50 Vulnerability Statistics and Trends

50 Vulnerability Statistics and Trends: Risk, Exploitation, and Discovery

|

BY Konstantine Zuckerman

Published

08/06/2026

|

Last updated on:

08/06/2026

Every year, tens of thousands of new software vulnerabilities are disclosed, and only a small fraction are ever exploited in the real world. The hard part for security teams isn’t finding vulnerabilities anymore; it’s figuring out which ones matter before an attacker does.

That challenge keeps getting harder. Exploiting known vulnerabilities is now the single most common way attackers break into corporate networks, ahead of phishing and stolen credentials, and the gap between disclosure and weaponization keeps shrinking: a growing share of vulnerabilities are exploited within days of going public, some before the public even knows they exist.

Remediation hasn’t kept pace. The median time to fully patch a critical vulnerability now stretches well over a month, even as attackers move in days or hours.

This article compiles 50 vulnerability statistics covering CVE discovery, severity, exploitation, remediation, and the most significant vulnerabilities of 2025-2026, revealing where risk is concentrated, how quickly threats evolve, and what the data means for security priorities in 2026.

While this report focuses on the data, many of these statistics relate to the most prevalent Common Vulnerabilities and Exposures (CVEs) tracked through the CVE Program and the National Vulnerability Database. These include widely exploited issues such as remote code execution, SQL injection, cross-site scripting (XSS), privilege escalation, and server-side request forgery (SSRF), all of which continue to shape modern cyber attacks and vulnerability management priorities.

CVE Discovery & Disclosure Statistics

1. A record 48,185 CVEs were published in 2025, per Edgescan, closely echoed by VulnCheck’s 48,174 and confirmed by researcher Jerry Gamblin’s CVE Data Review. One tracker, Zafran, counted fewer (46,407), but most converge near 48,000-48,200. (Edgescan / VulnCheck / Gamblin / Zafran)

2. That pace has only accelerated since: 35,364 CVEs were published in just the first half of 2026, up 49.5% over the same window in 2025 and putting the full year on track for roughly 71,000-72,000, nearly 50% more than 2025’s record total. Confirmed exploitation stayed just as rare, though: only 85 of those H1 2026 CVEs (0.24%) had appeared in the CISA KEV catalog as of July 2026. (Jerry Gamblin CVE Data Review, July 2026)

3. Of VulnCheck’s full-year count, 40,085 (83.21%) carried 2025 identifiers; the rest were issued for older, previously undocumented vulnerabilities. (VulnCheck)

4. 26% of CVEs with 2025 identifiers had public proof-of-concept code or exploit details available by year’s end (10,480 unique CVEs). (VulnCheck)

5. The CISA Known Exploited Vulnerabilities catalog stood at 1,484 total vulnerabilities by the end of 2025, with 245 added during the year, cross-confirmed by researcher Zafran (Edgescan’s own report states this two ways in two sections; this uses the confirmed figure). (Edgescan / Zafran)

6. Within that catalog, vendor concentration is stark: Microsoft accounts for 361 KEV entries, more than four times the next closest vendor, with Apple (90), Cisco (85), Adobe (76), and Google (68) rounding out the top five. (Edgescan 2026 Vulnerability Statistics Report)

7. VulnCheck’s research team separately curated nearly 20,000 exploits in 2025. Of those, 74% targeted 2025 CVEs, and 99% were publicly available rather than commercial-only. (VulnCheck)

8. Exploit sourcing is dominated by CVE Numbering Authorities: 73.8% of 2025 exploits were surfaced via CNA advisories, with GitHub (14.4%) and blogs (8.7%) rounding out the top sources. Within CNAs, VulDB (42.1%) and MITRE (25.8%) led. (VulnCheck)

Vulnerability Risk, Severity, and CVSS Statistics

9. Despite the flood of new disclosures, a mere 1% of 2025 CVEs, 422 total, were confirmed exploited in the wild by year’s end: 52 with APT usage, 39 tied to ransomware, 23 to botnets. (VulnCheck)

10. Independent scanning data points to a similar concentration of risk: across the full stack, 20% of discovered internet-facing vulnerabilities were rated critical or high severity, critical alone at 11%. (Edgescan 2026 Vulnerability Statistics Report)

11. Full weaponization remains rare even among exploited vulnerabilities: more than 98% of the exploits VulnCheck tracked in 2025 were proof-of-concept code, not fully weaponized tooling. Only 417 new weaponized exploits emerged all year, 70% private or commercial-only. (VulnCheck)

12. Vulnerability risk is outpacing remediation capacity: only 26% of CISA KEV-listed critical vulnerabilities were fully remediated in 2025, down sharply from 38% the year before. (Verizon 2026 DBIR)

13. 16% of KEV vulnerabilities remained fully unremediated in 2025, up from 12% the prior year. (Verizon 2026 DBIR)

