Hackers Exploit 23% of Vulnerabilities Before CVE Publication
In the first half of 2026, nearly a quarter of exploited vulnerabilities were actively targeted before their official CVE designation, underscoring a critical window for attackers.
Attackers are increasingly demonstrating their agility by exploiting software vulnerabilities even before they are formally assigned a CVE (Common Vulnerabilities and Exposures) identifier. Analysis for the first half of 2026 reveals that 23.43% of known exploited vulnerabilities showed signs of active exploitation on or before the day their CVE was published. While this figure is a slight decrease from the 28.93% observed in 2025, the overall trend indicates a persistent and accelerating pace of exploitation, posing a significant challenge for defensive security teams.
The median time for a vulnerability to be added to VulnCheck’s Known Exploited Vulnerabilities (KEV) database has dramatically shortened, dropping from 120 days in 2025 to just 80 days in the first six months of 2026. During this period, VulnCheck tracked 495 vulnerabilities confirmed to be exploited in the wild. This rapid timeline means that public disclosure of a vulnerability does not guarantee a safe window for remediation. In many instances, attackers may already possess exploit code, be actively scanning for vulnerable systems, or have already compromised targets by the time a CVE is officially assigned.
Compounding this challenge is the sheer volume of disclosed vulnerabilities. The rate of CVE issuance has surged by 45% compared to the previous six-month period, significantly outpacing the growth in confirmed exploited vulnerabilities, which increased by only 10%. Consequently, the ratio of KEVs to newly published CVEs has fallen to 1.4%, down from a peak of 2.7% in late 2023. Despite this lower ratio, the operational risk for defenders remains high, as evidence of exploitation can surface weeks, months, or even years after an initial disclosure.
While the overall number of CVEs being exploited early has not drastically increased, approximately 200 CVEs reached known-exploited status within 31 days of publication in the first half of 2026, a rate consistent with previous years. This sustained rapid exploitation highlights the persistent threat landscape, even as the overall volume of new CVEs grows.
Content management systems (CMS) continue to be a primary target for attackers, accounting for roughly one-third of all KEVs tracked by VulnCheck. A significant portion of this activity is linked to vulnerabilities within WordPress plugins, emphasizing the ongoing need for diligent patching of both CMS cores and their extensive ecosystems of third-party extensions. Beyond WordPress, other platforms like Drupal, Ghost, and Kentico Xperience also saw exploitation.
Network edge devices remain a critical attack vector. Vulnerabilities in products from vendors such as Cisco, Palo Alto Networks, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, D-Link, and Netgear were actively exploited. These internet-facing appliances are highly attractive to attackers as successful exploitation can provide direct access to sensitive corporate networks.
Emerging technologies are also entering the attack surface. The report notes observed attacks targeting tools used in AI model development, workload scaling, AI gateways, agents, and workflow automation. Specifically, vulnerabilities in LangFlow, including CVE-2026-0769 and CVE-2026-5027, were exploited for credential harvesting, cryptomining, and lateral movement within compromised networks. Interestingly, despite concerns about AI-driven vulnerability discovery, the data indicates that AI-found flaws are not disproportionately exploited; only 1.3% of 1,061 vulnerabilities linked to AI-assisted discovery were confirmed to be exploited in the wild.
These findings underscore the critical need for organizations to adopt a risk-based remediation strategy. Prioritizing internet-facing systems and addressing confirmed exploited vulnerabilities with utmost urgency remains paramount. The shrinking window between vulnerability disclosure and active exploitation demands continuous vigilance and accelerated patching cycles to mitigate potential breaches.