix; median time to revision 3 days; 17,161 records published; too few raised to rankWPScan: 0.089% [0.024–0.32%] of 2,252 records stating a fix; median time to revision 10 days; 3,032 records published; too few raised to rankapple: 0.13% [0.045–0.39%] of 2,274 records stating a fix; median time to revision 8 days; 2,275 records published; too few raised to rankGitLab: 0.55% [0.21–1.4%] of 727 records stating a fix; median time to revision 20 days; 1,120 records published; too few raised to rankdell: 0.52% [0.18–1.5%] of 578 records stating a fix; median time to revision 171 days; 958 records published; too few raised to ranksiemens: 0.36% [0.10–1.3%] of 548 records stating a fix; median time to revision 141 days; 867 records published; too few raised to rankTR-CERT: 0.64% [0.22–1.9%] of 467 records stating a fix; median time to revision 17 days; 738 records published; too few raised to rankvmware: 0.55% [0.097–3.0%] of 182 records stating a fix; median time to revision 15 days; 498 records published; too few raised to rankqnap: 0.46% [0.13–1.7%] of 437 records stating a fix; median time to revision 7 days; 443 records published; too few raised to rankMattermost: 0.46% [0.13–1.7%] of 433 records stating a fix; median time to revision 17 days; 438 records published; too few raised to rankdrupal: 0.33% [0.057–1.8%] of 307 records stating a fix; median time to revision under a day; 356 records published; too few raised to rankJetBrains: 0.35% [0.062–2.0%] of 286 records stating a fix; median time to revision 2 days; 319 records published; too few raised to rankf5: 0.38% [0.067–2.1%] of 262 records stating a fix; median time to revision 140 days; 310 records published; too few raised to rankpalo_alto: 0.96% [0.26–3.4%] of 208 records stating a fix; median time to revision 20 days; 239 records published; too few raised to rankGo: 0.58% [0.10–3.2%] of 172 records stating a fix; median time to revision 65 days; 208 records published; too few raised to rankcisa-cg: 0.92% [0.16–5.0%] of 109 records stating a fix; median time to revision 158 days; 184 records published; too few raised to rankTPLink: 0.81% [0.14–4.5%] of 123 records stating a fix; median time to revision under a day; 181 records published; too few raised to rankAMZN: 0.92% [0.16–5.0%] of 109 records stating a fix; median time to revision 9 days; 169 records published; too few raised to ranksuse: 0.79% [0.14–4.3%] of 127 records stating a fix; median time to revision 35 days; 161 records published; too few raised to rankAcronis: 0.69% [0.12–3.8%] of 144 records stating a fix; median time to revision under a day; 144 records published; too few raised to rankGitHub_P: 2.9% [1.00–8.2%] of 103 records stating a fix; median time to revision 38 days; 106 records published; too few raised to rankLinux: 0.080% [0.043–0.15%] of 12,537 records stating a fix; median time to revision 22 days; 12,560 records published; rank 4LinuxVulnCheck: 0.46% [0.27–0.78%] of 2,833 records stating a fix; median time to revision 2 days; 5,439 records published; rank 3VulnCheckmicrosoft: 2.7% [2.3–3.2%] of 4,812 records stating a fix; median time to revision 28 days; 5,273 records published; rank 1microsoftCERT-PL: 3.5% [1.8–6.7%] of 231 records stating a fix; median time to revision under a day; 515 records published; rank 2CERT-PL26 publishers of records published with CVE ID years 2023–2026, by share of records stating a fix whose fix later moved (with 95% interval) against the median days the old answer stood. Each adjacent pair of ranked publishers has overlapping 95% intervals. Interval overlap alone is not a test of whether their rates differ.

Filled and named: ranked. Hollow: too few raised to rank, drawn for the interval alone. Whisker: the 95% interval.

Publishers of 2023–2026 records, ranked

4 ranked · 22 too few to rank · by lower bound
Publishers with at least 100 records stating a fix version published with CVE ID years 2023–2026, ranked by the lower bound of the 95% interval on the share whose fix later moved. Publishers with fewer than 5 raised records follow, unranked.
Publisher, The CVE Numbering Authority that published the record, as the catalog names it. Links to every counted change in its records.Stating a fix, Records this publisher put out with CVE ID years 2023–2026 which stated a fix version that could be put in order. The denominator of the rate.Raised, Of those, records whose stated fix later moved to a different version.Rate [95%], Raised as a share of records stating a fix, with the Wilson 95% interval in brackets.Median days to revision, For fix moves: median days from publication to the initial value’s first observed replacement, over this publisher's raised records. Same day is under one day.Events, Distinct correcting commits behind this publisher's counted rows. One commit that re-issued fifty records is one event.Shape: fix · range · bulk, What changed, in records: a stated fix moved, a last-affected version was raised, and how many of the fix moves sat in a bulk commit of fifty rows or more. The three are not added.Edits: same day → over a year, Days until the initial value’s first observed replacement, binned same day, within a week, within a month, within a quarter, within a year, over a year. Bar height is the share of the publisher's edits in that bin.Feed, An RSS feed of every counted change in records this publisher assigned.
microsoft#14,8121322.7% [2.3–3.2%]28 days40132 fix moved·0 range extended·54 in bulkmicrosoft: 218 counted rows by the interval to the first recorded revision: 6 same day, 9 1 to 7 days, 102 8 to 30 days, 72 31 to 90 days, 23 91 to 365 days, 6 over a yearRSS
CERT-PL#223183.5% [1.8–6.7%]under a day38 fix moved·2 range extended·0 in bulkCERT-PL: 10 counted rows by the interval to the first recorded revision: 8 same day, 2 8 to 30 daysRSS
VulnCheck#32,833130.46% [0.27–0.78%]2 days913 fix moved·10 range extended·0 in bulkVulnCheck: 23 counted rows by the interval to the first recorded revision: 4 same day, 15 1 to 7 days, 2 8 to 30 days, 2 91 to 365 daysRSS
Linux#412,537100.080% [0.043–0.15%]22 days810 fix moved·0 range extended·0 in bulkLinux: 26 counted rows by the interval to the first recorded revision: 4 same day, 4 1 to 7 days, 11 8 to 30 days, 1 31 to 90 days, 6 91 to 365 days; 1 more with no located commit, not datedRSS
Too few to rank: fewer than 5 records raised. Listed for interval overlap alone. This is not a test of whether their rates differ.
GitHub_P10332.9% [1.00–8.2%]38 days33 fix moved·0 range extended·0 in bulkGitHub_P: 15 counted rows by the interval to the first recorded revision: 5 8 to 30 days, 10 31 to 90 daysRSS
palo_alto20820.96% [0.26–3.4%]20 days22 fix moved·0 range extended·0 in bulkpalo_alto: 2 counted rows by the interval to the first recorded revision: 1 same day, 1 31 to 90 daysRSS
TR-CERT46730.64% [0.22–1.9%]17 days43 fix moved·1 range extended·0 in bulkTR-CERT: 4 counted rows by the interval to the first recorded revision: 1 1 to 7 days, 2 8 to 30 days, 1 91 to 365 daysRSS
GitLab72740.55% [0.21–1.4%]20 days44 fix moved·0 range extended·0 in bulkGitLab: 7 counted rows by the interval to the first recorded revision: 2 same day, 4 8 to 30 days, 1 91 to 365 daysRSS
dell57830.52% [0.18–1.5%]171 days33 fix moved·0 range extended·0 in bulkdell: 3 counted rows by the interval to the first recorded revision: 1 same day, 2 91 to 365 daysRSS
AMZN10910.92% [0.16–5.0%]9 days11 fix moved·0 range extended·0 in bulkAMZN: 1 counted rows by the interval to the first recorded revision: 1 8 to 30 daysRSS
cisa-cg10910.92% [0.16–5.0%]158 days11 fix moved·0 range extended·0 in bulkcisa-cg: 1 counted rows by the interval to the first recorded revision: 1 91 to 365 daysRSS
TPLink12310.81% [0.14–4.5%]under a day11 fix moved·0 range extended·0 in bulkTPLink: 1 counted rows by the interval to the first recorded revision: 1 same dayRSS
suse12710.79% [0.14–4.3%]35 days11 fix moved·0 range extended·0 in bulksuse: 6 counted rows by the interval to the first recorded revision: 6 31 to 90 daysRSS
Mattermost43320.46% [0.13–1.7%]17 days22 fix moved·0 range extended·0 in bulkMattermost: 2 counted rows by the interval to the first recorded revision: 2 8 to 30 daysRSS
qnap43720.46% [0.13–1.7%]7 days12 fix moved·0 range extended·0 in bulkqnap: 2 counted rows by the interval to the first recorded revision: 2 1 to 7 daysRSS
Acronis14410.69% [0.12–3.8%]under a day11 fix moved·0 range extended·0 in bulkAcronis: 1 counted rows by the interval to the first recorded revision: 1 same dayRSS
Go17210.58% [0.10–3.2%]65 days11 fix moved·0 range extended·0 in bulkGo: 1 counted rows by the interval to the first recorded revision: 1 31 to 90 daysRSS
siemens54820.36% [0.10–1.3%]141 days42 fix moved·0 range extended·0 in bulksiemens: 6 counted rows by the interval to the first recorded revision: 4 8 to 30 days, 2 91 to 365 daysRSS
vmware18210.55% [0.097–3.0%]15 days11 fix moved·0 range extended·0 in bulkvmware: 1 counted rows by the interval to the first recorded revision: 1 8 to 30 daysRSS
mitre59220.34% [0.093–1.2%]4 days52 fix moved·3 range extended·0 in bulkmitre: 7 counted rows by the interval to the first recorded revision: 2 same day, 3 1 to 7 days, 1 31 to 90 days, 1 91 to 365 daysRSS
f526210.38% [0.067–2.1%]140 days11 fix moved·0 range extended·0 in bulkf5: 1 counted rows by the interval to the first recorded revision: 1 91 to 365 daysRSS
JetBrains28610.35% [0.062–2.0%]2 days11 fix moved·0 range extended·0 in bulkJetBrains: 1 counted rows by the interval to the first recorded revision: 1 1 to 7 daysRSS
drupal30710.33% [0.057–1.8%]under a day11 fix moved·0 range extended·0 in bulkdrupal: 1 counted rows by the interval to the first recorded revision: 1 same dayRSS
apple2,27430.13% [0.045–0.39%]8 days33 fix moved·0 range extended·0 in bulkapple: 7 counted rows by the interval to the first recorded revision: 1 same day, 1 1 to 7 days, 4 31 to 90 days, 1 over a yearRSS
WPScan2,25220.089% [0.024–0.32%]10 days162 fix moved·18 range extended·0 in bulkWPScan: 20 counted rows by the interval to the first recorded revision: 2 same day, 4 1 to 7 days, 12 8 to 30 days, 1 31 to 90 days, 1 91 to 365 daysRSS
Patchstack7,17640.056% [0.022–0.14%]3 days524 fix moved·647 range extended·1 in bulkPatchstack: 651 counted rows by the interval to the first recorded revision: 3 same day, 9 1 to 7 days, 17 8 to 30 days, 14 31 to 90 days, 483 91 to 365 days, 125 over a yearRSS

