July 24, 2026
July 24, 2026
FIRST’s forecasting team says the 2026 vulnerability landscape has shifted sharply, with CVE volumes running 46.3% above the original forecast and the revised projection reaching about 66,000 CVEs for the year. The article attributes this surge partly to AI-assisted vulnerability discovery, including autonomous tools used to find legacy bugs, but also to structural factors such as more open-source projects receiving attention, GitHub Security Advisories expansion, and VulnCheck absorbing unassigned backlogs as a CNA of Last Resort.
The key message is that higher CVE volume does not automatically mean a proportionally higher emergency patching burden. FIRST argues that when vulnerabilities are filtered by real exploitability, such as CISA KEV presence or EPSS scores above 10%, the actionable risk line remains relatively stable. The article advises defenders to focus on exploitability overlays, contextual asset mapping, defensive AI, and better cataloging of AI-generated “ephemeral” software, while software vendors should prepare to ship more fixes per security release.
Source: FIRST.org