This article analyzes the projected surge in CVE disclosures—~66,000 expected in 2026—and argues that raw volume does not equate to exploitable risk. Critical-severity share has dropped from ~13% to ~7%, and actively exploited vulnerabilities remain under 1% of all disclosures. The real threat is the collapsing window between disclosure and exploitation, now measured in hours, combined with an overwhelmed NVD that fully analyzed only ~28% of 2025 CVEs. The author recommends shifting from volume-based metrics to exploitability-driven triage using CISA KEV and EPSS, supplemented by virtual patching and containment.
CVE triage
1 post
Volume Is Not Risk: Making Sense of the “Vulnpocalypse”