14. The median number of KEV vulnerabilities an organization had to patch rose to 16 in 2025, up from 11 in 2024, nearly 50% more per organization in a single year. (Verizon 2026 DBIR)

15. Roughly 60 to 70% of KEV vulnerabilities remain open at the one-week mark, regardless of year, volume, or maturity. The DBIR notes this rate “barely moved despite three years of additional process development, tooling investment and mandate pressure.” (Verizon 2026 DBIR)

Zero-Day & Exploitation Statistics

16. Separately from the CISA catalog, VulnCheck maintains its own KEV dataset and added 884 vulnerabilities to it in 2025 (118 sources), partly reflecting new sources VulnCheck onboarded rather than purely more exploitation. (VulnCheck)

17. 47.7% of 2025 KEV additions carried 2025 CVE identifiers, underscoring how quickly adversaries weaponize newly disclosed flaws. (VulnCheck)

18. 28.96% of 2025 KEVs were exploited on or before the day their CVE was published, up from 23.6% in 2024: defenders increasingly have zero lead time. (VulnCheck)

19. As noted above, exploitation is now the most common initial access vector for breaches, at 31%, overtaking credential abuse (13%) for the first time in the DBIR’s reporting. (Verizon 2026 DBIR)

20. Mandiant’s independent figure, exploits comprising 32% of 2025 incident response investigations, marks the sixth straight year exploits led that list. (Mandiant M-Trends 2026)

21. 2025’s single most significant vulnerability, CVE-2025-55182 (“React2Shell”), a critical RCE in React Server Components, accumulated 236 valid public exploits in the last four weeks of the year, more than any CVE in history. VulnCheck Canaries detected over 26,000 exploit attempts by late January 2026. (VulnCheck)

22. Global median attacker dwell time rose to 14 days in 2025, up from 11 in 2024, the second straight annual increase after roughly a decade of decline from a 2011 peak of 416 days. (Mandiant M-Trends 2026)

23. The median time between an initial-access broker’s foothold and handoff to a more damaging group fell to 22 seconds in 2025, down from more than 8 hours in 2022. (Mandiant M-Trends 2026)

24. Along with non-functional and misleading exploit code, AI-generated exploit code is degrading public vulnerability intelligence. This aligns with broader AI cybersecurity statistics showing how artificial intelligence is reshaping both cyberattacks and cyber defense. VulnCheck found GitHub repos with fabricated “proof-of-concept” exploits, including one for React2Shell that never exercised the vulnerable code path, yet was absorbed into Google’s AI search summaries as authoritative. (VulnCheck)

Vulnerability Management & Remediation Statistics

25. The median time for full resolution of a critical (KEV-listed) vulnerability rose to 43 days in 2025, up from 32 days the year prior. (Verizon 2026 DBIR)

26. At the 28-day mark, 35% of vulnerability instances remained open in 2025, up from 27% in 2024: an estimated 184 million open instances, more than five times 2022’s 31 million. (Verizon 2026 DBIR)

27. The share of proactive patching, before a vulnerability lands on the KEV catalog, is also declining: only 12% of instances were remediated pre-KEV-inclusion in 2025, down from 17% in 2024. Despite that decline, defenders proactively patched 63.7 million vulnerability instances in 2025 overall, up 30% from 48.9 million in 2024. (Verizon 2026 DBIR)

28. Edgescan’s data confirms the same slow pace independently. Average MTTR for high/critical Application/API vulnerabilities was 54.8 days, dropping to 39 days for Device/Network. By predicted exploitability, MTTR was 134.3 days for EPSS above 0.7 but 210 days for EPSS below 0.1, suggesting only partial risk-based prioritization. (Edgescan 2026 Vulnerability Statistics Report)

29. Remediation speed varies sharply by industry: Software fastest at 55 days, Construction slowest at 123.1 days (Edgescan’s narrative separately rounds Software to 53). (Edgescan 2026 Vulnerability Statistics Report)

30. Ransomware groups don’t need broad coverage to be effective. VulnCheck tracked only 39 CVEs with confirmed 2025 ransomware exploitation, down 25% from 2024, yet 56.4% were discovered via zero-day exploitation, up sharply from 33%. (VulnCheck)

31. Among known 2025 ransomware-linked CVEs, one third still had no public or commercial exploit as of January 2026, suggesting crews increasingly keep exploit chains private. (VulnCheck)

32. Ransomware itself continues climbing as a breach category. Ransomware was present in 48% of all 2025 breaches, up from 44% the year before. (Verizon 2026 DBIR)

Browser Vulnerability Statistics

33. Chrome’s disclosure pace surged sharply in early 2026. A single release, Chrome 149, patched 429 vulnerabilities, a record and reportedly several times all of Chrome’s 2025 fixes combined, over 100 rated critical or high. (SecurityWeek)

