Hackers Exploiting Nearly 25% of Vulnerabilities Before CVE Publication

In the first half of 2026, nearly a quarter of known exploited vulnerabilities were actively targeted by attackers on or before their Common Vulnerabilities and Exposures (CVE) publication date. Specifically, 23.43% of these vulnerabilities showed evidence of exploitation prior to or on the day their CVE was published. While this is a slight decrease from the 28.93% observed in 2025, the overall trend indicates an acceleration in the exploitation of vulnerabilities.

The median time between CVE publication and a vulnerability being added to VulnCheck’s Known Exploited Vulnerabilities (KEV) database has decreased from 120 days in 2025 to just 80 days in the first six months of 2026. During this period, VulnCheck identified 495 vulnerabilities that were confirmed to be exploited in the wild, underscoring the persistent challenge for defenders: public disclosure does not necessarily provide a safe window for remediation.

In many instances, attackers may already possess exploit code, be scanning for vulnerable systems, or have compromised targets even before a CVE is formally assigned. Additionally, the volume of CVEs is increasing at a faster rate than the confirmation of their exploitation. CVE issuance rose by 45% compared to the previous six-month period, while the number of known exploited vulnerabilities increased by 10%. Consequently, the ratio of KEVs to newly published CVEs fell to 1.4%, down from a peak of 2.7% in the second half of 2023.

However, this does not imply a reduced risk for defenders. Evidence of exploitation often emerges weeks, months, or even years after disclosure. In the first half of 2026, approximately 200 CVEs reached known-exploited status within just 31 days of publication, a rate consistent with previous years. Although the rapid increase in new CVEs has outpaced early exploitation, the pace remains operationally risky.

Content management systems (CMS) were the most targeted technology category, accounting for about one-third of all KEVs tracked by VulnCheck. Much of this activity was linked to vulnerabilities in WordPress plugins. However, attackers also targeted other platforms, including Drupal, Ghost, and Kentico Xperience. This trend emphasizes the need for continuous patching of both CMS cores and third-party extensions.

Network edge devices also remained a major target. Newly exploited vulnerabilities affected products from vendors such as Cisco, Palo Alto Networks, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, D-Link, and Netgear. Internet-facing appliances are particularly attractive to attackers since successful exploitation can grant direct access to corporate networks.

AI products are also becoming part of the attack surface. VulnCheck observed attacks on tools used for AI model development, workload scaling, AI gateways, agents, and workflow automation. Attackers targeting vulnerabilities in LangFlow, including CVE-2026-0769 and CVE-2026-5027, were seen harvesting credentials, deploying cryptominers, and attempting lateral movement within networks.

Despite concerns about AI-assisted vulnerability discovery, the data does not yet indicate that AI-found flaws are more likely to be exploited. Of 1,061 vulnerabilities linked to AI-assisted discovery, only 14, or 1.3%, were confirmed to be exploited in the wild. Organizations should prioritize risk-based remediation, focus on internet-facing systems, and patch confirmed exploited vulnerabilities as quickly as possible.

These findings highlight the critical need for organizations to enhance their vulnerability management processes. The shrinking window between vulnerability disclosure and exploitation necessitates a more proactive approach to patching and system hardening. Prioritizing vulnerabilities that are known to be exploited in the wild and focusing on securing internet-facing systems can significantly reduce the risk of compromise. Additionally, staying informed about emerging threats and adapting security strategies accordingly is essential in this rapidly evolving landscape.