Back Morningstar VulnCheck Exploit Intelligence Report Separates Real-World Exploitation Activity ...
VulnCheck Exploit Intelligence Report Separates Real-World Exploitation Activity from Theoretical Vulnerability Risk
Analysis Finds 1% of Vulnerabilities Were Exploited in the Wild in 2025 and Identifies the 50 Most Routinely Targeted Flaws of Last Year
VulnCheck , the exploit intelligence company, today released the 2026 VulnCheck Exploit Intelligence Report (VEIR), a first-of-its-kind analysis of real-world exploitation trends and attacker behavior, along with its inaugural list of the 50 most routinely targeted vulnerabilities of the past year. By separating vulnerability disclosure data from confirmed exploitation, the report is designed to help security teams prioritize remediation based on operational risk instead of raw volume.
The VEIR shows that while CVE disclosures and public proof-of-concept code increased significantly in 2025, just 1% of vulnerabilities were confirmed to be exploited in the wild, with a small subset driving disproportionate real-world impact. The report is based on data from over two dozen unique VulnCheck indices , more than 500 data sources and proprietary first-party intelligence. It examines attacker behavior and which vulnerabilities drove confirmed compromise during a year marked by AI-generated exploit code, geopolitical tension and uncertainty surrounding core vulnerability programs.
“The data shows that exploitation is concentrated in a very small number of vulnerabilities, but those vulnerabilities are being weaponized faster and at greater scale,” said Jacob Baines, Chief Technology Officer, VulnCheck. “At the same time, the volume of exploit content, much of it AI-generated slop, is making it harder to distinguish real operational risk from background noise.”
In 2025, VulnCheck tracked more than 14,400 exploits developed for 10,480 unique 2025 CVEs, a 16.5% year-over-year increase in same-year exploit coverage. Much of that growth was associated with AI-generated proof-of-concept code, including nonfunctional or misleading exploit content. Other key findings from the 2026 VEIR report include:
“Organizations are managing more disclosures than ever, but only a small fraction of those vulnerabilities see active exploitation,” said Caitlin Condon, Vice President of Research, VulnCheck. “The difficulty is identifying that fraction early enough to act. This analysis focuses on confirmed exploitation trends to improve prioritization decisions. ”
The report also includes VulnCheck’s first-ever Routinely Targeted Vulnerabilities list, a rankable set of 50 CVEs disclosed and exploited in 2025 that demonstrated sustained attacker interest. The list is also available separately, along with associated metadata. See the full list here: .
The 2026 VulnCheck Exploit Intelligence Report is available here: .
Media: Jason Vancura Marketbridge for VulnCheck vulncheck@marketbridge.com
View source version on businesswire.com:
The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.
Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.
Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
