Data shows the “Vulnpocalypse” is a myth — Only 1.5% of CVEs ever get exploited

https://cdn1.expresscomputer.in/wp-content/uploads/2026/07/23085230/AI-Security-AI-Attack.jpg

Security teams have long operated under a simple, anxiety-inducing assumption: every new CVE is a new fire to put out. A new report from vulnerability-management startup Root Evidence argues that assumption is wrong — and that the data has said so for years.

The company’s newly released “Vulnpocalypse Report” analyzed 253,912 CVEs published between January 2018 and mid-July 2026, cross-referencing them against confirmed exploitation data from CISA’s Known Exploited Vulnerabilities (KEV) catalog and VulnCheck KEV. The result: just 3,769 vulnerabilities — roughly 1.48% of the total — have ever been confirmed as exploited in the wild. The other 98.5% have not shown up in a real-world attack in the dataset Root Evidence examined.

That ratio has held remarkably steady. In every complete year from 2018 through 2025, the share of newly disclosed CVEs with confirmed exploitation stayed under 2.2% — even as the annual volume of published CVEs...

Copyright of this story solely belongs to www.expresscomputer.in. To see the full text click HERE