Security researchers have warned that more than 50,000 new Common Vulnerabilities and Exposures (CVEs) will be identified for the first time this year, with security teams cautioned to prepare for even more extreme scenarios.
In its 2026 Vulnerability Forecast, the Forum of Incident Response and Security Teams (FIRST), a cybersec non-profit, predicts that 59,427 new CVEs will be discovered this year, up from more than 49,100 published in 2025.
But while FIRST’s central estimate puts 2026 CVEs over the 50,000 mark, the report warns that realistic scenarios could push the total between 70,000 and 100,000, with the upper range of its projection sitting at nearly 118,000 – a number that would represent a “paradigm shift” in vulnerability management.
This could signal the beginning of rapid growth, with FIRST’s three-year outlook forecasting nearly 193,000 CVEs published by 2028 under extreme scenarios.
“The question organisations need to ask right now is: are my people and processes ready to handle this volume, and am I prioritising the vulnerabilities that actually put my data at risk?” said Éireann Leverett, lead member of FIRST’s Vulnerability Forecasting Team.
FIRST’s model, based on historical CVE records and publication trends from the National Vulnerability Database (NVD) and MITRE, predicted between 41,000 and 50,000 new CVEs in 2025, with the actual count falling towards the upper bounds of this range.
In 2024, however, FIRST underestimated the number of disclosures by more than 6,000, a pattern which, if it holds in 2026, would push CVEs closer to the report’s high‑end estimate, an unsettling scenario for those charged with patching, detecting, and managing vulnerabilities.
Recommended reading
- Less than Half of All Exploitable Vulnerabilities Get Fixed
- Commercial Codebases Leave Gaping Vulnerabilities
- Cracks in CVE Program Risking Security “Blind Spots”, Warns Report
However, FIRST stressed that security teams should use these figures to plan for a spectrum of possible outcomes, including planning patching capacity, coordinating vulnerability disclosure reports with vendors, and developing detection signatures for SIEM, EDR, or IDS platforms.
“Much like a city planner considering population growth before commissioning new infrastructure, security teams benefit from understanding the likely volume and shape of vulnerabilities they will need to process,” said Leverett. “The difference between preparing for 30,000 vulnerabilities and 100,000 is not merely operational, it’s strategic.”
With a potentially record-breaking year ahead, FIRST recommended that organisations begin to assess whether their people and processes can handle 50,000+ CVEs, build contingency plans for higher-volume scenarios, and focus on vulnerabilities that pose the greatest risk to their specific environment.





