NewsTradingSentimentCalendarCommunityBriefing
Tech

Rising CVE Volume Outpaces Security Response

By Tech Desk · 2026-09-14 · 2 min read
A digital shield protecting a network node
Illustration: Tradingbird

AI has accelerated vulnerability discovery to a degree that overwhelms traditional triage methods, forcing security teams to rethink how they prioritize risks.

The rapid expansion of vulnerability reporting is creating a crisis of signal amidst noise. In the first half of 2026, 35,853 Common Vulnerabilities and Exposures (CVEs) were published, a 49% increase over the previous year. However, only 495 of these were confirmed as exploited in the wild. This disparity highlights a critical inefficiency: defenders are spending vast resources triaging thousands of potential threats while a small fraction actually pose an immediate danger.

As reported by The Hacker News, this surge is partly driven by AI models like Anthropic’s Mythos class, which identified over 26,000 vulnerability candidates in open-source software. Yet, fewer than 2% of these candidates were patched upstream. The core issue is no longer finding vulnerabilities, but determining which ones require immediate action before they are weaponized.

Severity Scores Lack Context

Traditional security metrics, such as the Common Vulnerability Scoring System (CVSS), provide a baseline for severity but fail to account for organizational context. A vulnerability rated as critical may be irrelevant if the affected asset is unreachable or protected by effective controls. Conversely, a lower-rated issue on a business-critical system might present a significant risk if prevention mechanisms fail. Relying solely on static scores leads to misallocation of limited security resources.

Defenders need evidence that an exposure is exploitable in their specific environment. This requires understanding not just the theoretical risk, but the actual reachability of the asset and the effectiveness of existing security controls. Without this contextual validation, security teams cannot distinguish between genuine threats and false alarms.

Automated Testing Has Limits

Automated penetration testing offers stronger evidence than scoring alone by simulating real attacks. It can demonstrate how vulnerabilities chain together and how far an attacker could progress. However, coverage remains constrained. Research indicates that only 32% of an organization's average attack surface is tested annually, even when pentesting is a top priority.

Furthermore, automated tools require working exploits to function effectively. For newly disclosed vulnerabilities, no exploit may exist yet. Additionally, testing live exploits on restricted or air-gapped systems is often impossible due to safety and compliance concerns. This leaves a gap where critical exposures remain unvalidated because standard automated methods cannot safely or effectively reach them.

Integrated Validation Is Essential

Closing this gap requires a multi-layered approach. Organizations need capabilities that go beyond automated testing to include exploitability validation for assets that cannot be safely tested, as well as security control validation to ensure defenses are actually working. By combining these methods, security teams can move from reactive triage to proactive validation, ensuring that resources are focused on the exposures that truly threaten the business.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories