CVE disclosures are projected to hit ~66,000 in 2026, up from 48,185 in 2025, but the share of critical vulnerabilities has roughly halved and actively exploited flaws remain well under 1% of total disclosures. The surge is driven by AI-assisted bug discovery, structural reporting changes, and product sprawl — not a sudden collapse in software security. The real threat is the shrinking window between disclosure and exploitation, now collapsing from weeks to hours. Security leaders are advised to stop reporting raw CVE counts, triage using CISA KEV and EPSS scores, deploy virtual patching to cover the disclosure-to-patch gap, and invest in automation and exploitability intelligence rather than scaling patch volume.
108 Impressions