2026 is shaping up to be a CVE year like we’ve never seen. At FIRST’s 38th Annual Conference in Denver, the org released its Mid-Year 2026 Vulnerability Forecast: registered CVEs could hit ~66,000—up again from the February estimate of 59,427. And it’s not just the forecast. From Jan–Apr, real-world disclosure already exceeded expectations by ~6,420 issues, a +46.3% jump. Sounds like software security is getting worse… but FIRST stresses the point: it’s not necessarily “more vulnerable code,” it’s a changed vulnerability pipeline. What’s driving the surge? AI-assisted discovery is increasing the speed at which findings become submit-ready. Security reporting on platforms like GitHub spiked—+449%. Plus “CNA-of-Last-Resort” is clearing backlogs fast, re-assigning tons of previously unnumbered CVEs (up ~3,119%). Key takeaway: the share of exploited/high-impact bugs isn’t rising in lockstep with total CVEs. So stop treating every CVE as equal. Focus on EPSS/KEV triage, tighter patch scheduling, verification, and MTTR-reducing defensive AI. #Cybersecurity #VulnerabilityManagement #CVE #EPSS #CISAKEV #AppSec
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论