-

Root Evidence Finds the “Vulnpocalypse” Isn’t Showing Up in the Data

New research analyzes 253,912 CVEs and 3,769 confirmed exploited vulnerabilities, finding adversaries continue to target a small fraction of the vulnerability population

BOISE, Idaho--(BUSINESS WIRE)--Root Evidence, the cybersecurity startup championing evidence-based security, today released “The Vulnpocalypse Report,” a new analysis of vulnerability exploitation from 2018 through July 2026 that shows how, and how often, adversaries exploit disclosed vulnerabilities, how quickly they act after patches become available and which vulnerabilities they repeatedly target.

"Security teams have spent years counting vulnerabilities. Exploitation data shows a much smaller population of vulnerabilities that adversaries actually use. That distinction matters when teams decide where to spend limited remediation resources."

Share

Researchers examined 253,912 CVEs from that time period and found only 3,769 (1.48%) of CVEs with confirmed exploitation. During every complete year from 2018 through 2025, the share of newly published CVEs with confirmed exploitation remained below 2.2%, even as annual CVE volume grew 2.5 times.

“Security teams have more vulnerabilities to manage every year, but adversaries continue to focus on just a small fraction of them,” said Jeremiah Grossman, CEO of Root Evidence. “Our data gives security teams a clearer picture of what adversaries actually use, how much time defenders have to respond and where prioritization can make the biggest difference.”

The report also examines whether recent advances in AI have accelerated vulnerability exploitation. Root Evidence researchers found record levels of CVE publication but no corresponding increase in the rate of exploitation or the share of vulnerabilities exploited as zero-days. The research does not establish whether AI caused recent changes in vulnerability volume, but the available exploitation data does not show broad acceleration in attacks.

Key findings include:

  • Most vulnerabilities are never exploited. Researchers identified 3,769 confirmed exploited CVEs among 253,912 published since 2018. The remaining 98.5% have not been detected in an attack within the dataset.
  • 81.1% of exploited CVEs had a patch available before exploitation. Researchers classified 3,058 of the 3,769 exploited CVEs as n-days, while 711 were true zero-days.
  • Most defenders have meaningful time to respond. Researchers found the median time between patch release and first confirmed exploitation reached 116 days in 2026 through mid-July. At the same time, 33.5% of 2026 n-days were exploited within 30 days, while 30.4% arrived more than a year after patch release.
  • Adversaries repeatedly target the same vendors and vulnerability classes. Microsoft ranked first in n-day exploitation counts for nine consecutive years. OS command injection, path traversal and SQL injection have remained among the leading exploited vulnerability classes since 2018.

“Security teams have spent years counting vulnerabilities,” said Grossman. “Exploitation data shows a much smaller population of vulnerabilities that adversaries actually use. That distinction matters when teams decide where to spend limited remediation resources.”

Root Evidence analyzed CVEs published between January 1, 2018, and July 15, 2026, using confirmed exploitation data from CISA KEV and VulnCheck KEV along with patch availability and other vulnerability intelligence sources. The research distinguishes true zero-days from n-days based on whether a patch existed when exploitation was first confirmed.

Grossman has shared additional insights on what the data tells us about how adversaries actually exploit vulnerabilities in a blog post, “The Lion isn’t Always in the Bushes,” published today on the Root Evidence blog.

“The Vulnpocalypse Report” is available for download today from Root Evidence.

About Root Evidence

Root Evidence is a cybersecurity company pioneering evidence-based vulnerability management to help organizations focus on the small percentage of vulnerabilities that are actually exploited in the wild, have caused reported breaches, and led to material financial losses. With Root Evidence, security teams can measurably reduce financial risk, prioritize remediation efforts where they have the greatest impact, and reduce the likelihood of breaches. Founded in 2025 by Jeremiah Grossman, Robert Hansen, Heather Konold, and Lex Arquette, the company is headquartered in Boise, Idaho and backed by Ballistic Ventures, Grossman Ventures, and leading cybersecurity experts.

Contacts

Media Contact:
Kylie Heintz
kylie@rootevidence.com

Root Evidence


Release Summary
New research challenges the AI-driven “vulnpocalypse” narrative with data on what attackers actually exploit.
Release Versions

Contacts

Media Contact:
Kylie Heintz
kylie@rootevidence.com

Social Media Profiles
More News From Root Evidence

Cybersecurity Experts Jeremiah Grossman and Robert Hansen Call for the End of Guesswork in Cybersecurity

LAS VEGAS--(BUSINESS WIRE)--After decades spent helping define modern cybersecurity, Root Evidence Co-founders Jeremiah Grossman and Robert (RSnake) Hansen are challenging one of the industry’s most deeply held assumptions: that finding more vulnerabilities makes organizations more secure. Their new book, “The End of Guessing,” debuts this week at Black Hat USA, making the case that vulnerability management has become an exercise in managing volume rather than reducing risk. The authors argue t...

Root Evidence Launches Full Platform to Help Security Teams Stop Chasing Millions of Vulnerabilities and Start Preventing Financial Loss

BOISE, Idaho--(BUSINESS WIRE)--Root Evidence, the cybersecurity startup championing evidence-based security, launched its full platform today with a simple premise: The cybersecurity industry has been measuring the wrong thing. For decades, organizations have measured cyber risk by the number of vulnerabilities discovered, severity scores assigned, and critical findings remediated. Yet despite more tools, more alerts, and more data than ever before, organizations continue to suffer costly ranso...

Root Evidence Research Finds Only 1.4% of Vulnerabilities Are Known to Be Exploited in Real-World Attacks

BOISE, Idaho--(BUSINESS WIRE)--Root Evidence, the cybersecurity startup championing evidence-based security, today released new research showing that the cybersecurity industry’s current approach to vulnerability management is overwhelmingly focused on the wrong problems. The report, Stop Counting CVEs: What Actually Mattered in Q1 2026, analyzed publicly available vulnerability and exploitation data from Q1 2026 and found that only a small fraction of vulnerabilities are actually tied to real-...
Back to Newsroom