Threat Actors Exploiting 23% of Vulnerabilities Before CVEs Issued
Key Takeaways A significant portion of vulnerabilities, nearly a quarter, are actively exploited by threat actors before their Common Vulnerabilities and Exposures (CVE) identifiers are publicly...
Key Takeaways
- A significant portion of vulnerabilities, nearly a quarter, are actively exploited by threat actors before their Common Vulnerabilities and Exposures (CVE) identifiers are publicly released.
- The median time for a vulnerability to transition from CVE publication to known exploitation has decreased to 80 days in the first half of 2026, down from 120 days in 2025.
- Content Management Systems (CMS), especially WordPress plugins, and network edge devices remain primary targets for attackers.
- Artificial Intelligence (AI) products are emerging as a new attack surface, with observed exploitation of AI development tools and gateways.
Attackers Exploit Critical Flaws Before Public Disclosure, Speeding Up Exploitation Cycle
Threat actors are consistently leveraging a substantial percentage of security vulnerabilities in the wild even before their corresponding CVEs are officially published, presenting a severe challenge for defenders. This pre-disclosure exploitation creates a “zero-day” scenario for organizations, leaving them vulnerable without prior warning or readily available patches.
Table Of Content
- Key Takeaways
- Attackers Exploit Critical Flaws Before Public Disclosure, Speeding Up Exploitation Cycle
- The Shrinking Window for Remediation
- CVE Volume Rises, Exploitation Ratio Declines
- Top Targeted Categories: CMS and Network Edge Devices
- AI Products Emerge as a New Attack Surface
- What You Should Do
Analysis from the first half of 2026 reveals that 23.43% of all vulnerabilities confirmed to be under active exploitation showed evidence of compromise on or before the day their CVEs were released. While this figure represents a slight decrease from the 28.93% observed in 2025, the overall speed at which vulnerabilities are being exploited continues to accelerate, narrowing the window for defensive action.
The Shrinking Window for Remediation
The time it takes for a vulnerability to move from public CVE disclosure to active exploitation is rapidly shrinking. VulnCheck’s data indicates that the median period for a vulnerability to be included in its Known Exploited Vulnerabilities (KEV) database after CVE publication dropped from 120 days in 2025 to a mere 80 days in the first six months of 2026. This accelerated pace underscores the critical need for rapid patching and proactive threat intelligence.
During this recent period, VulnCheck identified 495 vulnerabilities that were confirmed as exploited in real-world attacks. This consistent trend highlights a persistent issue for cybersecurity professionals: the public announcement of a vulnerability does not guarantee a safe period for remediation. Attackers often possess exploit code, are actively scanning for vulnerable systems, or have already breached targets well before a CVE is formally assigned and disclosed.
CVE Volume Rises, Exploitation Ratio Declines
Despite the increasing speed of exploitation for individual vulnerabilities, the overall volume of new CVEs is growing at a faster rate than the number of confirmed exploited vulnerabilities. CVE issuance saw a 45% increase compared to the preceding six-month period, while the number of known exploited vulnerabilities rose by 10%. Consequently, the ratio of KEVs to newly published CVEs decreased to 1.4%, a notable drop from its peak of 2.7% in the latter half of 2023.
However, this shift in ratio does not necessarily translate to reduced risk for organizations. The emergence of exploitation evidence often lags behind disclosure, sometimes by weeks, months, or even years. In the first half of 2026, approximately 200 CVEs achieved known-exploited status within 31 days of their publication, a rate consistent with prior years. While the surge in new CVEs has outpaced early exploitation, the ongoing pace remains operationally hazardous for defenders.
Top Targeted Categories: CMS and Network Edge Devices
Content Management Systems (CMS) emerged as the most frequently targeted technology category, accounting for roughly one-third of all KEVs tracked by VulnCheck. A significant portion of this activity was linked to vulnerabilities within WordPress plugins. Beyond WordPress, attackers also targeted other popular CMS platforms, including Drupal, Ghost, and Kentico Xperience. This sustained focus on CMS platforms emphasizes the critical importance of continuously patching both the core CMS installations and all third-party extensions.
Network edge devices also continued to be a prime target for threat actors. Newly exploited vulnerabilities were observed in products from a wide range of vendors, including Cisco, Palo Alto Networks, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, D-Link, and Netgear. Internet-facing appliances remain highly attractive to attackers due to their direct exposure to the public internet, where successful exploitation can grant immediate access to internal corporate networks.
AI Products Emerge as a New Attack Surface
The expanding landscape of Artificial Intelligence (AI) products is now forming a new attack surface. VulnCheck has documented active attacks targeting tools used for AI model development, workload scaling, AI gateways, agents, and workflow automation. For instance, attackers exploited vulnerabilities in LangFlow, specifically CVE-2026-0769 and CVE-2026-5027, to harvest credentials, deploy cryptominers, and attempt lateral movement within compromised networks.
Despite growing speculation regarding AI-assisted vulnerability discovery, current data does not yet indicate that AI-found flaws are inherently more susceptible to exploitation. Out of 1,061 vulnerabilities linked to AI-assisted discovery, only 14, or 1.3%, were confirmed to be exploited in the wild. This suggests that while AI may aid in finding vulnerabilities, the actual exploitation landscape is driven by other factors.
What You Should Do
- Prioritize Risk-Based Remediation: Focus patching efforts on vulnerabilities that are internet-facing and those confirmed to be actively exploited in the wild.
- Patch CMS and Extensions Diligently: Regularly update all Content Management Systems (CMS) cores, themes, and plugins/extensions, as these remain a top target.
- Secure Network Edge Devices: Ensure all internet-facing network devices (firewalls, VPNs, routers) are consistently updated and configured with robust security policies.
- Monitor AI Infrastructure: Implement security best practices for AI development tools, gateways, and related infrastructure, treating them as critical components of your attack surface.
- Stay Informed: Leverage threat intelligence feeds, such as VulnCheck’s KEV database, to identify and prioritize vulnerabilities that are actively being exploited.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.