Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Cisco Secure Firewall Management Critical 0-Day Actively Exploited CVE-2024-20353
July 30, 2026
Critical Home Assistant FFmpeg Bug Allows File Theft, Root Commands
July 30, 2026
AI Security Planning: Managing Resources and Mitigating Risks
July 30, 2026
Home/CyberSecurity News/Threat Actors Exploiting 23% of Vulnerabilities Before CVEs Issued
CyberSecurity News

Threat Actors Exploiting 23% of Vulnerabilities Before CVEs Issued

Key Takeaways A significant portion of vulnerabilities, nearly a quarter, are actively exploited by threat actors before their Common Vulnerabilities and Exposures (CVE) identifiers are publicly...

Sarah simpson
Sarah simpson
July 30, 2026 4 Min Read
5 0

Key Takeaways

  • A significant portion of vulnerabilities, nearly a quarter, are actively exploited by threat actors before their Common Vulnerabilities and Exposures (CVE) identifiers are publicly released.
  • The median time for a vulnerability to transition from CVE publication to known exploitation has decreased to 80 days in the first half of 2026, down from 120 days in 2025.
  • Content Management Systems (CMS), especially WordPress plugins, and network edge devices remain primary targets for attackers.
  • Artificial Intelligence (AI) products are emerging as a new attack surface, with observed exploitation of AI development tools and gateways.

Attackers Exploit Critical Flaws Before Public Disclosure, Speeding Up Exploitation Cycle

Threat actors are consistently leveraging a substantial percentage of security vulnerabilities in the wild even before their corresponding CVEs are officially published, presenting a severe challenge for defenders. This pre-disclosure exploitation creates a “zero-day” scenario for organizations, leaving them vulnerable without prior warning or readily available patches.

Table Of Content

  • Key Takeaways
  • Attackers Exploit Critical Flaws Before Public Disclosure, Speeding Up Exploitation Cycle
  • The Shrinking Window for Remediation
  • CVE Volume Rises, Exploitation Ratio Declines
  • Top Targeted Categories: CMS and Network Edge Devices
  • AI Products Emerge as a New Attack Surface
  • What You Should Do

Analysis from the first half of 2026 reveals that 23.43% of all vulnerabilities confirmed to be under active exploitation showed evidence of compromise on or before the day their CVEs were released. While this figure represents a slight decrease from the 28.93% observed in 2025, the overall speed at which vulnerabilities are being exploited continues to accelerate, narrowing the window for defensive action.

The Shrinking Window for Remediation

The time it takes for a vulnerability to move from public CVE disclosure to active exploitation is rapidly shrinking. VulnCheck’s data indicates that the median period for a vulnerability to be included in its Known Exploited Vulnerabilities (KEV) database after CVE publication dropped from 120 days in 2025 to a mere 80 days in the first six months of 2026. This accelerated pace underscores the critical need for rapid patching and proactive threat intelligence.

During this recent period, VulnCheck identified 495 vulnerabilities that were confirmed as exploited in real-world attacks. This consistent trend highlights a persistent issue for cybersecurity professionals: the public announcement of a vulnerability does not guarantee a safe period for remediation. Attackers often possess exploit code, are actively scanning for vulnerable systems, or have already breached targets well before a CVE is formally assigned and disclosed.

CVE Volume Rises, Exploitation Ratio Declines

Despite the increasing speed of exploitation for individual vulnerabilities, the overall volume of new CVEs is growing at a faster rate than the number of confirmed exploited vulnerabilities. CVE issuance saw a 45% increase compared to the preceding six-month period, while the number of known exploited vulnerabilities rose by 10%. Consequently, the ratio of KEVs to newly published CVEs decreased to 1.4%, a notable drop from its peak of 2.7% in the latter half of 2023.

However, this shift in ratio does not necessarily translate to reduced risk for organizations. The emergence of exploitation evidence often lags behind disclosure, sometimes by weeks, months, or even years. In the first half of 2026, approximately 200 CVEs achieved known-exploited status within 31 days of their publication, a rate consistent with prior years. While the surge in new CVEs has outpaced early exploitation, the ongoing pace remains operationally hazardous for defenders.

Top Targeted Categories: CMS and Network Edge Devices

Content Management Systems (CMS) emerged as the most frequently targeted technology category, accounting for roughly one-third of all KEVs tracked by VulnCheck. A significant portion of this activity was linked to vulnerabilities within WordPress plugins. Beyond WordPress, attackers also targeted other popular CMS platforms, including Drupal, Ghost, and Kentico Xperience. This sustained focus on CMS platforms emphasizes the critical importance of continuously patching both the core CMS installations and all third-party extensions.

Network edge devices also continued to be a prime target for threat actors. Newly exploited vulnerabilities were observed in products from a wide range of vendors, including Cisco, Palo Alto Networks, Check Point, F5, Juniper, Fortinet, SonicWall, Ubiquiti, D-Link, and Netgear. Internet-facing appliances remain highly attractive to attackers due to their direct exposure to the public internet, where successful exploitation can grant immediate access to internal corporate networks.

AI Products Emerge as a New Attack Surface

The expanding landscape of Artificial Intelligence (AI) products is now forming a new attack surface. VulnCheck has documented active attacks targeting tools used for AI model development, workload scaling, AI gateways, agents, and workflow automation. For instance, attackers exploited vulnerabilities in LangFlow, specifically CVE-2026-0769 and CVE-2026-5027, to harvest credentials, deploy cryptominers, and attempt lateral movement within compromised networks.

Despite growing speculation regarding AI-assisted vulnerability discovery, current data does not yet indicate that AI-found flaws are inherently more susceptible to exploitation. Out of 1,061 vulnerabilities linked to AI-assisted discovery, only 14, or 1.3%, were confirmed to be exploited in the wild. This suggests that while AI may aid in finding vulnerabilities, the actual exploitation landscape is driven by other factors.

What You Should Do

  • Prioritize Risk-Based Remediation: Focus patching efforts on vulnerabilities that are internet-facing and those confirmed to be actively exploited in the wild.
  • Patch CMS and Extensions Diligently: Regularly update all Content Management Systems (CMS) cores, themes, and plugins/extensions, as these remain a top target.
  • Secure Network Edge Devices: Ensure all internet-facing network devices (firewalls, VPNs, routers) are consistently updated and configured with robust security policies.
  • Monitor AI Infrastructure: Implement security best practices for AI development tools, gateways, and related infrastructure, treating them as critical components of your attack surface.
  • Stay Informed: Leverage threat intelligence feeds, such as VulnCheck’s KEV database, to identify and prioritize vulnerabilities that are actively being exploited.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB Instances

Next Post

Analog Devices Confirms Data Breach After Cyberattack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB Instances
July 30, 2026
Google Chrome 115 Patches 37 Vulnerabilities, 7 Critical
July 30, 2026
GenieLocker Ransomware Targets Windows, ESXi, and Linux Systems
July 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us