cybersecurity
education
€ EUR
  • $ USD
  • € EUR

The Problem of 35,800 Vulnerabilities: Why Your CVSS Score is Lying to You

If you feel like you’re drowning in vulnerability alerts, you’re not alone and you’re not imagining it.

by Kajetan Porwolik, CQURE Threat Hunting Expert

In the first half of 2026, nearly 36,000 CVEs were published. That’s a 49% jump from the year before. But here’s the twist that should change your entire security strategy: Fewer than 500 were actually exploited in the wild.
We have a massive vulnerability problem, but a much smaller action problem. The traditional model of treating every “Critical” CVSS score as a five-alarm fire is broken. It’s impossible to keep up, and frankly, it’s the wrong strategy.

Why CVSS Isn’t Enough?

A CVE might affect hundreds of assets, but the impact is rarely the same. A critical flaw on an isolated, air-gapped server is a very different beast than the same flaw on a public-facing, business-critical database.
CVSS gives you a generic severity baseline, but it cannot tell you:
If the asset is actually reachable?
If your existing security controls block the exploit?
If the business relies on that specific system to function?

You need evidence from your environment, not just a global score.

The New Standard.

To cut through the noise, leading security teams are moving toward a unified validation program. It’s not about replacing one tool; it’s about combining three distinct methods to get a definitive answer on what is actually exploitable.

Exploitability Validation: This determines if an exposure is real, even for CVEs with no public exploit yet. It covers the blind spots where you can’t safely run a live test (like on critical or restricted assets).
Security Control Validation: This shows whether your firewalls, EDR, and other defenses can actually stop the attack.
Agentic Pentesting: This safely runs real exploits to chain vulnerabilities together and show you exactly how far an attacker could move through your network.

Stop Chasing Ghosts.

The gap between disclosure and exploitation is narrowing. Attackers are using AI to speed up their process, and defenders need to match that speed with precision, not panic. The goal isn’t to patch everything. The goal is to validate what matters. By integrating exploitability checks, control validation, and automated pentesting into one workflow, you stop guessing and start making decisions based on evidence.

This article is based on: AI Changed the Exposure Problem. Validation Needs to Change With It., published by The Hacker News.
Read the original article on The Hacker News

Want to learn more?

Join our FREE live webinar:

Uncovering New Identity Theft Vectors and How to Mitigate Them

Discover how identity theft no longer begins and ends with a stolen password.

Paula Januszkiewicz (CEO of CQURE and CQURE Academy, Cybersecurity Expert & Red Teamer, Microsoft Regional Director, MVP, and MCT) will unveil new identity attack paths, including original research from the CQURE Team demonstrating how an attacker can move from endpoint access to cloud identity takeover, compromise sensitive user secrets, gain access to protected resources such as KeePass, and evade traditional EDR/XDR visibility.

Register for free:
👉 https://luma.com/TheftVectors

You may also be interested in:

How can we help you?

Suggested searches

    Search history

      Popular searches:

      Not sure what course to look for?

      Mobile Newsletter Form