Friday, September 11, 2026

Hackers Exploit Nearly 1 in 4 Vulnerabilities Before or on Disclosure Day

Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they are publicly disclosed, according to VulnCheck’s State of Exploitation report for the first half of 2026, published on July 28, 2026.

VulnCheck identified 495 Known Exploited Vulnerabilities (KEVs) in the first half of 2026. Of these, 23.43% showed evidence of exploitation on or before the date of their Common Vulnerabilities and Exposures (CVE) disclosure.

While this figure is slightly lower than 2025’s rate of 28.93%, it still indicates a significant acceleration in the overall pace of exploitation. The median time between CVE publication and active exploitation has decreased from 120 days in 2025 to just 80 days in 2026.

This suggests that threat actors are operationalizing vulnerabilities more quickly, even if pre-disclosure exploitation has marginally declined.

Hackers Exploit Nearly 1 in 4 Vulnerabilities

Early-stage exploitation remains consistent, with approximately 200 CVEs being exploited within 31 days of disclosure, similar to previous years. However, due to a sharp increase in total CVE volume, this number represents a smaller overall proportion.

The report highlights a growing gap between vulnerability disclosure and exploitation rates. The volume of CVEs surged by 45% in the first half of 2026, while the number of KEVs increased by only 10%, reducing the KEV-to-CVE ratio to 1.4%, down from a peak of 2.7% in 2023.

vulnerabilities being exploited in 2026 (Source: VulnCheck)
vulnerabilities being exploited in 2026 (Source: VulnCheck)

This suggests that while more vulnerabilities are being discovered, partly due to automation and AI-assisted research, not all of them are immediately weaponized. However, exploitation often lags behind disclosure, meaning current figures may evolve.

Content Management Systems (CMS) emerged as the most targeted technology category, accounting for roughly one-third of all KEVs.

Vulnerabilities in WordPress plugins, as well as in platforms like Drupal and Ghost, were heavily exploited, reflecting recent large-scale campaigns flagged by global cybersecurity agencies.

Network edge devices also remained prime targets, with vulnerabilities affecting vendors such as Cisco, Palo Alto, Fortinet, and Juniper. These systems continue to provide attackers with crucial entry points into enterprise environments.

Additionally, security tools, developer platforms, and device management systems were exploited at faster rates due to their privileged access and widespread deployment.

Despite growing concerns, AI-assisted vulnerability discovery has not yet led to a higher rate of exploitation. Of the 1,061 vulnerabilities attributed to AI-driven discovery, only 14 (1.3%) were confirmed to have been exploited, closely matching the overall exploitation rate.

However, AI technologies themselves are becoming targets. Exploited systems include model-building platforms, AI gateways, and workflow automation tools.

CVE Volume (Source: VulnCheck)
CVE Volume (Source: VulnCheck)

In one observed case, attackers leveraged vulnerabilities in LangFlow (CVE-2026-0769 and CVE-2026-5027) to gain access, harvest credentials, deploy cryptominers, and attempt lateral movement.

Anthropic’s Project Glasswing, which reported over 23,000 findings, has thus far resulted in only 126 CVEs, with just one confirmed to have been exploited in the wild, raising questions about the current real-world impact of AI-driven discovery.

These findings emphasize the need for rapid patching and risk-based prioritization. CISA’s Binding Operational Directive 26-04 recommends remediation within as little as three days for vulnerabilities that are known to be exploited, have a high impact, or are publicly exposed.

While AI is expanding the vulnerability landscape, current data suggests that its role is increasing the volume of discoveries rather than amplifying immediate risks. For defenders, this creates a critical window to identify and remediate flaws before adversaries can take action.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News