AUGUST 26, 2026
CVE volume in 2026 is genuinely unprecedented. Publication is running close to double the figure from three years ago, one recent six month period grew 45 percent over the one before it, and projections for the full year sit somewhere between 55,000 and 60,000 published vulnerabilities. Every one of those numbers is real and every one of them gets quoted in board decks.
The part that rarely follows is the denominator. Of the tens of thousands published, 495 vulnerabilities entered the CISA Known Exploited Vulnerabilities catalog across the first half of 2026. Round that to roughly a thousand for the year and the share of published CVEs that ever produce documented exploitation lands near two percent. Volume grew. The exploited population did not grow proportionally.
This article is about the gap between those two curves, which specific vulnerabilities landed on the wrong side of it in 2026, and what the ones that mattered had in common.
| 55,000+ CVEs projected for publication in 2026, close to double the volume of three years ago | 495 vulnerabilities entered the KEV catalog in the first half of 2026 | 1.3% of AI discovered vulnerabilities were confirmed exploited in the wild | 80 days median time from CVE publication to KEV listing, down from 120 |

Volume statistics are quoted without a base rate because the base rate is unflattering to the statistic. Saying that 55,000 vulnerabilities will be published this year sounds like an emergency. Saying that roughly one in fifty of them will ever be seen exploited sounds like a planning problem, which is what it actually is.
The second figure is the one that changes behaviour. A team that treats all 55,000 as inbound work will burn its capacity on triage and still miss the ones that matter, because the ones that matter are not distributed evenly across the population. They cluster, and the clustering is predictable.
A large share of the recent growth comes from automated and AI assisted discovery, and this is where the volume and risk curves separate most visibly. Independent tracking identified 1,061 vulnerabilities attributed to AI assisted discovery. Fourteen of them, 1.3 percent, have been confirmed exploited in the wild.
That ratio deserves to be understood correctly. It does not mean AI discovered vulnerabilities are harmless. It means discovery capacity has scaled faster than attacker interest, so a rising CVE count now measures how much we are looking rather than how much is being used against us. Treating those two as the same number is the central error the volume narrative encourages.

Abstractions about prioritisation are easy to agree with and hard to act on. The concrete version is a short list of the vulnerabilities that consumed real incident response hours this year.
| CVE | PRODUCT | WHY IT MATTERED | OUR COVERAGE |
| CVE-2025-55182 React2Shell | React Server Components | Maximum severity remote code execution in a framework embedded in a very large share of modern web front ends, exploited by multiple actors including state linked groups within days of disclosure. | Technical analysis published |
| CVE-2026-63030 CVE-2026-60137 WP2Shell | WordPress Core | Two flaws chained into unauthenticated remote code execution against the most widely deployed content management system on the internet. | Technical analysis published |
| CVE-2026-64638 XSS2Shell | WordPress Core | Pre authentication cross site scripting on the login page escalating to remote code execution, reachable before any credential is presented. | Technical analysis published |
| CVE-2026-8037 | Progress Kemp LoadMaster | Pre authentication command injection scored 9.6 in an internet facing load balancer, drawing 792 exploitation attempts from 65 IP addresses across 18 countries over 41 days before it entered the KEV catalog. | Featured in vulnerability intelligence content |
| CVE-2026-1281 | Ivanti EPMM | Command injection in a mobile device management platform, tracked to four distinct threat actors with five public exploits. | Actor tracking |
| CVE-2026-1731 | BeyondTrust Remote Support and Privileged Remote Access | Command injection in privileged remote access software, four threat actors, seven exploits, documented ransomware usage. | Actor tracking |
| CVE-2026-21509 | Microsoft Office | Security feature bypass with the widest actor spread of the year at six tracked groups. | Actor tracking |
Read down that list and the selection criteria write themselves. Not one of these was chosen by an attacker because of its severity score.
| SHARED PROPERTY | WHY IT DECIDES EXPLOITATION |
| Reachable without credentials | Every entry above is exploitable pre authentication or through a bypass. A flaw that requires an existing session competes with thousands of others for attacker attention and usually loses. |
| Sits in a concentrated product class | Content management systems alone accounted for one third of all KEV entries in the first half of 2026. Edge appliances, remote access software and device management platforms make up most of the rest. Attackers pre position against categories, not products. |
| Ubiquitous deployment | A framework or CMS embedded in millions of sites turns one exploit into an untargeted campaign. Scale of deployment is a stronger predictor than depth of impact. |
| Short path from disclosure to weaponisation | Median time from publication to KEV listing has fallen to 80 days, and roughly a third of exploited vulnerabilities are attacked on or before their publication date. The window for a deliberate patch cycle is closing on both ends. |
The practical answer to volume is not a faster queue. It is a smaller queue, produced by filters applied in this order.
| FILTER | THE QUESTION IT ANSWERS |
| 1. Reachability | Is this asset exposed to the internet, and can an unauthenticated request reach the vulnerable component? This single filter removes the majority of published CVEs from your working set and it is the only filter that can be applied before anyone knows whether a flaw will be exploited. |
| 2. Exploitation evidence | Is there public exploit code, observed scanning, or confirmed in the wild use? Evidence beats severity, and its absence is meaningful information rather than an excuse to defer indefinitely. |
| 3. Product class concentration | Does this sit in a category that attackers systematically target, meaning content management, edge security appliances, remote access or device management? A medium severity flaw in a concentrated class outranks a critical one in a niche product. |
| 4. Business dependency | If this system is taken offline as a containment measure, what stops? Knowing this in advance converts an incident decision into a pre made one. |
Applied to 55,000 published vulnerabilities, these four questions produce a list a human being can actually work through. Applied in the wrong order they produce the queue most teams have now, sorted by a severity score that was never designed to predict attacker behaviour.
| CAPABILITY | WHAT IT ADDRESSES |
| EASM | Continuous discovery of externally exposed assets, subdomains, certificates and shadow IT, which is what answers the reachability filter without waiting for an internal inventory to be updated. |
| Cyber Threat Intelligence | Threat actor tracking, ransomware group activity and technique mapping, which is what supplies the exploitation evidence filter with something better than a severity score. |
| Dark Web Monitoring | Collection across surface, deep and dark web through more than 190 sensors in over 40 countries, covering the channels where exploit capability and access to affected products are traded. |
RELATED READING
Vulnerability Exploitation Trends: H1 2026: What Threat Actors Are Actually Using: https://brandefense.io/blog/vulnerability-exploitation-trends-h1-2026/ The full exploitation picture behind the volume figures used here.
Why CVSS Scores Are Lying to Your Security Team (And What to Use Instead): https://brandefense.io/blog/why-cvss-scores-are-lying-to-your-security-team/ Why the score you are currently sorting by does not predict what gets attacked.
From Disclosure to Exploit: How Fast Are Threat Actors Weaponizing New CVEs?: https://brandefense.io/blog/disclosure-to-exploit-speed/ How little time the filters above have to run before exploitation begins.
XSS2Shell (CVE-2026-64638): WordPress Login Page Pre-Auth XSS to RCE Chain Explained: https://brandefense.io/blog/xss2shell-wordpress-pre-auth-xss-rce/ One of the vulnerabilities in the table above, taken apart in full technical detail.
Vulnpocalypse is a good word for a real phenomenon, but it describes the publishing rate rather than the threat. The organisations that handled 2026 well were not the ones that processed 55,000 advisories. They were the ones that could answer, on the morning an advisory landed, whether the affected product was running anywhere they could be reached. That question has nothing to do with volume, and it is the only one that scales.

Take control of your digital security with an exclusive demo of our powerful threat management platform.