![]()
Root Evidence, the cybersecurity startup championing evidence-based security, today released “The Vulnpocalypse Report,” a new analysis of vulnerability exploitation from 2018 through July 2026 that shows how, and how often, adversaries exploit disclosed vulnerabilities, how quickly they act after patches become available and which vulnerabilities they repeatedly target.
Researchers examined 253,912 CVEs from that time period and found only 3,769 (1.48%) of CVEs with confirmed exploitation. During every complete year from 2018 through 2025, the share of newly published CVEs with confirmed exploitation remained below 2.2%, even as annual CVE volume grew 2.5 times.
“Security teams have more vulnerabilities to manage every year, but adversaries continue to focus on just a small fraction of them,” said Jeremiah Grossman, CEO of Root Evidence. “Our data gives security teams a clearer picture of what adversaries actually use, how much time defenders have to respond and where prioritization can make the biggest difference.”
The report also examines whether recent advances in AI have accelerated vulnerability exploitation. Root Evidence researchers found record levels of CVE publication but no corresponding increase in the rate of exploitation or the share of vulnerabilities exploited as zero-days. The research does not establish whether AI caused recent changes in vulnerability volume, but the available exploitation data does not show broad acceleration in attacks.
Key findings include:
- Most vulnerabilities are never exploited. Researchers identified 3,769 confirmed exploited CVEs among 253,912 published since 2018. The remaining 98.5% have not been detected in an attack within the dataset.
- 81.1% of exploited CVEs had a patch available before exploitation. Researchers classified 3,058 of the 3,769 exploited CVEs as n-days, while 711 were true zero-days.
- Most defenders have meaningful time to respond. Researchers found the median time between patch release and first confirmed exploitation reached 116 days in 2026 through mid-July. At the same time, 33.5% of 2026 n-days were exploited within 30 days, while 30.4% arrived more than a year after patch release.
- Adversaries repeatedly target the same vendors and vulnerability classes. Microsoft ranked first in n-day exploitation counts for nine consecutive years. OS command injection, path traversal and SQL injection have remained among the leading exploited vulnerability classes since 2018.
“Security teams have spent years counting vulnerabilities,” said Grossman. “Exploitation data shows a much smaller population of vulnerabilities that adversaries actually use. That distinction matters when teams decide where to spend limited remediation resources.”
Root Evidence analyzed CVEs published between January 1, 2018, and July 15, 2026, using confirmed exploitation data from CISA KEV and VulnCheck KEV along with patch availability and other vulnerability intelligence sources. The research distinguishes true zero-days from n-days based on whether a patch existed when exploitation was first confirmed.
Grossman has shared additional insights on what the data tells us about how adversaries actually exploit vulnerabilities in a blog post, “The Lion isn’t Always in the Bushes,” published today on the Root Evidence blog.
“The Vulnpocalypse Report” is available for download today from Root Evidence.
About Root Evidence
Root Evidence is a cybersecurity company pioneering evidence-based vulnerability management to help organizations focus on the small percentage of vulnerabilities that are actually exploited in the wild, have caused reported breaches, and led to material financial losses. With Root Evidence, security teams can measurably reduce financial risk, prioritize remediation efforts where they have the greatest impact, and reduce the likelihood of breaches. Founded in 2025 by Jeremiah Grossman, Robert Hansen, Heather Konold, and Lex Arquette, the company is headquartered in Boise, Idaho and backed by Ballistic Ventures, Grossman Ventures, and leading cybersecurity experts.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260903321086/en/
Media gallery
