▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

Root Evidence Finds the “Vulnpocalypse” Isn’t Showing Up in the Data

#Mythos--Root Evidence, the cybersecurity startup championing evidence-based security, today released “The Vulnpocalypse Report,” a new analysis of vulnerability exploitation from 2018 through Jul...

Immagine

New research analyzes 253,912 CVEs and 3,769 confirmed exploited vulnerabilities, finding adversaries continue to target a small fraction of the vulnerability population

BOISE, Idaho: #Mythos--Root Evidence, the cybersecurity startup championing evidence-based security, today released “The Vulnpocalypse Report,” a new analysis of vulnerability exploitation from 2018 through July 2026 that shows how, and how often, adversaries exploit disclosed vulnerabilities, how quickly they act after patches become available and which vulnerabilities they repeatedly target.

Researchers examined 253,912 CVEs from that time period and found only 3,769 (1.48%) of CVEs with confirmed exploitation. During every complete year from 2018 through 2025, the share of newly published CVEs with confirmed exploitation remained below 2.2%, even as annual CVE volume grew 2.5 times.

“Security teams have more vulnerabilities to manage every year, but adversaries continue to focus on just a small fraction of them,” said Jeremiah Grossman, CEO of Root Evidence. “Our data gives security teams a clearer picture of what adversaries actually use, how much time defenders have to respond and where prioritization can make the biggest difference.”

The report also examines whether recent advances in AI have accelerated vulnerability exploitation. Root Evidence researchers found record levels of CVE publication but no corresponding increase in the rate of exploitation or the share of vulnerabilities exploited as zero-days. The research does not establish whether AI caused recent changes in vulnerability volume, but the available exploitation data does not show broad acceleration in attacks.

Key findings include:

  • Most vulnerabilities are never exploited. Researchers identified 3,769 confirmed exploited CVEs among 253,912 published since 2018. The remaining 98.5% have not been detected in an attack within the dataset.
  • 81.1% of exploited CVEs had a patch available before exploitation. Researchers classified 3,058 of the 3,769 exploited CVEs as n-days, while 711 were true zero-days.
  • Most defenders have meaningful time to respond. Researchers found the median time between patch release and first confirmed exploitation reached 116 days in 2026 through mid-July. At the same time, 33.5% of 2026 n-days were exploited within 30 days, while 30.4% arrived more than a year after patch release.
  • Adversaries repeatedly target the same vendors and vulnerability classes. Microsoft ranked first in n-day exploitation counts for nine consecutive years. OS command injection, path traversal and SQL injection have remained among the leading exploited vulnerability classes since 2018.

“Security teams have spent years counting vulnerabilities,” said Grossman. “Exploitation data shows a much smaller population of vulnerabilities that adversaries actually use. That distinction matters when teams decide where to spend limited remediation resources.”

Root Evidence analyzed CVEs published between January 1, 2018, and July 15, 2026, using confirmed exploitation data from CISA KEV and VulnCheck KEV along with patch availability and other vulnerability intelligence sources. The research distinguishes true zero-days from n-days based on whether a patch existed when exploitation was first confirmed.

Grossman has shared additional insights on what the data tells us about how adversaries actually exploit vulnerabilities in a blog post, “The Lion isn’t Always in the Bushes,” published today on the Root Evidence blog.

“The Vulnpocalypse Report” is available for download today from Root Evidence.

About Root Evidence

Root Evidence is a cybersecurity company pioneering evidence-based vulnerability management to help organizations focus on the small percentage of vulnerabilities that are actually exploited in the wild, have caused reported breaches, and led to material financial losses. With Root Evidence, security teams can measurably reduce financial risk, prioritize remediation efforts where they have the greatest impact, and reduce the likelihood of breaches. Founded in 2025 by Jeremiah Grossman, Robert Hansen, Heather Konold, and Lex Arquette, the company is headquartered in Boise, Idaho and backed by Ballistic Ventures, Grossman Ventures, and leading cybersecurity experts.

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

CrowdStrike and Google Announce the Falcon Platform on Google Cloud

Fal.Con 2026--CrowdStrike (NASDAQ: CRWD) today announced the CrowdStrike Falcon® platform is now available on Google Cloud infrastructure, giving customers…

Hark Announces Multi-Year Partnership with NVIDIA to Advance Personalized…

Hark today announced a multi-year strategic partnership with NVIDIA to advance personalized agentic AI, including a deep technical collaboration and gigawatt-scale…

Simplify Healthcare Names Kamal Ahuja Chief Growth Officer to Accelerate…

#DigitalTransformation--Simplify Healthcare®, a Simplify Group™ company and leading provider of technology solutions for payers, today announced Kamal…

Perceptron AI Launches Isaac 0.5, a Frontier Open-Weight Robotics Model

Perceptron AI has launched Isaac 0.5, a 36-billion-parameter open-weight embodied foundation model that combines video understanding, embodied reasoning…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!