
Security leaders already know that attackers are moving faster. But, it is harder to demonstrate what that change means for the technologies and processes their organisations depend on, and whether existing vulnerability-management cadences are still fast enough.
The growing number of published vulnerabilities provides part of the picture, but volume alone does not explain operational urgency. Teams also need to understand how frequently new vulnerabilities are being disclosed, how many may be remotely exploitable, and how quickly disclosed issues are recognised as actively exploited.
Together, these measures provide a clearer view of exposure velocity: the rate at which new vulnerability information accumulates and becomes relevant to defenders. Understanding this rate is becoming an increasingly important part of a broader threat exposure management programme.
Vulnerability volume is only the starting point
A vulnerability report is a snapshot taken at a particular moment. As new CVEs are disclosed and new vulnerabilities are added to CISA’s Known Exploited Vulnerabilities catalogue, that snapshot becomes progressively less complete.
This does not make periodic reporting obsolete. It does mean that monthly exports, annual assessments and occasional audits should not be the only mechanisms used to identify newly urgent exposures.
Security teams need to consider several dimensions:
- the number of CVEs disclosed during a given period;
- the average time between disclosures;
- how many vulnerabilities may be remotely exploitable;
- how many have been added to the KEV catalogue;
- and the interval between public disclosure and KEV inclusion.
The disclosure-to-exploitation interval should not be interpreted as the precise time at which exploitation began. CISA may add a vulnerability after exploitation has already been underway. It does, however, show how quickly a public vulnerability becomes a confirmed prioritisation concern for defenders.
Hadrian’s 2026 Offensive Security Benchmark Report highlights the wider problem: security teams are not short of vulnerability data, but frequently struggle to determine which findings represent real and immediate risk. This gap between visibility and proof creates what we describe as the verification crisis.
Moving from industry averages to technology-specific context
Industry-wide figures can demonstrate that vulnerability pressure is increasing, but every attack surface is different.
A company operating internet-facing firewalls, identity systems and remote-access infrastructure may face a different pattern of vulnerability urgency than one whose most important systems are internally isolated. The same is true of organisations using different vendors, software categories and legacy platforms.
Filtering disclosure data by vendor or technology therefore provides more useful context than relying only on an overall CVE count. Teams can examine whether vulnerabilities associated with particular parts of their stack:
- appear frequently;
- are commonly classified as exploitable over a network;
- repeatedly enter the KEV catalogue;
- or move from disclosure to confirmed exploitation concern unusually quickly.
These figures should not be treated as a vendor security score. Vulnerability counts are influenced by product footprint, researcher attention, disclosure practices and several other factors. They can, however, help teams ask better questions about monitoring, patching and compensating controls.
Public vulnerability intelligence provides the starting point. Determining whether an issue is actually present and exploitable requires an up-to-date understanding of the organisation’s assets and exposures. Continuous external exposure-management products such as Hadrian Atlas connect this changing intelligence to the systems an organisation exposes to the internet.
Evaluating the window since your last assessment
One practical way to use exposure-velocity data is to examine what has changed since a previous security assessment.
A pentest establishes what could be identified and validated within its assessment window. It cannot account for every vulnerability disclosed afterwards, new infrastructure introduced since the test, or changes that alter whether an existing weakness can be exploited.
By measuring the CVEs and KEVs published since that date, teams can see how much new public vulnerability information has accumulated while their environment has continued to change.
This can help security leaders:
- review developments since their last pentest;
- assess whether current patching and review cadences remain appropriate;
- identify vendors or technologies that warrant closer attention;
- and communicate the pace of change to internal stakeholders.
However, disclosure data alone cannot confirm that a vulnerability affects the organisation or provides a viable route into its environment. That requires direct testing and adversarial exposure validation to establish what an attacker could actually exploit.
Explore vulnerability trends with the Hadrian Exposure Clock
We built the Exposure Clock to make these trends easier to examine.
The tool allows security teams to explore CVE and KEV disclosures across selected timeframes, review the average interval between disclosures, identify vulnerabilities whose CVSS data indicates potential remote exploitation, and filter the results by relevant technologies.
It does not scan your systems or determine whether a particular vulnerability is present in your environment. Instead, it provides a clearer view of how the public vulnerability landscape has changed, and where more direct investigation may be warranted.
Explore the Exposure Clock to see what has been disclosed since your last assessment and examine how vulnerability velocity differs across the technologies you rely on.






