The CVE Tsunami: When the Database Becomes the Breach

The CVE database in 2026 hit 240,000+ entries, with 28,000+ new CVEs in 2025, with the typical enterprise unable to patch the CVEs at the rate the CVEs come in. The CVE tsunami amounts to the situation where the patching…

A single overflowing stack of papers on a dark wood surface, dim warm amber side light, deep navy shadows, the stack is tall, no people visible.

The CVE database in 2026 hit 240,000+ entries, with 28,000+ new CVEs in 2025, with the typical enterprise unable to patch the CVEs at the rate the CVEs come in. The CVE tsunami amounts to the situation where the patching program runs behind the patching demand, the database becomes the breach vector the typical enterprise cannot defend. The 2026 guide covers what the CVE tsunami amounts to, what the patching program can do, what the enterprise should do when the patching cannot keep up.

The 2026 CVE numbers tell the story. The total CVE count sits at 240,000+, with 28,000+ new CVEs added in 2025 (up from 22,000+ in 2024). The typical enterprise has 1,000-10,000 assets in the patching scope, with each asset having 5-20 CVEs at any time, with the patching team patching 10-50 CVEs per week. The 2026 state of the patching program amounts to a state where the patching program processes 5-15% of the CVEs per month, the patching program falls further behind every month, the database sits exposed to the CVEs the patching program does not have the bandwidth to patch.

The numbers that show the problem

Four numbers, in roughly that order of how much they show the problem. The first runs as the 240,000 number, where the total CVE count sits at 240,000+, the number has grown 20% per year for the last 5 years, the number does not include the duplicates the NVD does not deduplicate. The second runs as the 28,000 number, where the new CVEs added in 2025 sit at 28,000+, the number sits up 27% from 2024, the growth rate sits accelerating. The third runs as the 70 number, where the typical enterprise has 70+ days mean time to patch the critical CVE, the number sits up from 50+ days in 2024, the patching program runs slower not faster. The fourth runs as the 5 number, where the typical enterprise has 5-15% of the CVEs unpatched at any time, the 5-15% translates to 50-200 CVEs per asset in the typical enterprise. The four numbers together show the patching program cannot keep up.

What the patching approaches fail at

Three approaches, in roughly that order of how often they have failed. The first runs as the patch everything approach, where the enterprise tries to patch every CVE, the patching team works 80 hours per week, the patching team burns out, the patching team quits, the patching program collapses. The second runs as the patch the criticals approach, where the enterprise patches the critical CVEs (the CVSS 9+, the CVSS 7+), the enterprise ignores the rest, the medium and the low CVEs sit unpatched, the attacker exploits the medium and the low CVEs because the attacker can. The third runs as the patch the exploitable approach, where the enterprise patches the CVEs with the known exploit, the enterprise ignores the rest, the enterprise misses the new exploit the CISA does not know about, the enterprise sits exposed to the new exploit. The three approaches together produce the failure pattern that the typical enterprise has not escaped.

What to do when the patching cannot keep up

Three moves if you are facing the patching program that cannot keep up. Use the risk based prioritisation, where the patching program prioritises the CVEs by the exploitability (the CISA KEV, the known exploit in the wild), the prioritisation patches the CVEs the attacker can use, the prioritisation does not waste the patching on the CVEs the attacker cannot use. Use the compensating controls, where the patching program applies the compensating control (the network segmentation, the application allow list, the behaviour monitoring) for the CVEs the patching program cannot patch, the compensating control reduces the impact. Use the virtual patching, where the patching program uses the WAF or the IPS to block the exploit of the CVE the patching program cannot patch, the virtual patching buys the time the patching program needs. The enterprise that uses the prioritisation, uses the compensating controls, and uses the virtual patching stands as the enterprise that survives the CVE tsunami.

Abstract CVE database as glowing cyan vertical columns of varying heights on a dark navy surface, dramatic chiaroscuro lighting from above.
The CVE tsunami in 2026: 4 numbers that show the problem, 3 patching approaches that fail, 3 moves that work when the patching cannot keep up.

The bottom line

The CVE tsunami in 2026 amounts to the situation where the patching program cannot keep up. The four numbers (240K total, 28K new, 70 day mean time, 5% unpatched) show the problem. The three failed approaches (patch everything, patch the criticals, patch the exploitable) do not solve it. The three moves (risk based prioritisation, compensating controls, virtual patching) cover the work. The enterprise that does the three moves stands as the enterprise that survives the CVE tsunami.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading