Newly disclosed CVSS 7 to 10 vulnerabilities accelerated exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Exploitation of newly disclosed CVSS 7 to 10 vulnerabilities surged 105% YoY, shrinking the time defenders have to react and patch. The median disclosure-to-CISA KEV inclusion window fell from 8.5 days to five days, while the mean dropped from 61 days to 28.5 days. Attackers are now turning exposure into weaponization in days, and in some cases, minutes, especially against unpatched edge infrastructure and other exposed services. The wave raises the risk of rapid compromise across multiple products and makes early patching and exposure reduction far more urgent.
Related Happenings
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score78
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
CERT-In 12-hour KEV remediation guidance
Advisory/Mitigation
H score39
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
About this happening:
CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...
CERT-In 12-hour KEV remediation guidance
Advisory/MitigationAbout this happening: CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector Action
H score38
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
About this happening:
CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector ActionAbout this happening: CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
Verizon 2026 DBIR shows vulnerability exploitation as the top breach access trend in 2025
Trend
H score39
First: 20.05.2026 03:04
Last: 20.05.2026 03:04
Sources 1
About this happening:
Vulnerability exploitation became the leading breach access vector in 2025, increasing compromise risk across 31,000 incidents and 22,000+ confirmed breaches. Un...
Verizon 2026 DBIR shows vulnerability exploitation as the top breach access trend in 2025
TrendAbout this happening: Vulnerability exploitation became the leading breach access vector in 2025, increasing compromise risk across 31,000 incidents and 22,000+ confirmed breaches. Un...
NIST CVE/NVD prioritization shift
Public Sector Action
H score35
First: 17.04.2026 00:47
Last: 17.04.2026 00:47
Sources 1
About this happening:
NIST is changing its CVE/NVD prioritization so that, starting April 15, 2026, it will provide full details only for a subset of CVEs. The shift matters because...
NIST CVE/NVD prioritization shift
Public Sector ActionAbout this happening: NIST is changing its CVE/NVD prioritization so that, starting April 15, 2026, it will provide full details only for a subset of CVEs. The shift matters because...
Timeline
-
18.03.2026 15:00 2 articles · 3mo ago
Rapid7 reports compressed disclosure-to-exploitation windows
Technical Analysis UpdateRapid7 reports that AI and automation accelerated exploitation in 2025, shrinking the median time from vulnerability publication to CISA’s Known Exploited Vulnerabilities (KEV) catalog from 8.5 days to five days and the mean from 61 days to 28.5 days. The same analysis says confirmed exploitation of newly disclosed CVSS 7 to 10 vulnerabilities rose from 71 in 2024 to 146 in 2025, while affected organizations faced faster weaponization of exposed services, weak identity controls, and unpatched edge infrastructure.
Show sources
- AI-Enabled Adversaries Compress Time-to-Exploit Following Vulnerability Disclosure — www.infosecurity-magazine.com — 18.03.2026 15:00
- AI-Enabled Adversaries Compress Time-to-Exploit Following Vulnerability Disclosure — www.infosecurity-magazine.com — 18.03.2026 15:00