www.infosecurity-magazine.com Surge in Exploitation of Vulnerabilities in 2026
Article Content
- •32.1% of vulnerabilities were exploited before detection in the first half of 2025.
- •Microsoft and Cisco were among the top targeted vendors for vulnerabilities.
- •The rise in zero-day exploitation emphasizes the need for improved threat intelligence.
In 2026, threat actors increasingly exploit vulnerabilities, with a significant rise in exploitation. A report by VulnCheck indicates that 32.1% of vulnerabilities in the Known Exploited Vulnerabilities (KEV) catalog were weaponized before detection or within 24 hours of disclosure. This marks a 8.5% increase from the previous year. The first half of 2025 saw 432 new vulnerabilities added to the KEV list, already surpassing half of the total CVEs exploited in 2024. Major targets include Microsoft and Cisco, with a notable focus on content management systems and network edge devices. The trend highlights the growing urgency for organizations to enhance their threat intelligence capabilities and response strategies against fast-evolving threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track S1ngularity/nx and Cisco in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What percentage of vulnerabilities are exploited quickly?
Which vendors are most targeted?
How can organizations improve their defenses?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…