H1 2026: 35,853 CVEs Published, Only 495 Exploited — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CVE volume surged to 35,853 in H1 2026, roughly 49% more than the prior year, yet only 495 were catalogued as exploited in the wild during that period, and 116 were already under attack on the day they were disclosed.
- Anthropic's disclosure data shows Mythos-class models surfacing 26,153 vulnerability candidates in open-source software, with only 421 patched upstream, underscoring the volume problem at the AI-discovery layer.
- Omdia research found 95% of organizations rank pentesting as a top or high priority, yet only 32% of their average attack surface is actually tested each year, leaving most exposures unvalidated by live exploitation.
- Picus Security will host The Validation Summit '26 on October 14–15, opening with Mikko Hyppönen and featuring Picus CTO Volkan Ertürk demonstrating a live workflow on a newly disclosed vulnerability from no-patch through post-fix re-validation.
- Security leaders from Chanel, Atlassian, and the NFL will discuss how mature enterprise teams are adapting their validation programs, including successes and failures inside real production environments.
- The article's thesis is that defenders should treat CVSS alone as a baseline rather than an action trigger, integrating exploitability validation, security control validation, and agentic pentesting into one decision process — a model aligned with Gartner's May research note on validated attack paths.
Why it matters: With CVE volume rising 49% in six months while only ~1.4% (495 of 35,853) were exploited in the wild, security teams cannot sustain a model where every High or Critical CVSS score triggers emergency response — they must shift to evidence-based prioritization using environment-specific exploitability and control-validation data, or drown in alerts that don't reflect actual risk.
Ask SkimNews




