VulnCheck reported that exploitation is moving faster in the first half of 2026, with the median time from CVE publication to inclusion in the Known Exploited Vulnerabilities (KEV) catalog falling from 120 days in 2025 to 80 days. The firm said about 200 CVEs were exploited within 31 days of publication, showing that early exploitation remained steady even as total CVE volume increased. Of 495 KEVs tracked in H1 2026, content management systems accounted for nearly one-third of cases, led by the WordPress plugin ecosystem, while network edge devices remained another heavily targeted category. The report also identified AI products as an emerging attack surface, including LangFlow flaws used for initial access, credential harvesting, cryptomining, and attempted lateral movement.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
On its publication, VulnCheck released its first-half 2026 exploitation report, concluding that AI-assisted vulnerability discovery was not producing disproportionately exploited flaws. The report said 14 of 1,061 AI-attributed vulnerabilities were confirmed exploited in the wild, roughly matching the broader exploitation rate.
CyberScoop says Microsoft’s July Patch Tuesday included a record 622 vulnerabilities, following 206 in June. The article presents this as a possible indicator that AI-assisted discovery may increase disclosure volume later in 2026.
CyberScoop reports that Microsoft disclosed 206 vulnerabilities in its June Patch Tuesday release. The figure is cited as part of a broader rise in disclosure volume that could reflect AI-driven vulnerability discovery.
The reporting says major AI vulnerability-hunting systems including Anthropic’s Project Glasswing, Microsoft’s MDASH, and OpenAI’s Daybreak launched in April or May 2026. The article cites these launches as too recent to judge their longer-term impact on exploitation trends.
VulnCheck reported that in the first half of 2026, the median time from CVE publication to KEV status fell to 80 days from 120 days in 2025, while about 200 CVEs were exploited within 31 days of publication. The analysis also found content management systems, especially WordPress plugins, remained the most targeted category and identified AI products as an emerging attack surface.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceinfosecurity-magazine.com
Open sourcecyberscoop.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.