Skip to content
🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Data page

CVE Trends 2026: why critical vulnerabilities went parabolic

For about four years, reported critical-severity vulnerabilities across 21 of the biggest software vendors never cleared roughly 100 a month. Since spring 2026 that line bends almost vertical, past 600 a month. Here is the data, the reason it bent, the caveat the authors themselves raise, and what a security leader should do about it.

010030050070020222023202420252026Critical CVEs / monthSpring 2026: the bend~100/mo for ~4 years600+/mo
Schematic of the trend in the a16z "Cyber Risk Goes Parabolic" chart (data via Epoch.ai, 3 Sep 2026), across 21 major vendors. The shape and anchor figures are from the published chart; intermediate points are illustrative, not a reproduction of every monthly value. The chart's authors note that reporting procedures and labelling vary between organisations, so part of the rise reflects faster disclosure, not only more bugs.
600+ /month

Critical-severity CVEs across 21 major vendors since spring 2026, up from under 100/month for the previous four years.

~2,200 /month

High-severity vulnerability reports at the 2026 peak across the same vendor set.

90+ zero-days

Found in production at customer sites in 2026 by one AI-driven offensive team (Kevin Mandia / Armadin), black-box from the internet.

What changed, in plain words

The honest reading has two parts, and they point the same way. AI has compressed the time it takes to find an exploitable flaw, for researchers and attackers alike, so more real vulnerabilities are surfacing. At the same time, disclosure has matured, so some of the rise is faster and better reporting rather than purely more bugs. The chart's authors say so explicitly, and keeping that caveat visible is the difference between data and hype.

The field data agrees on direction. Mandiant founder Kevin Mandia's venture Armadin reports finding more than 90 zero-days in production at customer sites in 2026, scanning black-box from the internet with no source code, using models post-trained with real red-teamers. Treat the specific numbers as that company's claims, not audited figures; treat the trend as real.

The leadership takeaway

Patch windows measured in weeks are now outrun by discovery measured in hours. Prioritise by exploitability, not raw count. Shrink and watch your external attack surface. And rehearse the "an outsider found remote code execution in our DMZ" call before it is real.

TL;DR

The surge in five lines

  • Reported critical-severity CVEs across 21 major software vendors held under ~100 per month for about four years, then bent sharply past 600 per month from spring 2026.
  • High-severity reports spiked toward ~2,200 per month at the peak. Source: a16z, using Epoch.ai data, published 3 September 2026.
  • The authors caution that reporting practices vary between organisations, so part of the jump is faster or better disclosure, not purely more bugs.
  • In parallel, AI is compressing time-to-find for exploitable flaws — Mandiant founder Kevin Mandia’s venture Armadin reports 90+ production zero-days found in 2026.
  • The leadership takeaway: patch windows measured in weeks are outrun by discovery measured in hours — prioritise by exploitability, shrink your external attack surface, and rehearse the call.

Frequently asked questions

Why have critical CVEs surged in 2026?

Two forces at once. First, AI is compressing the time it takes to find exploitable flaws — both for researchers and for attackers — so more real vulnerabilities are being discovered and reported. Second, disclosure practices have matured, so some of the measured rise is better and faster reporting rather than purely more underlying bugs. The a16z chart’s own authors flag this caveat. The shape of the curve and field reports from offensive-security teams agree that the discovery rate has genuinely accelerated.

What is the "Cyber Risk Goes Parabolic" chart?

A chart published by a16z (3 September 2026) using Epoch.ai data, plotting monthly critical- and high-severity CVE counts across 21 major vendors including Apple, AWS, Microsoft, Google, Cisco, Oracle and more. The critical line stayed under ~100 per month for roughly four years, then climbs past 600 per month from spring 2026; the high-severity line spikes toward ~2,200 per month.

What should a security leader do about it?

Stop counting raw CVEs and start ranking by exploitability and exposure. Measure and shrink your external attack surface, since AI-driven attackers scan it continuously. Shorten your detection-to-patch time for internet-facing and critical systems, and rehearse the "an outsider found remote code execution in our DMZ" call, because that is now a realistic 48-hour scenario rather than a tabletop hypothetical.

Is this a live feed of every CVE?

No. This page explains and visualises the 2026 surge from a specific, cited dataset, and tracks the figures PlayCISO has analysed. For scanning your own dependencies against known CVEs, use the free NPM Scanner and Package Scanner.

CVE Trends 2026 — Why Critical Vulnerabilities Went Parabolic · PlayCISO