34. The following release, Chrome 150, patched 382 more vulnerabilities, 358 found internally by Google, 15 rated critical. (PCWorld)

35. Reporting ties this surge to AI-assisted vulnerability discovery, which reportedly contributed to Google lowering its Chrome bug bounty payouts in April 2026. (SecurityWeek)

36. Google patched at least eight actively exploited Chrome zero-days during 2025 (through mid-December), spanning causes from an ANGLE Metal renderer buffer overflow to a sandbox-escape flaw tied to espionage. (BleepingComputer)

37. By comparison, one outlet reports Mozilla logged roughly 90 distinct CVE IDs across Firefox in 2025, a fraction of Chrome’s volume, largely reflecting Chrome’s larger attack surface. (Tech Insider; unverified against Mozilla’s own archive, lower-confidence than other stats here.)

38. CVE-2025-8088, a WinRAR path traversal flaw, was one of the year’s most broadly state-sponsored-targeted vulnerabilities, exploited by Chinese, North Korean, and Russian-aligned actors alike. (VulnCheck)

39. Russia-aligned RomCom incorporated CVE-2025-8088 into its client-side playbook in 2025, chaining its file-write primitive with Windows Startup folder execution, extending its pattern of abusing client-side flaws for initial access. (VulnCheck)

Cloud Vulnerability Statistics

40. CVE-2025-31324, an unrestricted file upload flaw in SAP NetWeaver, was one of 2025’s most consequential enterprise/cloud-adjacent flaws. By year’s end, VulnCheck tracked nine threat actors and four ransomware groups exploiting it, with honeypot detections still active in January 2026. (VulnCheck)

41. Security firms documented reconnaissance against CVE-2025-31324 as early as January 2025, three months before the CVE was published, showing how far exploitation can precede formal disclosure. (VulnCheck)

42. CVE-2025-61882, an Oracle E-Business Suite vulnerability that Mandiant says may have been exploited as a zero-day, was exploited by a suspected FIN11 threat cluster linked to the Cl0p extortion brand. Mandiant traced related activity to July 2025, roughly three months before public disclosure in October. (Mandiant M-Trends 2026)

43. As of January 24, 2026, more than 8,300 Oracle E-Business Suite instances remained exposed to the public internet, per VulnCheck’s Censys scanning, up from 2,000-3,000 in early October 2025. (VulnCheck)

44. Network edge devices were the top-targeted technology category among VulnCheck’s own 2025 KEV additions, at 191 entries, ahead of CMS platforms (163) and open-source software (129). (VulnCheck)

45. Among CVEs with confirmed threat-actor attribution in 2025, Enterprise Software led at 18 CVEs, with Network Edge close behind at 17. For ransomware groups, Enterprise Software led more clearly at 15 CVEs, against 8 for Driver-based targets. (VulnCheck)

Notable CVEs

46. CVE-2025-55182 (“React2Shell”): A critical RCE flaw in React Server Components, exploitable by default in vulnerable Next.js apps. It became the most researched CVE in history within weeks, drawing attribution from China, North Korea, and Iran-nexus state actors, three botnets (Gafgyt, Mirai, RondoDox), and the Weaxor ransomware family. (VulnCheck)

47. The Microsoft SharePoint “ToolShell” chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771): Four chained on-premises SharePoint flaws exploited at scale from July 2025 on. CVE-2025-53770 alone drew 10 threat-actor attributions and was linked to several ransomware families, including Warlock and Qilin. (VulnCheck / Mandiant M-Trends 2026)

48. CVE-2025-61882 and CVE-2025-61884 (Oracle E-Business Suite): A pair of zero-days disclosed during Cl0p’s mass data-theft campaign. The first alone spanned six root-cause weaknesses combined into one record. (VulnCheck / Mandiant M-Trends 2026)

49. CVE-2025-0282 (Ivanti Connect Secure): A critical stack-based buffer overflow exploited as a zero-day from mid-December 2024. Mandiant linked post-exploitation Spawn malware to UNC5337, a China-nexus group it assessed with medium confidence to be part of the larger UNC5221 cluster. (VulnCheck / SecurityWeek)

50. CVE-2024-55591 (Fortinet FortiOS/FortiProxy): A zero-day auth bypass disclosed in January 2025 that ended the year with the highest ransomware-group count of any 2025-tracked vulnerability: six families, including DragonForce, Qilin, and RansomHub. (VulnCheck)

What This Data Means for Cybersecurity in 2026

Three patterns run through nearly every statistic in this report.

1. Exploitation now outpaces disclosure awareness

Nearly 29% of 2025’s confirmed-exploited vulnerabilities in VulnCheck’s KEV dataset were exploited on or before their CVE publication date, and incidents like SAP NetWeaver and Oracle EBS show attacker activity preceding disclosure by weeks or months. Waiting for a CVE before assessing exposure is no longer sufficient.

2. Remediation capacity has not kept pace with disclosure volume

Median time to patch a critical vulnerability grew from 32 to 43 days in 2025. Proactive pre-KEV patching declined, and even Edgescan’s fastest industry, Software, averaged 55 days to remediate a high or critical flaw. The problem isn’t detection; it’s fixing what’s already been found. Regular penetration testing can also help organizations validate whether critical vulnerabilities are actually exploitable in their environments.

3. A small number of flaws drive most real-world risk

Just 1% of 2025 CVEs were ever exploited, and a handful, including React2Shell, the SharePoint ToolShell chain, and the Oracle EBS zero-days, accounted for most threat-actor, ransomware, and botnet activity tracked all year. Effective prioritization in 2026 depends less on CVSS scores and raw CVE counts than on real-time exploitation intelligence: what’s actually being used against high-value targets right now. Organizations that combine this intelligence with strong network security practices will be better positioned to reduce real-world risk.

As these vulnerability statistics show, organizations should prioritize vulnerabilities based on real-world vulnerability exploitation, validate defenses through regular penetration tests, and address weaknesses identified by frameworks such as the OWASP Top 10 rather than relying solely on CVSS scores.

Sources

Discuss your project now

Related Content

Schedule a personalized demo with CYBRI.

Don't wait, reputation damages & data breaches could be costly.

Tell us a little about your company so we can ensure your demo is as relevant as possible. We’ll take the scheduling from there!
Michael B.
Michael B.Managing Partner, Barasch & McGarry
I am an attorney who represents thousands of people in the 9/11 community. CYBRI helped my company resolve several cybersecurity issues. I definitely recommend working with CYBRI.
Tim O.
Tim O.CEO at Cylera
I’m using CYBRI and have been very impressed with the experience and quality of the experts and CYBRI’s customer service. It has been a super seamless process that I’m happy and pleased with – I recommend CYBRI to all businesses.
Sergio V.
Sergio V.CTO at HealthCare.com
I hired CYBRI to help my company with various cybersecurity services, specifically HIPAA and CCPA. I have been satisfied with the quality of work performed by the cybersecurity expert. The customer service is excellent. I would recommend CYBRI for all of your cybersecurity needs.
L.D. Salmanson
L.D. SalmansonCEO at Cherre.com
We worked with CYBRI on assessing vulnerabilities and understanding the risks of our client-facing web assets. We are satisfied with the results and the professionalism of the Red Team members. Highly recommend CYBRI to all businesses.
Marco Huslmann
Marco HuslmannCTO MyPostcard
CYBRI is a great solution that helps streamline the penetration testing process. I strongly recommend them and will work with them again.
Alex Rothberg
Alex RothbergCTO IntusCare
I highly recommend CBYRI to businesses that need penetration testing to ensure their business infrastructure is secure.
John Tambuting
John TambutingCTO Pangea.app
I am confident CYBRI is the right penetration testing choice if you are looking to build a secure business environment.

Discuss your Project







    Michael B.
    Michael B.Managing Partner, Barasch & McGarry
    I am an attorney who represents thousands of people in the 9/11 community. CYBRI helped my company resolve several cybersecurity issues. I definitely recommend working with CYBRI.
    Tim O.
    Tim O.CEO at Cylera
    I’m using CYBRI and have been very impressed with the experience and quality of the experts and CYBRI’s customer service. It has been a super seamless process that I’m happy and pleased with – I recommend CYBRI to all businesses.
    Sergio V.
    Sergio V.CTO at HealthCare.com
    I hired CYBRI to help my company with various cybersecurity services, specifically HIPAA and CCPA. I have been satisfied with the quality of work performed by the cybersecurity expert. The customer service is excellent. I would recommend CYBRI for all of your cybersecurity needs.
    L.D. Salmanson
    L.D. SalmansonCEO at Cherre.com
    We worked with CYBRI on assessing vulnerabilities and understanding the risks of our client-facing web assets. We are satisfied with the results and the professionalism of the Red Team members. Highly recommend CYBRI to all businesses.
    Marco Huslmann
    Marco HuslmannCTO MyPostcard
    CYBRI is a great solution that helps streamline the penetration testing process. I strongly recommend them and will work with them again.
    Alex Rothberg
    Alex RothbergCTO IntusCare
    I highly recommend CBYRI to businesses that need penetration testing to ensure their business infrastructure is secure.
    John Tambuting
    John TambutingCTO Pangea.app
    I am confident CYBRI is the right penetration testing choice if you are looking to build a secure business environment.

    Find mission-critical vulnerabilities before hackers do.

    CYBRI’s manual pen tests are performed by U.S.-based highly certified Red Team experts.

    We help businesses detect & remediate catastrophic vulnerabilities in applications, cloud, and networks.