06/09/2026

The CVE Explosion Nobody Budgeted For

The CVE Explosion Nobody Budgeted For

72,000 vulnerabilities a year, a funding scare at the program's core, and an exploit window that's gone negative. Notes on a queue that stopped being a queue.

Forget the AI-ends-vuln-management headlines for a second. The number that should actually worry you is more boring than that: volume. In the first half of 2026, the CVE program published 35,364 new identifiers. That is a 49.5% jump over the same six months in 2025, and on its own it beat every full calendar year before 2024. One new CVE roughly every 7.4 minutes, all day, every day, for six straight months.

Run the tape back and the shape of this stops looking like growth and starts looking like compounding.

New CVEs published per year
the queue everyone is patching against, and losing to
7,938
2014
16,500
2018
20,000
2021
25,081
2022
28,902
2023
40,009
2024
48,185
2025
~72,000
2026*
*2026: H1 actual annualised. Sources: JerryGamblin.com CVE data reviews, FIRST.org 2026 Vulnerability Report, StingRAI Vulnerability Statistics 2026.

2024 was the first year to cross 40,000. 2025 added another 20% on top of that. FIRST's own forecasting group, the people whose job is literally predicting this curve, opened 2026 with a median call of roughly 59,000 CVEs for the year, which would have been the first time anyone crossed 50,000. By July, with H1 already running at 35,364, they'd revised the projection north of 90,000. Straight-line off the actual H1 pace, the year lands closer to 70-72k. Either way, the headline is the same: every single year since 2017 has been a record year. FIRST's own report flags a structural change in CVE publication patterns starting around 2017-2018, without spelling out every cause, and whatever triggered it never reversed. It just kept accelerating.

The plumbing nearly failed at the worst possible moment

Here's the part that should bother you more than the raw count. In April 2025, right as this curve was steepening, the CVE program's own funding nearly lapsed. MITRE's DHS contract for running CVE and CWE was set to expire on April 16, and CISA only pushed through an 11th-hour extension to keep "no lapse in critical CVE services," in their own words. The bedrock database that every vulnerability scanner, every SOC, every vendor advisory ultimately traces back to came within a day of going dark, not because of an attack, but because of a lapsed federal contract.

Meanwhile NIST's National Vulnerability Database, the enrichment layer that adds CVSS scores and CPE data on top of raw CVE entries, has been running a backlog since early 2024 that analysts projected could hit 30,000 unanalyzed vulnerabilities. VulnCheck has been tracking exploitation activity sitting quietly inside that backlog, which is exactly the kind of blind spot you do not want when disclosure volume is going vertical. The industry built its entire tooling stack on the assumption that someone, somewhere, was triaging and enriching every CVE before it reached your scanner. That assumption is now visibly under strain.

Zero-days aren't exploding. They're concentrating.

If you only look at raw zero-day counts, 2025 looks almost calm. Google's Threat Intelligence Group tracked 90 zero-days exploited in the wild for the year, sitting comfortably inside the 60-100 band the industry has held for five years running (2023 hit 100, 2024 came in at 78). The real story is where those 90 landed.

Enterprise technology took 48% of them, the highest share GTIG has recorded, up from 46% in 2024. Security and networking products (the VPNs, the firewalls, the SASE boxes you bought specifically to reduce your attack surface) accounted for 21 zero-days on their own, 14 of them in edge devices specifically. PRC-nexus groups, UNC3886 and UNC5221 among them, burned roughly 10 zero-days on exactly that category, chaining things like a Juniper router flaw (CVE-2025-21590) and an Ivanti VPN bug (CVE-2025-0282) to sit inside networks that were supposed to be the hardened perimeter. Ransomware crews weren't far behind. FIN11 and the CL0P-linked extortion operation used zero-days in Oracle E-Business Suite (CVE-2025-61882 and CVE-2025-61884) to run a mass-exploitation campaign against exactly the kind of ERP system that nobody patches on a Friday.

And for the first time, commercial spyware vendors (the Intellexa-adjacent surveillance-for-hire crowd) outpaced state-sponsored groups as zero-day consumers. The zero-day market got more efficient at finding the boxes that matter most and staying there, without needing to get bigger.

