VulnCheck State of Exploitation 1H-2026
Key takeaways from VulnCheck’s analysis in the First Half of 2026 include: In the first half of 2026, 23.43% of KEVs showed evidence of exploitation on or before the day the CVE was published. A slight drop percentage wise from the 28.93% of KEVs we observed in 2025. At the same time, vulnerabilities appear to be being exploited faster, with the median time from CVE publication to KEV falling from 120 days in 2025 to 80 days during the first half of 2026. Exploitation activity early in the CVE lifecycle remained steady, with roughly 200 CVEs becoming exploited within 31 days in the first half of 2026. Early exploitation activity has not scaled at the same pace as CVE issuance. Content management systems remained the most targeted technology category, accounting for one-third of all KEVs, a more significant percentage of KEVs than we’ve seen historically.
During the first half of 2026, 79 unique sources were the first to report exploitation. The top six sources first to report include Patchstack (70 KEVs), CrowdSec (64 KEVs), ShadowServer (57 KEVs), VulnCheck (37 KEVs), Wordfence (20 KEVs), and CISA (19 KEVs).









