The intersection of artificial intelligence and cybersecurity is reshaping how vulnerabilities are identified and addressed. With the rapid pace of vulnerability discovery, security teams are challenged to discern which vulnerabilities require immediate attention. This dynamic was highlighted in the first half of 2026 when 35,853 CVEs were published, marking a 49% increase from the previous year. Despite this surge, only a fraction was actively exploited, underscoring the need for a refined approach to vulnerability management.
Understanding the Vulnerability Landscape
During this period, it became evident that not all vulnerabilities pose an equal threat. Anthropic’s data revealed that out of 26,153 potential vulnerabilities identified in open-source software, only 421 received patches. This highlights the critical task for security teams: prioritizing vulnerabilities based on actual threat levels, rather than relying solely on severity scores.
The traditional CVSS framework provides a baseline for severity but lacks the contextual insight needed to assess impact within specific environments. Factors such as asset exposure, existing security controls, and business criticality must be evaluated to determine which vulnerabilities warrant immediate action.
The Limits of Automated Pentesting
While automated pentesting offers substantial evidence of exploitability, it does not cover the entire attack surface. Omdia’s research indicates that organizations prioritize pentesting, yet only test 32% of their attack surface annually. This gap suggests the need for more comprehensive strategies that combine automated and agentic methods.
Automated tests may not always be feasible for newly disclosed CVEs, especially on critical systems where live exploits cannot be safely tested. In such scenarios, an exploitability assessment is needed to decide on further action. Automated pentesting is essential, but it must be part of a broader validation strategy.
Integrating Validation Methods
Combining exploitability validation, security control testing, and agentic pentesting creates a robust framework for managing vulnerabilities. These methods collectively address different aspects of exposure, ensuring comprehensive coverage. Effective integration allows for dynamic response and strategic prioritization of security efforts.
The upcoming Picus Validation Summit ’26 will explore these concepts in depth. Hosted by Picus Security, the event will feature insights from industry leaders, including Mikko Hyppönen and Picus CTO Volkan Ertürk. Attendees will learn how leading enterprises are adapting their validation processes to keep pace with AI-driven threats.
Looking Ahead
The evolution of cybersecurity validation is crucial in an era where AI amplifies both the scale and complexity of threats. By adopting integrated validation strategies, organizations can better protect their assets from emerging risks. The Picus Validation Summit ’26 presents an opportunity to learn from pioneering security experts about effective practices and future trends.
