Record WatchRecord
CVE disclosure is on pace for a record year
10 August 2026 · Timeframe: Weekly, last 16 weeks (window still filling toward 52)
At the current rate, roughly 92,669 CVEs are projected for the year, the highest annualised pace we have tracked (prior high: 92,557).
Why it matters
Record disclosure volume is a scaling problem, not a panic. It means triage discipline (exploitation-first) matters more than ever, because you cannot patch a record year by volume.
What to do
- Security leaders. Make exploitation-first triage (KEV/EPSS) an explicit policy; blanket patching does not scale to a record year.
- Lean IT orgs. Do not try to keep up with the total; keep up with the confirmed-exploited subset.
- MSPs. Forecast the higher patching load into staffing and client SLAs now.
Our take
A record year of disclosure is exactly why exploitation-based prioritization beats compliance-by-volume. The number that matters is not the total, it is the exploited slice.
The data behind this