Site navigation

Zero-Day Pressure Mounts as Newly Exploited Flaws Jump 20%

Tom Quinn

,

2026 CVEs, CISA vulnerabilities 2025
Cyber researchers are warning that the pace of known exploited vulnerabilities is accelerating heading into 2026, with ransomware groups weaponising flaws faster than ever.

The US cybersecurity agency CISA added 245 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue last year, a 20% surge in exposed flaws that intensified the malicious activities of ransomware gangs.

An analysis of CISA’s KEV list by cybersec firm Cyble revealed that while the agency removed at least one vulnerability from its catalogue in 2025 (a Velociraptor Incorrect Default Permissions flaw), the database has grown to a staggering 1,484 software and hardware security gaps at high risk of attack.

Last year saw the steepest rise in known vulnerabilities since CISA launched the database in 2021, outpacing the 187 added in 2023 and 185 in 2024, a trend which Cyble’s analysts said was likely to continue into 2026 based on a spike in exposed vulnerabilities in recent weeks.

Cyble researchers previously cautioned that new vulnerabilities were emerging at twice the long-term rate in the last weeks of the year, with many already having a publicly available Proof-of-Concept that increased the likelihood of real-world attacks.

Among the most prominent common weakness enumerations (CWEs) found by Cyble were Out-of-bounds Write (CWE-787), Cross-site Scripting (CWE-79), and Code Injection (CWE-94), new to the list but appearing in significant numbers in 2025.

“The persistently high number of new vulnerabilities observed in recent weeks is a worrisome new trend as we head into 2026,” the cyber firm warned.

“More than ever, security teams must respond with rapid, well-targeted actions to patch the most critical vulnerabilities and successfully defend IT and critical infrastructure.”

But even as organisations move to reinforce their cyber defences, Cyble’s findings suggest that malicious actors can just as quickly identify fresh openings to abuse.

Of the vulnerabilities added last year, 24 were marked by CISA as being actively exploited by ransomware groups, including high‑profile flaws like CitrixBleed 2 (CVE-2025-5777), and weaknesses in the Oracle E‑Business Suite, previously exploited by the notorious CL0P gang.


Recommended reading


Attackers have also taken advantage of newly exposed vulnerabilities in Microsoft Sharepoint, Fortinet’s FortiOS, and Ivanti Connect Secure, all systems routinely used by enterprise firms.

According to Cyble, Microsoft remains the most frequently listed vendor in CISA’s database, with 39 vulnerabilities logged for the tech giant in 2025, up from 36 the previous year, far ahead of Apple in second position, which saw just nine additions.

Meanwhile, in a faint silver lining, several vendors saw the number of vulnerabilities affecting them fall last year, including the likes of Adobe, Android, Apache, Ivanti, and Palo Alto Networks, which Cyble said suggests improvements to security controls.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data