What the money people think about all this

This isn't just an engineering problem anymore, and you don't need to take an AppSec engineer's word for it. The Bank of England runs a Systemic Risk Survey twice a year asking the UK's largest financial institutions what keeps them up at night. In the 2026 H1 round, 82% of respondents named cyberattack as one of their top five risks to the financial system, and 26% called it the single most important risk they face, up six points from the prior survey. Cyberattack ranks second only to geopolitical risk, and 77% of respondents said it's the hardest risk on the list to actually manage, up four points on the prior survey. This has now been a top-tier concern in every BoE survey since it resumed in 2021.

The World Economic Forum's Global Risks Report 2026 puts cyber insecurity at #6 on the two-year outlook, grouped with disinformation as a technological risk the report says is "growing largely unchecked." ENISA's Threat Landscape 2025, covering roughly 4,900 incidents across the EU between July 2024 and June 2025, found vulnerability exploitation behind 21.3% of intrusions, with ransomware driving 81.1% of cybercrime incidents against European organisations. None of these bodies are trying to sell you a scanner. They're trying to figure out how much of the financial system falls over if this queue keeps growing the way it has.

CVE to PoC: the part that should actually keep you up

Everything above is a volume story. This is a speed story, and it's the one that actually changes what "patch management" means.

Median time from CVE disclosure to working exploit
log scale. attackers didn't get patient, they got tooling
2018
756 days
2022
32 days
2023
5 days
2025-26
same day, or before
Sources: Cloud Security Alliance ("The Collapsing Exploit Window"), VulnCheck State of Exploitation 1H-2025, Mandiant M-Trends 2026.

In 2018, the median gap between a CVE going public and a working exploit hitting the wild was 756 days. Two years ago that was down to roughly 32 days. Last year it was 5. VulnCheck's mid-2025 data found that 32.1% of known-exploited vulnerabilities had exploitation evidence on or before the CVE's own publication date, up from 23.6% the year before. Mandiant's M-Trends 2026 puts the mean time-to-exploit at approximately negative seven days. Read that again: on average, exploitation is happening before the advisory exists. CrowdStrike's 2026 numbers back this up from a different angle, 42% of exploited vulnerabilities were attacked before public disclosure, and once an intrusion starts, average eCrime breakout time is 29 minutes, with the fastest observed case at 27 seconds.

That collapse shows up in the breach data too. For the first time in the DBIR's history, vulnerability exploitation overtook phishing and credential abuse to become the single most common initial access vector, at 31% of incidents, up 55% year over year from 20% in 2025. And the defenders' side of the same report is going the wrong direction: median remediation time for known-exploited vulnerabilities climbed to 43 days in 2026, up from 32 the year before, only 26% of known-exploited vulnerabilities got fully remediated (down from 38%), and 60-70% were still sitting unpatched at day seven regardless of how mature the organisation claimed to be.

The part that actually broke this for me is the economics. A Cloud Security Alliance whitepaper on what they're calling "AI-speed vulnerability weaponization" documents AI models producing working proof-of-concept code for a published CVE in 10-15 minutes, at around a dollar an attempt. The CVE-Genie research framework automatically reproduced working exploits for 51% of tested 2024-2025 CVEs at an average cost of $2.77 each. One documented agent swarm found more than 100 exploitable kernel vulnerabilities across major hardware vendors in 30 days, for about $600 total. Building a PoC used to be the bottleneck between "there's a CVE" and "there's a problem." That bottleneck is gone. It costs less than your coffee and takes less time than your standup.

The take: "Patch faster" was always weak advice and now it's actively delusional. You cannot out-run a queue growing 20-50% a year with a remediation cycle measured in weeks, against an exploit window measured in minutes and increasingly measured in negative days. The only posture that survives contact with these numbers is assuming disclosed means exploited, on day zero, by default, and building exposure reduction that doesn't wait on a patch cycle to start doing its job. Vulnerability management as a discipline built around "assess, prioritise, patch" is a good process for a world that stopped existing around 2023.

Keep patching. Just stop treating the CVE feed as a to-do list. Treat it as a live threat feed running hours behind, not weeks, and budget your team accordingly.

No comments:

The CVE Explosion Nobody Budgeted For

The CVE Explosion Nobody Budgeted For 72,000 vulnerabilities a year, a funding scare at the program's core, and an exploit window t...