Attackers are exploiting a significant portion of vulnerabilities even before defenders receive a published CVE (Common Vulnerabilities and Exposures).
In the first half of 2026, 23.43% of known exploited vulnerabilities had evidence of active exploitation on or before the day their CVE was published. This figure is slightly lower than the 28.93% recorded in 2025, but overall, the pace of exploitation is increasing.
The median time between CVE publication and a vulnerability being included in VulnCheck’s Known Exploited Vulnerabilities (KEV) database dropped from 120 days in 2025 to just 80 days in the first six months of 2026.
During this period, VulnCheck identified 495 vulnerabilities that were confirmed to be exploited in the wild. This highlights an ongoing challenge for defenders: public disclosure does not necessarily create a safe window for remediation.
In many cases, attackers may already have exploit code, be scanning for vulnerable systems, or have compromised targets even before a CVE is formally assigned. Furthermore, the volume of CVEs is growing faster than the rate at which they are confirmed to be exploited.
CVE issuance rose by 45% compared to the previous six-month period, while the number of known exploited vulnerabilities increased by 10%. As a result, the ratio of KEVs to newly published CVEs fell to 1.4%, down from a peak of 2.7% in the second half of 2023.
However, this does not mean that defenders face less risk. Evidence of exploitation often emerges weeks, months, or even years after disclosure.

In the first half of 2026, approximately 200 CVEs reached known-exploited status within just 31 days of publication, a rate consistent with previous years. The rapid increase in new CVEs has outpaced early exploitation, but the pace is still operationally risky.
Content management systems (CMS) were the most targeted technology category, accounting for about one-third of all KEVs tracked by VulnCheck. Much of this activity was linked to vulnerabilities in WordPress plugins.
However, attackers also targeted other platforms, including Drupal, Ghost, and Kentico Xperience. This trend emphasizes the need for continuous patching of both CMS cores and third-party extensions.
Network edge devices also remained a major target. Newly exploited vulnerabilities affected products from vendors such as Cisco, Palo Alto Networks, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, D-Link, and Netgear.
Internet-facing appliances are particularly attractive to attackers since successful exploitation can grant direct access to corporate networks.
AI products are also becoming part of the attack surface. VulnCheck observed attacks on tools used for AI model development, workload scaling, AI gateways, agents, and workflow automation.

Attackers targeting vulnerabilities in LangFlow, including CVE-2026-0769 and CVE-2026-5027, were seen harvesting credentials, deploying cryptominers, and attempting lateral movement within networks.
Despite concerns about AI-assisted vulnerability discovery, the data does not yet indicate that AI-found flaws are more likely to be exploited.
Of 1,061 vulnerabilities linked to AI-assisted discovery, only 14, or 1.3%, were confirmed to be exploited in the wild. Organizations should prioritize risk-based remediation, focus on internet-facing systems, and patch confirmed exploited vulnerabilities as quickly as possible.