By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CVE volumes may plausibly reach 100,000 this year | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > CVE volumes may plausibly reach 100,000 this year | Computer Weekly
News

CVE volumes may plausibly reach 100,000 this year | Computer Weekly

News Room
Last updated: 2026/02/11 at 8:52 PM
News Room Published 11 February 2026
Share
CVE volumes may plausibly reach 100,000 this year | Computer Weekly
SHARE

The total number of common vulnerabilities and exposures (CVEs) disclosed in 2026 is set to romp past the 50,000 mark in 2026 and may plausibly run as high as six figures for the first time ever, according to the Forum of Incident Response and Security Teams’ (First’s) annual Vulnerability Report.

In its latest set of predictions, First said that this year, the upper bounds of its 90% confidence interval in fact approaches 118,000 CVEs, and according to the data, realistic scenarios suggest 70,000 to 100,000 disclosed vulnerabilities are “entirely possible”. The median figure for 2026, it said, would most likely be around 59,000.

First said that whatever the figure turns out to be, it underscored an “urgent need” for organisations to both scale their security ops and strategically prioritise their vulnerability response and patching practices.

“The question organisations need to ask right now is: are my people and processes ready to handle this volume, and am I prioritising the vulnerabilities that actually put my data at risk?” said Éireann Leverett, first liaison and lead member of First’s Vulnerability Forecasting Team

“Our forecast allows defenders to stop reacting to every new CVE and start making strategic decisions about where to focus limited resources before attackers exploit the gaps.

The 50,000 vulnerability question

In its 2025 report, First said that the higher end of its predicted range topped out at 50,000 CVEs – the number its analysts expect to comfortably exceed this year. This was partly due to the rapid adoption of open source software (OSS) and the use of AI tools both in vulnerability discovery  During the course of the year, the emergence of the vibecoding phenomenon likely also had an impact.

In the event, First’s prediction was bang on, Leverett revealed, tipping over the upper confidence mark on 31 December 2025 for a final total of 49,972 observed CVEs, just 28 short of the magic number.

However, ideally, the upper confidence point would fall somewhere in 2026, with the median confidence point falling on New Year’s Eve, and as a result, First has reviewed its approaches and methodology going forward. Whether or not this means its 2026 forecast will be even more accurate remains to be seen.

“[Our] new method of forecasting … allows for asymmetric confidence intervals. This means we are taking into account that the publication number is more likely to exceed last year than be less than last year,” Leverett told Computer Weekly.

“So while we expect the number to be closer to 60,000, there is a 10% chance it exceed 118,000. Most of this is just statistics, but there is also discussion about emerging technologies and how they might stretch the range of possible numbers, which meant we were more comfortable publishing the results of this modelled outcome than some others.”

Next steps

While at first glance First’s annual CVE report might seem just an interesting statistical marker, the forecast serves as a potentially critical planning tool for the security sector when it comes to planning patching capacity, writing coordinated disclosures, or developing new detection signatures for SIEM, EDR or IDS platforms.

“Much like a city planner considering population growth before commissioning new infrastructure, security teams benefit from understanding the likely volume and shape of vulnerabilities they will need to process,” said Leverett.

“The difference between preparing for 30,000 vulnerabilities and 100,000 is not merely operational, it’s strategic.”

Whether they end up facing 50,000 or 100,000 CVEs and always keeping in mind that not every flaw will affect every business, security leaders at end-user organisations can start the work to get out in front of the problem right now.

A strong jumping off point is to assess whether the organisation has the people, processes, and capacity to handle so many issues. A well-prepared CISO will have prepared for the median forecast but will also have built contingency plans for the higher-volume scenarios.

Security pros also need to master the art of ruthless prioritisation, focusing on the flaws that pose the greatest risk to their specific IT estates, and not just those with the most critical CVSS numbers.

Finally, leaders should leverage external vulnerability forecasts alongside their own asset inventories to make vendor- and product-specific preparations.

“No company can solve vulnerabilities and cyber security in isolation. The organisations that recover fastest are the ones with trusted networks already in place, sharing threat intelligence and coordinating response before a crisis hits,” said First CEO Chris Gibson.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article How To Start Your Car When The Key Fob Battery Is Dead – BGR How To Start Your Car When The Key Fob Battery Is Dead – BGR
Next Article Threads’ new ‘Dear Algo’ feature lets you tell the algorithm what you want to see Threads’ new ‘Dear Algo’ feature lets you tell the algorithm what you want to see
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Remember James Van Der Beek by Streaming Dawson's Creek and His Other Roles
Remember James Van Der Beek by Streaming Dawson's Creek and His Other Roles
News
Anthropic vows to protect consumers from rising electricity costs –  News
Anthropic vows to protect consumers from rising electricity costs – News
News
Tencent hiring posts reveal new Unreal Engine 5 single-player game similar to Uncharted and Tomb Raider · TechNode
Tencent hiring posts reveal new Unreal Engine 5 single-player game similar to Uncharted and Tomb Raider · TechNode
Computing
Apple’s AirPods Are 22% Off With This Undeniably Sweet Deal
Apple’s AirPods Are 22% Off With This Undeniably Sweet Deal
News

You Might also Like

Remember James Van Der Beek by Streaming Dawson's Creek and His Other Roles
News

Remember James Van Der Beek by Streaming Dawson's Creek and His Other Roles

6 Min Read
Anthropic vows to protect consumers from rising electricity costs –  News
News

Anthropic vows to protect consumers from rising electricity costs – News

7 Min Read
Apple’s AirPods Are 22% Off With This Undeniably Sweet Deal
News

Apple’s AirPods Are 22% Off With This Undeniably Sweet Deal

4 Min Read
Best Samsung deal: Get a  credit when reserving a new Samsung Galaxy device
News

Best Samsung deal: Get a $30 credit when reserving a new Samsung Galaxy device

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?