Skip to content

AI Isn’t Causing a ‘Vulnpocalypse.’ CVE Volume Is the Real Problem

Root Evidence analyzed 253,912 CVEs and found AI is accelerating vulnerability discovery, but not exploitation — exposing a vulnerability management model increasingly overwhelmed by noise.

For the past several years, cybersecurity teams have been warned that artificial intelligence is about to radically compress the vulnerability exploitation window.

AI will find vulnerabilities faster. Attackers will weaponize them faster. Zero-days will multiply. The time between disclosure and exploitation will shrink from days to hours and eventually minutes.

Root Evidence went looking for evidence that this “Vulnpocalypse” is actually happening. It didn't find much.

The company's new Vulnpocalypse Report analyzed 253,912 CVEs published between Jan. 1, 2018 and July 15, 2026, then traced 3,769 vulnerabilities with confirmed exploitation in the wild. Its central finding is difficult to square with much of the industry's prevailing narrative: Vulnerability publication is exploding, but attacker behavior has not accelerated along with it.

Full report and blog post:

The Vulnpocalypse Report · Evidence
Root Evidence traced every confirmed in-the-wild exploitation of a published CVE from January 1, 2018 through July 15, 2026 and measured how much adversary behavior has actually changed.
The Lion Isn’t Always In The Bushes · Evidence Blog
Jeremiah Grossman takes a closer look at the “vulnpocalypse” narrative and what the data really shows. The answer points to a better way to prioritize vulnerabilities based on real-world impact, not fear.

Only 1.48% of the vulnerabilities published during the period have confirmed exploitation in the dataset. And 81.1% of those exploited vulnerabilities already had a patch available before attackers were observed exploiting them.

That doesn't make the vulnerability problem smaller. Just different.

The more important takeaway from Root Evidence's research may be that vulnerability management has become increasingly disconnected from the way attackers actually behave.

CVEs are exploding. Exploitation isn't.

The numbers illustrate the disconnect.

NVD recorded roughly 17,800 CVEs in 2018 and more than 44,800 in 2025, about a 2.5-fold increase. Yet the share of vulnerabilities confirmed as exploited remained below 2.2% during every complete year analyzed.

Root Evidence argues that AI appears to be contributing to faster vulnerability discovery, although the researchers explicitly say they cannot isolate how much of the increase is attributable to AI.

What they don't see is a corresponding explosion in exploitation. Of the 253,912 CVEs examined, 3,769 have confirmed exploitation. The other 98.5% have not been observed in an attack within the dataset. That distinction matters because security organizations don't experience vulnerability growth as an academic statistic. They experience it as work.

More CVEs become more scanner findings, more tickets, more risk scores, more remediation requests and more vulnerabilities competing for finite engineering time. If AI continues lowering the cost of vulnerability discovery, that imbalance gets worse.

Attackers don't have to exploit every new vulnerability for AI to create a serious security problem. They merely have to let defenders drown trying to treat every vulnerability as though they might.

Related:

The Vulnpocalypse Isn’t Your Problem
But it might be your company’s problem.
The CVE Stampede Is a Distraction From Real Risk
With 48,000+ CVEs published annually, the challenge isn’t volume. It’s finding the vulnerabilities attackers will actually exploit.

Attackers apparently aren't racing the clock

Perhaps the report's most provocative finding concerns time-to-exploitation.

Root Evidence argues that conventional measurements often start the clock at NVD publication. The researchers instead measure from when a vendor made a patch available, reasoning that this represents the point at which defenders could actually do something about the vulnerability.

Using that measurement, the report found that vulnerabilities first exploited in 2026 had a median 116-day gap between patch availability and confirmed exploitation. The comparable figure in 2018 was 24 days.

That's almost the opposite of the widely repeated claim that exploitation windows are universally collapsing. But the 116-day number requires some caution. Attackers aren't politely waiting four months for everyone.