The rate divides by the records that stated a fix version at all, never by everything a publisher put out: a publisher whose versions are rarely comparable would otherwise read low for that reason rather than for accuracy. Records, not rows, in every column: a record that raised the fix for four products is one record here and four rows in the change list.

Shape, in records: fix is records whose stated fix moved, range is records whose last-affected version was raised, and bulk is how many of the fix moves sat in one commit of fifty rows or more. The three are never added. Events are distinct correcting commits.

A high rate is not bad practice. A publisher that finds its first patch incomplete should raise the version; what this measures is that nobody downstream is told.

All years All years uses the engine's pooled publisher population, including quiet years and years below the annual listing floor. Display and ranking floors are applied after pooling. Each record belongs to one CVE ID year; these are not calendar publication-year cohorts.

Where two scorers disagree →The same records by vendor →Every raised fix version, one row each →

Data sources and quality

The organisation that publishes a CVE record is its CNA, a CVE Numbering Authority: a vendor, a research team or a national CERT that writes the record and can edit it afterwards. A rate here is the share of its records that stated a fix version whose fix later moved. It ranks one of the 15 kinds of change this site watches, and it is not a quality score.

We compare each record as it read on the day it was published against the same record today. The older copies come from the catalog's public git history, where a commit is one dated save; the first commit is the earliest copy anyone can read, and “backfilled” means a file was added to that history in a batch, later than the day the record itself went out. “Days”, for fix moves, measures from publication to the initial value’s first observed replacement. It does not date when a value became wrong.

These figures are concentrated. One publisher, microsoft, accounts for 132 of the 228 records raised with CVE ID years 2023–2026. The 4 ranked publishers published 23,787 of the 169,256 records compared and hold 163 of the raised ones, so the catalog's pooled rate is an average over all of them, not a typical publisher.

Records this site refused as false positives, product lines renumbered rather than a fix raised, are counted in no figure on this page. They are listed, marked, under every change so the filter can be checked; that list counts rows, this page counts records, so the same filter reads as two different numbers on the two pages. 1,430 refused with CVE ID years 2023–2026.

Not listed: a publisher with fewer than 100 records stating a fix version with CVE ID years 2023–2026, or none whose fix moved, is absent from this page (14 such publishers had a raised record with CVE ID years 2023–2026). Below that floor a single record swings the rate by a whole point. Absence here is not a clean record.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, so no publisher is credited or blamed for one. Left-censoring: where the first commit lands more than 7 days after the record's own datePublished, the catalog backfilled it, so the blob we call 'state at publication' already contains whatever was amended in between. Moves inside that window are invisible and are not estimated. This is part of why the earliest in-scope year reads low; the larger part is that the 2026 bulk re-edits by a few publishers fell on 2024-2025 records.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

Shipped snapshot computed 2026-09-07 from catalog commit 1f78fd2580c1. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.

How every one of these figures is measured, in full →