Four Rules for Surviving 2026’s 66,000 CVE Surge

By Éireann Leverett and Jerry Gamblin, FIRST Vulnerability Forecasting Team [ Join Cybersecurity Insiders ]
threat-landscape

In February, we published a forecast that was already considered record-breaking by industry standards: 2026 would be the first year in history to cross 50,000 published CVEs. Our upper bound (approaching 118,000) seemed like a tail risk few would take seriously.

Now at the midpoint of the year, that upper bound isn’t looking like a tail anymore.

In just the first four months of 2026, the industry recorded 6,420 excess CVEs. Because disclosures are climbing significantly faster than initially predicted, our updated 2026 Mid-Year Vulnerability Forecast has revised the full-year median projection to approximately 66,000 CVEs, up from 59,427.

But before security leaders assume that the internet has suddenly become 46% more dangerous overnight, we need to address the true prioritization risks that lie in these metrics. This surge reflects a structural transformation in our collective ability to find flaws, not a sudden decline in software security itself. 

What’s Driving the Surge

We are witnessing a major shift in the vulnerability landscape. AI-assisted discovery tools have permanently altered what gets found and reported, and the legacy tracking infrastructure is catching up to that reality all at once.

The forecast highlights three major structural drivers behind this volume:

  • AI-Assisted Automated Scopes: Automated bug-hunting tools are ripping through legacy software codebases at unprecedented speed. For example, the Mozilla CVE Numbering Authority (CNA) experienced a 164% spike in Q1 disclosures against their prior-year baseline, directly attributable to AI-assisted tooling running against the Firefox engine.
  • Ecosystem Reporting Maturation: GitHub Security Advisories (GHSAs) have experienced a massive 449% year-over-year surge in volume as open-source maintainers utilize automated pipelines to catalog minor bugs.
  • Backlog Absorption: VulnCheck, acting as a CNA of Last Resort to absorb unassigned vulnerability backlogs, saw a staggering 3,119% increase in activity, pulling historical flaws out of the shadows and into the official ledger.

Much of what AI tools are generating right now amounts to theoretical bugs that sound like valid human discoveries but lack real-world exploitability. If your defensive posture treats every newly minted CVE number as a critical emergency, you are introducing severe operational friction into your engineering teams for very little security ROI. 

The risk isn’t the vulnerabilities themselves; it’s the operational burden of sorting the signal from the noise.

Rain vs. Flood

To manage this volume, security teams must understand what we call the “Rain vs. Flood” distinction. Total CVE volume is the rainfall, and in 2026, the rain will not stop. But the job of a modern security team is no longer counting the drops; it’s knowing which ones will actually overrun the levee.

When you filter the total 2026 CVE volume against actual exploitability—specifically looking for vulnerabilities that have entered CISA’s Known Exploited Vulnerabilities (KEV) catalog or carry an Exploit Prediction Scoring System (EPSS) score above 10%—the actionable patching burden is remarkably flat. Only about 7% of 2026 CVEs clear the actionable threshold of real-world exploitability. The remaining 93% represent background noise.

However, while the pool of actionable risk remains stable, the time window to react to that 7% has collapsed. Once a legitimate CVE is published, the time required for threat actors to reverse-engineer an exploit using generative tools has shrunk from weeks to hours.

The Real Risk Lies in Prioritization 

This creates a severe downstream bottleneck. The constraint then lies in the human capacity to verify flaws, prioritize them, coordinate responses, and write detection signatures. Knowing a vulnerability exists is entirely different from being able to detect its active exploitation, and that translation still requires skilled human analysts.

Furthermore, software itself is growing. The sheer number of distinct products in enterprise environments has expanded by orders of magnitude. The CVE count is a symptom; the expanding asset register is the cause. If you’re managing security budgets, the conversation needs to pivot away from raw CVE volumes and toward software growth and automation capacity.

Four Steps to Navigate the 2026 Surge

To ensure your organization does not succumb to prioritization fatigue in the second half of the year, we recommend implementing four tactical changes to your security playbook:

1. Stop using CVSS as your primary filter. It was never designed for prioritization at this volume. Use KEV and EPSS together. The 7% figure is your working universe. Everything else is noise until you have capacity to revisit it.

2. Treat discovery and remediation as separate resource problems. AI expanding the discovery pipeline does not automatically expand your remediation capacity. Those are different teams, different budgets, different constraints. Plan for them separately.

3. If you ship software, you need to ship more patches per release. This is already happening. The CVE volume surge is a workload problem for software maintainers, not just for the teams patching live systems. Build it into your release cycles now.

4. The defensive AI window is open, but it won’t stay open. Offensive capabilities always get adapted for defense — history is consistent on this. Right now, the same AI driving discovery can be turned toward automated patch generation and exploitation signature creation. The organizations that build those capabilities in the next six months will have a real advantage. The ones that wait will be playing catch-up in a faster race.

AI has fundamentally changed the vulnerability landscape. Forecasters have to adapt their models, and defenders have to adapt their playbooks. 

By aggressively filtering out the noise of automated discovery and focusing heavily on automated remediation, security teams can easily turn this record-breaking volume into a highly manageable routine.

The full mid-year update, data, and methodology are here at first.org.

_____________

About: Éireann Leverett is FIRST Liaison and Lead Member of FIRST’s Vulnerability Forecasting Team. Jerry Gamblin is co-author of the FIRST Vulnerability Forecast and creator of the FirstForecast methodology.

 

 

Join our LinkedIn group Information Security Community!

No posts to display