Among the 391 n-day vulnerabilities first exploited through mid-July 2026, 33.5% were attacked within 30 days of patch availability. At the other extreme, 30.4% weren't exploited until more than a year after a patch existed.

That distribution may be more useful to CISOs than the median itself. There isn't one exploitation window.

Some vulnerabilities require an immediate response. Others remain exploitable for months or years largely because organizations haven't installed fixes that already exist.

Zero-days aren't taking over either

AI's ability to discover vulnerabilities has also fed predictions that zero-days will become dramatically more common.

Root Evidence again says the data doesn't show it — at least not yet.

The researchers classified a vulnerability as a “true zero-day” only when exploitation occurred before a patch was available. By that definition, 711 of the 3,769 exploited CVEs were zero-days. That's 18.9% of the exploited dataset but just 0.28% of all CVEs published during the period.

That leaves 3,058 exploited vulnerabilities where defenders already had access to a fix. Put another way, attackers exploited roughly four already-patched vulnerabilities for every vulnerability for which defenders had no patch. That should change how organizations think about vulnerability risk.

Zero-days deserve attention precisely because conventional patch management can't stop them. But they remain the minority of known exploited vulnerabilities in this dataset. The much larger problem is brutally familiar: patches exist, but vulnerable systems remain exposed.

A 9.8 isn't necessarily a 9.8

There's another finding buried deeper in the research that could ultimately matter more than the AI argument.

Attackers don't distribute their attention evenly.

They repeatedly target particular vendors and vulnerability classes, and their exploitation speed can vary dramatically depending on what they're attacking.

For 2026 n-days, for example, Root Evidence calculated an 11-day median exploitation window for Cisco vulnerabilities, compared with 31 days for Microsoft and roughly 225 to 235 days for Oracle, SonicWall and D-Link vulnerabilities represented in the analysis.

That creates an obvious problem with vulnerability programs built primarily around severity scores. Two vulnerabilities can both carry a CVSS score of 9.8 while facing radically different historical patterns of attacker interest.

Jeremiah Grossman, CEO of Root Evidence, makes essentially the same argument in an accompanying essay: vulnerability management needs to become more specific about which vendors and vulnerability classes attackers actually target rather than assuming an identical severity score represents identical risk.

That's where the report moves beyond another debate over whether AI is overhyped.

The Vulnpocalypse may be happening on the defender side

Root Evidence's research doesn't prove AI won't radically accelerate offensive security. It explicitly doesn't make that claim.

Nor is the dataset a perfect representation of every attack. The researchers acknowledge that exploitation dates are based on when activity was publicly recorded rather than necessarily when exploitation first began. Recent years remain incomplete, 114 same-day cases could not be definitively classified, and CISA KEV and VulnCheck KEV inherently favor severe and well-documented exploitation.

But even with them, the report poses an uncomfortable question for vulnerability management programs.

What happens if AI dramatically increases the number of vulnerabilities defenders can discover without proportionately increasing the number attackers actually exploit? Traditional vulnerability management gets worse.

Teams already struggling to remediate everything their scanners identify will receive even more findings. Severity-based queues grow. Backlogs expand. Engineers spend more time fixing vulnerabilities attackers may never touch while genuinely dangerous exposures compete for the same resources.

In that sense, AI doesn't need to create armies of autonomous attackers weaponizing zero-days within minutes to produce a Vulnpocalypse.

It only needs to make vulnerability discovery cheap enough that finding vulnerabilities scales faster than organizations' ability to understand which ones matter.

Root Evidence's own accompanying commentary takes that argument one step further: eventually prioritization may not simply mean deciding what to remediate first. Organizations may have to decide what vulnerabilities are worth looking for in the first place. That's the part of this report security leaders should pay attention to. The vulnerability management problem was never really about how many vulnerabilities exist.

It's about figuring out which ones are most likely to hurt you — and getting there before the attackers do.

HOU.SEC.CON CTA

Latest