State of the Vulnerability: Q2 2026

Q2 2026 closed with 18,400 new CVEs assigned. The number is up 22 percent year over year. The number that matters is different, and the gap between the two is the story.

Dark cinematic editorial image for State of the Vulnerability: Q2 2026 - abstract cyan and electric blue digital composition in deep black, hacker aesthetic, no text no logos

3 MIN READ

Q2 2026 closed with 18,400 new CVEs filed against vulnerabilities disclosed in the quarter. Up 22 percent year on year, the kind of number that gets a chart in a board deck. The number that actually determines whether the enterprise gets breached is somewhere in the four digits, and most of it lives in a list the board has probably never heard of. The gap between the two is where the work lives, and where most of the work is not getting done.

Picture the typical defender on a Tuesday morning. The inbox has 800 fresh CVE emails from the vuln feed. The patch SLA is set at 14 days. The cycle is a treadmill, and the treadmill is the point. Defenders who try to patch all 18,400 in a quarter are spending most of the budget on vulnerabilities nobody is ever going to use against them. Defenders who patch the CISA KEV catalog, the list of vulnerabilities with confirmed active exploitation, have patched the vulnerabilities that matter. Roughly 1,000 entries, refreshed weekly, free to read. That catalog is the work.

What the database actually shows

Web application CVEs keep climbing because the web application count keeps climbing. Cross site scripting, SQL injection, server side request forgery, the third party portal that ships with the new HR system, all of it shows up in the same feed. Dependency CVEs have exploded because the supply chain has exploded. A 2024 Docker image with an unpatched parser library will produce a CVE in the new build at the rate the upstream maintainer ships fixes, and the rate has gone up. Snyk, GitHub Dependabot, and Trivy will tell you the same thing, and the telling is not the fixing. Operating system and platform CVEs have flattened, and the flatness reflects the maturity of the OS patching pipeline. Windows, the Linux kernel, the container runtime, none of them are exciting, all of them are routine, and routine is the goal.

What the database misses

Most enterprise incidents do not start with a CVE. They start with a public S3 bucket, an over privileged IAM role in the AWS account, a network security group that lets the world in. They start with a stolen password from a phishing page, a leaked API key in a public repo, a session token harvested from a malware infostealer on the contractor laptop. They start with a refund flow that lets a customer drain the balance, a contractor onboarding path that escalates to admin, an approval workflow that nobody actually checks. None of those get a CVE. All of them get a breach, and the breach gets a postmortem that names the absence of a control the database would not have caught.

What the defender should actually do

Patch the KEV catalog on a weekly cadence. It is roughly 1,000 entries, it is free, and it is the only list the attacker is reading. Everything else is a derivative work.

Invest in the misconfiguration and credential stack. CSPM from Wiz, Lacework, or Orca; identity threat detection from Push Security, Okta, or Entra ID Protection; credential rotation on the service accounts the supply chain actually touches. These address the categories the CVE database misses, which are also the categories most incidents come from.

Threat model the business logic. A red team engagement that tries to extract value from the refund flow. A security review of the new feature before the demo, not after. A tabletop exercise where the engineering lead walks through the top three ways a customer could break the new workflow. The business logic flaw is the most expensive to discover after the breach, and the database will not warn you it is coming.

A Q2 2026 vulnerability chart with 18,400 CVEs, 22 percent YoY, three categories, dark navy background, cyan and red.
Q2 2026: 18,400 CVEs filed, up 22 percent YoY. The KEV catalog is the work. The misconfig and the credential are the work the database misses. The business logic is the work only a red team will find.

The bottom line

The CVE count is a vanity metric. Patch the KEV catalog on a weekly cadence, fund the misconfig and credential stack, and threat model the new feature before the customer finds the bug for you. That is the work.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading