Wed, Sep 2

So you don’t believe there’s a Vulnpocalypse?

My friend Andrey Lukashenkov of Vulners follows the CVE news very carefully. Yesterday, he put up this post on LinkedIn. I summarize it this way: Every software developer and user should know by now that the threat of unpatched software vulnerabilities is rapidly increasing. There are two reasons for this:

1.      AI makes it much easier for researchers to identify vulnerabilities.

2.      AI makes it much easier for the bad guys (and women, of course!) to exploit those vulnerabilities to hack into systems worldwide.

Andrey doesn’t just display a graph – he does those regularly. Instead, he makes these points (I’ve interpolated a few of them):

1.      There were over 12,000 new CVE records created in August. This was once again an all-time record (I believe just about every month has set a new record this year). This was three times the number reported in January.

2.      172 CNAs (CVE Numbering Authorities) reported at least one new CVE in August; as of September 2, 2026, there are 544 CNAs.[i]

3.      As always, a small number of CNAs report most of the new vulnerabilities. For a long time, the most prolific CNAs were big developers like Microsoft, Red Hat, IBM and Oracle, that were reporting vulnerabilities in their own software. However, this year the most prolific CNAs are organizations that report vulnerabilities in software they didn’t write.

4.      In August, the three top CNAs were GitHub, VulnCheck, and the Linux Foundation (which reports vulnerabilities in the Linux kernel, as well as in some products based on Linux). To be clear, no CNA is paid to report vulnerabilities. Andrey noticed that those three CNAs reported more vulnerabilities than did all CNAs (including those three) in January.

5.      One fact I noticed was that, if the number of new CVEs reported every month remains at the level it was in August (12,000+), there will be close to 150,000 vulnerabilities reported in the next 12 months. That is well over one third of the 360,000+ vulnerabilities reported since the CVE program started in 1999. However, it’s certain the monthly totals will continue to grow, and most likely at or above the current rate.

If you don’t believe there’s a Vulnpocalypse (and I admit I was initially skeptical of the idea), you need to believe in it now.

Tom Alrich’s Blog, too is a reader-supported publication. You can view new posts for three months after they come out by becoming a free subscriber. You can also access all of my 1300 existing posts dating back to 2013, as well as support my work, by becoming a paid subscriber for $30 for one year (and if you feel so inclined, you can become a founding subscriber for $100). Whether free or paid, please subscribe. 

If you would like to comment on what you have read here, I would love to hear from you. Please comment in my chat or email me at [email protected].


[i] If you don’t know what a CNA is and why they’re important, see this post.

1