Skip to content

Build1 publisher2 min readPublished

Exploitation beat CVE publication for about 256 vulnerabilities last year

VulnCheck logged 884 vulnerabilities with first-time exploitation evidence in 2025, and 28.96% of them were already being exploited by the day their CVE appeared, up from 23.6% a year earlier. The same report calls the year's timing highly consistent with 2024.

The Engineer · Build desk

Illustration accompanying Exploitation beat CVE publication for about 256 vulnerabilities last year

What happened

  • VulnCheck says it identified 884 vulnerabilities during 2025 that showed evidence of exploitation for the first time, and added each of them to its own KEV catalog.
  • Of those, 28.96% showed exploitation evidence on or before the day their CVE was published, up from the 23.6% VulnCheck reported in its 2024 trends analysis.
  • VulnCheck also says it flagged exploitation significantly earlier than CISA KEV in the majority of cases, sometimes by days and sometimes by months or years.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A remediation SLA measured from CVE publication can only act on the interval it can see, and for about 256 of last year's cases that interval opened at or below zero.
  • contradiction The same report carries a 5.36-point rise and a statement that 2025's timing was highly consistent with 2024, so the year-over-year delta cannot carry a trend argument on its own.
  • decision Teams whose change process gates on CISA KEV have to choose between ingesting a second exploitation feed and accepting the lead time VulnCheck claims over that catalog.
  • exposure An estate of internet-facing appliances and CMS installs is the one this base rate describes; a fleet without them should not plan its exposure window against 29%.

The percentage is the distance between two dates. VulnCheck uses CVE publication as a proxy for the day defenders gain awareness of a vulnerability [4]. The comparison date is the first public report of exploitation evidence. Neither one is the day the attack began.

That second date comes out of an observation network, and the network changed during the year. VulnCheck counted 118 organizations that were first to publicly report exploitation activity in 2025, with hundreds more corroborating [6]. Shadowserver was still the leading first reporter [9]. CrowdSec was onboarded as a new source and scaled significantly over the year [10], and VulnCheck's own first-report count rose after it launched Canary Intelligence [11]. A larger sensor set finds evidence sooner, and evidence found sooner is dated sooner. Cases that used to land a few days after publication land on or before it.

Now the arithmetic on the move itself. The share rose 5.36 points [5]. Applied to 884 vulnerabilities, 28.96% is about 256 [1]; last year's 23.6% applied to the same 884 would be about 209 [2]. That is a gap of roughly 47 vulnerabilities across twelve months [3], one every eight days [4]. VulnCheck wrote that time-to-exploitation patterns "remained highly consistent with 2024, indicating stable and sustained attacker behavior" [8]. The takeaway bullet that carries the 28.96% figure ends "underscoring the persistence of rapid exploitation" [17], with the proxy caveat left back in the methodology [4].

For 29% to describe your own portfolio, your exposed inventory has to resemble the population VulnCheck was watching. That population was led by network edge devices including firewalls, VPNs and proxies, then content management systems, then open source software [5]. VulnCheck says attackers kept focusing on internet-facing and widely deployed technology while opportunistically hitting a long tail of enterprise software, hardware and emerging technology such as AI [15], and that the activity spanned hundreds of vendors and products, broader than public KEV catalogs alone [12]. A fleet with no internet-facing appliance in it draws from a different distribution.

Roughly 256 of last year's first-time exploited CVEs [1] had their clock running at or before the moment a publication-keyed SLA starts counting. VulnCheck's stated recommendation is to act quickly on newly disclosed vulnerabilities while continuing to reduce long-standing backlogs [13]. If your change process gates on CISA KEV, add whatever lead time VulnCheck holds over that catalog: it says it was significantly earlier in the majority of cases, often by days, months or even years [7]. VulnCheck KEV is a free community service, and during 2025 it added email and Slack alerting [14].

What to watch

  • Whether VulnCheck's next report separates the effect of newly onboarded first-reporting sources from any change in attacker timing.
  • Ransomware attribution for CVEs exploited in 2025, which VulnCheck expects to keep growing as more research is published.
  • Whether CISA KEV narrows the lead time VulnCheck says it holds over that catalog.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories