3 MIN READ
Q2 2026 closed with 18,400 new CVEs filed against vulnerabilities disclosed in the quarter. Up 22 percent year on year, the kind of number that gets a chart in a board deck. The number that actually determines whether the enterprise gets breached is somewhere in the four digits, and most of it lives in a list the board has probably never heard of. The gap between the two is where the work lives, and where most of the work is not getting done.
Picture the typical defender on a Tuesday morning. The inbox has 800 fresh CVE emails from the vuln feed. The patch SLA is set at 14 days. The cycle is a treadmill, and the treadmill is the point. Defenders who try to patch all 18,400 in a quarter are spending most of the budget on vulnerabilities nobody is ever going to use against them. Defenders who patch the CISA KEV catalog, the list of vulnerabilities with confirmed active exploitation, have patched the vulnerabilities that matter. Roughly 1,000 entries, refreshed weekly, free to read. That catalog is the work.
What the database actually shows
Web application CVEs keep climbing because the web application count keeps climbing. Cross site scripting, SQL injection, server side request forgery, the third party portal that ships with the new HR system, all of it shows up in the same feed. Dependency CVEs have exploded because the supply chain has exploded. A 2024 Docker image with an unpatched parser library will produce a CVE in the new build at the rate the upstream maintainer ships fixes, and the rate has gone up. Snyk, GitHub Dependabot, and Trivy will tell you the same thing, and the telling is not the fixing. Operating system and platform CVEs have flattened, and the flatness reflects the maturity of the OS patching pipeline. Windows, the Linux kernel, the container runtime, none of them are exciting, all of them are routine, and routine is the goal.
What the database misses
Most enterprise incidents do not start with a CVE. They start with a public S3 bucket, an over privileged IAM role in the AWS account, a network security group that lets the world in. They start with a stolen password from a phishing page, a leaked API key in a public repo, a session token harvested from a malware infostealer on the contractor laptop. They start with a refund flow that lets a customer drain the balance, a contractor onboarding path that escalates to admin, an approval workflow that nobody actually checks. None of those get a CVE. All of them get a breach, and the breach gets a postmortem that names the absence of a control the database would not have caught.
What the defender should actually do
Patch the KEV catalog on a weekly cadence. It is roughly 1,000 entries, it is free, and it is the only list the attacker is reading. Everything else is a derivative work.
Invest in the misconfiguration and credential stack. CSPM from Wiz, Lacework, or Orca; identity threat detection from Push Security, Okta, or Entra ID Protection; credential rotation on the service accounts the supply chain actually touches. These address the categories the CVE database misses, which are also the categories most incidents come from.
Threat model the business logic. A red team engagement that tries to extract value from the refund flow. A security review of the new feature before the demo, not after. A tabletop exercise where the engineering lead walks through the top three ways a customer could break the new workflow. The business logic flaw is the most expensive to discover after the breach, and the database will not warn you it is coming.

The bottom line
The CVE count is a vanity metric. Patch the KEV catalog on a weekly cadence, fund the misconfig and credential stack, and threat model the new feature before the customer finds the bug for you. That is the work.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



