Hackers are increasingly targeting vulnerabilities before they are officially documented through Common Vulnerabilities and Exposures (CVE). This trend poses a significant challenge for cybersecurity defenders, who often find themselves one step behind the attackers.
Early Exploitation Trends
In the first half of 2026, data shows that 23.43% of vulnerabilities were being exploited on or before the date their CVE was published. Although this represents a decrease from 28.93% the previous year, the overall speed of exploitation is on the rise. The median gap between CVE publication and inclusion in VulnCheck’s Known Exploited Vulnerabilities (KEV) database has decreased from 120 days in 2025 to just 80 days in 2026.
VulnCheck reported that 495 vulnerabilities were actively exploited during this period. This underscores the ongoing issue that public disclosure alone is not sufficient for timely remediation, as attackers may already have the means to exploit these vulnerabilities before they are formally documented.
Increasing CVE Issuance and Implications
The number of CVEs issued has surged by 45%, yet the rate of confirmed exploited vulnerabilities only rose by 10%. Consequently, the percentage of KEVs to newly published CVEs has dropped to 1.4%, down from 2.7% in late 2023. Despite the lower ratio, this does not imply reduced risk for defenders; evidence of exploitation can appear long after the initial disclosure.
About 200 CVEs achieved known-exploited status within 31 days of publication in early 2026, highlighting a pattern consistent with past observations. Although the growth of new CVEs has surpassed early exploitation rates, the risk remains operationally significant.
Targeted Technologies and Emerging Threats
Content management systems (CMS) have emerged as the most targeted category, with approximately one-third of KEVs linked to vulnerabilities in platforms like WordPress, Drupal, Ghost, and Kentico Xperience. This trend highlights the necessity for regular updates to both CMS cores and extensions.
Network edge devices also remain under siege, with products from companies like Cisco, Palo Alto Networks, and F5 being frequently targeted. Internet-facing devices are particularly vulnerable, offering attackers potential direct access to corporate networks.
The expanding role of artificial intelligence in technology has also attracted attention from attackers. VulnCheck has identified exploits in AI development tools and associated technologies, though only a small percentage of AI-discovered vulnerabilities (1.3%) have been confirmed as exploited.
Organizations are advised to prioritize risk-based remediation strategies, especially focusing on internet-facing systems and swiftly addressing confirmed exploited vulnerabilities.
Strengthen your security operations center by enhancing threat detection and rapid response capabilities. Consider integrating tools like ANY.RUN with your SOC to improve your defensive measures.
