Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility
New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking.
The global interconnectivity of business, and the systems and software it uses, has elevated the supply chain and supply chain threats to a preeminent cybersecurity concern. A particular issue is that many organizations are unaware of their position within a supply chain and can be victimized through no active fault of their own.
The 2026 supply chain vulnerability report from Black Kite leads with the statement, ‘velocity without visibility is the new supply chain crisis’. Its analysis offers three primary takeaways:
- more than 48,000 CVEs were published in 2025
- the time to exploitation is now a negative number
- only 58 of the CVEs are identified as posing a genuine, discoverable, and exploitable threat to enterprise supply chains.
The first takeaway is a matter of record. The second is a conclusion...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE