
At the start of 2026, Hadrian’s Offensive Security Benchmark Report argued that the traditional vulnerability management timeline was breaking down. Exploitation was increasingly beginning before or around the point a CVE was published, while security teams were still relying on processes built around disclosure, prioritization and remediation.
Six months later, the pressure on that model has increased. The number of published vulnerabilities continues to rise, the time available to investigate high-value exposures remains short, and widely used confirmation signals such as CISA’s Known Exploited Vulnerabilities catalogue can arrive well after exploitation has begun.
Vulnerability volume is still accelerating
Hadrian’s Exposure Clock tracks how quickly the public vulnerability landscape is changing. Across the first half of 2026, an average of 195 new CVEs were published every day. If that rate continues, 2026 is on pace for approximately 71,314 published CVEs.
The pace increased again in July, when 9,771 CVEs were published in a single month, the highest monthly total on record. The longer-term trend is similar: CVE submissions increased 263% between 2020 and 2025, according to NIST.
A larger number of CVEs does not mean that every organization has proportionally more exploitable risk. Many vulnerabilities affect products an organization does not use, systems that are not externally reachable or configurations in which exploitation is not possible. The challenge is that security teams still need to work through an increasingly large pool of disclosures to determine which ones are relevant.
Some of the information normally used to make that decision is also incomplete. The Exposure Clock data shows that 15% of incoming CVEs to the National Vulnerability Database still arrive without enrichment, leaving gaps in the severity, affected-product and contextual information that vulnerability-management teams commonly use for prioritization.
Based on the first-half rate, the Exposure Clock calculates that a new potential exposure enters the public vulnerability landscape approximately every four minutes. For security programs that depend heavily on periodic assessments, that means the environment they tested may not have changed, but the set of vulnerabilities that could affect it continues to expand between assessments.
Exploitation can begin before defenders have a reliable signal
Hadrian’s 2026 benchmark cited VulnCheck data showing that 32.1% of Known Exploited Vulnerabilities in 2025 had evidence of exploitation on or before the day the associated CVE was published, compared with 23.6% in 2024. The report associated much of this activity with internet-facing technologies such as VPNs, firewalls and gateways, where attackers can continuously scan for newly exploitable weaknesses.
Zero Day Clock tracks the same broader issue using a different dataset. Its published timeline shows median time from vulnerability disclosure to observed exploitation falling from 771 days in 2018 to 84 days in 2021, around six days in 2023 and four hours in 2024, with its analysis showing exploitation increasingly occurring before disclosure by 2025.
The figures come from different datasets and should not be treated as directly comparable, but they point to a similar operational problem. Security teams cannot assume that publication creates a predictable period in which they can investigate a vulnerability before attackers begin using it. For exposed systems that are actively targeted, exploitation may already be underway by the time the vulnerability becomes part of a normal patching workflow.
KEV confirmation can come much later
CISA’s Known Exploited Vulnerabilities catalogue is one of the most useful signals available to defenders because it identifies vulnerabilities with reliable evidence of exploitation in the wild. It is also, by design, a confirmation mechanism rather than an early-warning system.
Hadrian’s Exposure Clock records a median period of 57 days between vulnerability disclosure and a KEV exploitation listing. That figure does not mean exploitation begins 57 days after disclosure. Hadrian’s benchmark already shows that, for a meaningful share of exploited vulnerabilities, activity starts on or before the publication date.
This creates a difficult prioritization problem. Waiting for KEV inclusion can provide greater confidence that a vulnerability is being used by attackers, but for some vulnerabilities that confirmation arrives after the organization needed to decide whether the issue affected its environment. Treating every newly published vulnerability as an emergency creates the opposite problem, because the disclosure volume is too large for most teams to investigate and remediate indiscriminately.
Point-in-time assessments have a shorter useful life
A penetration test can provide a detailed view of what was exploitable when the assessment took place. It cannot account for vulnerabilities that have not yet been discovered or disclosed.
Hadrian’s Exposure Clock makes that gap visible by allowing a security team to enter the date of its last assessment and see how many CVEs have been published since then. The tool then narrows that population to vulnerabilities with a Network attack vector and those subsequently added to CISA’s KEV catalogue.
Neither filter proves that an organization is vulnerable. A Network attack vector indicates that remote exploitation may be possible, but it does not establish whether the affected software exists in the environment or whether the vulnerable component is externally reachable. KEV inclusion confirms exploitation in the wild, but an organization still needs to determine whether the vulnerable technology is present and exposed.
The work therefore sits between public vulnerability intelligence and the organization’s own attack surface. For each potentially relevant vulnerability, security teams need to establish whether the affected technology is present, whether an attacker can reach it, whether the necessary conditions for exploitation exist and what access successful exploitation would provide. As hundreds of new CVEs are published each day, those questions have to be answered repeatedly rather than only during a periodic assessment.
Patching faster cannot compensate for poor prioritization
For vulnerabilities affecting exposed and business-critical systems, faster remediation remains important. Hadrian’s benchmark found that critical verified exposures had a median remediation time of four days, suggesting that organizations can move quickly when the risk is clear.
The problem is deciding which findings deserve that level of urgency. Hadrian’s analysis found that only 0.47% of risks detected by vulnerability scanners in its dataset ultimately proved exploitable and required action. The figure comes from Hadrian’s own analysis across more than 300 organizations and should not be interpreted as a universal false-positive rate for vulnerability scanners.
It does show why vulnerability volume and attacker speed create a prioritization problem. A CVE record can establish that a weakness exists in a product, while a severity score can describe its potential technical impact. Neither establishes that an attacker can reach and exploit that weakness in a particular organization.
The Offensive Security Benchmark Report therefore recommended validating exploitability in real-world conditions and prioritizing remediation according to actual exposure. Hadrian’s agentic offensive security platform applies the same principle by continuously discovering internet-facing assets and testing whether identified weaknesses can be exploited, giving security teams evidence about which findings represent usable attack paths rather than relying on vulnerability presence alone.
The first half of 2026 has made that distinction harder to ignore. With roughly 195 new CVEs published each day, a potential exposure entering the public landscape every four minutes, and exploitation sometimes beginning before defenders receive a mature intelligence signal, security teams need to reduce the time between a new vulnerability appearing and knowing whether it creates a real risk in their environment.
See what has changed since your last pentest
If your last penetration test or security assessment was completed weeks or months ago, thousands of vulnerabilities may have been disclosed since it was carried out. Hadrian’s Exposure Clock shows how many CVEs have appeared since your assessment, how many may be remotely exploitable and how many have subsequently been associated with known exploitation.
Use the Exposure Clock to see how much the public vulnerability landscape has changed since your last pentest.




