FIRST says 2026 could bring more than 50,000 new CVEs

March 23, 20262 min read2 sources
Share:
FIRST says 2026 could bring more than 50,000 new CVEs

FIRST, the Forum of Incident Response and Security Teams, is forecasting that annual vulnerability disclosures could top 50,000 CVEs this year, according to reporting by Infosecurity Magazine. If that happens, it would set a new high for the Common Vulnerabilities and Exposures program, which assigns standardized IDs to publicly disclosed security flaws.

The forecast points to continued growth rather than a one-off spike. CVE volume has climbed steadily as software supply chains have expanded, bug bounty and coordinated disclosure programs have matured, and automated testing tools have made it easier to find flaws across applications, firmware, cloud services, and embedded systems. FIRST, which operates the CVE program, says the trend suggests this year could break prior records for newly disclosed issues.

The number matters because CVEs are the starting point for vulnerability management across scanners, advisories, patching systems, and threat intelligence feeds. A higher count does not automatically mean attackers are exploiting more flaws, but it does increase the workload for defenders that already struggle with patch backlogs and incomplete asset inventories.

For security teams, the bigger problem is prioritization. Not every CVE is severe, and not every severe flaw is exploited in the wild. That is why many organizations increasingly pair CVE tracking with CVSS scores and CISA's Known Exploited Vulnerabilities catalog to decide what to patch first. As disclosure volume rises, that filtering becomes more important than raw counts alone.

The forecast also lands amid broader strain on the vulnerability ecosystem. The National Vulnerability Database has faced processing delays, and vendors continue to issue advisories at a pace that can overwhelm smaller teams. A record year for CVEs would add pressure on enterprises, software makers, and managed security providers to automate more of their remediation and exposure-management workflows.

In practice, the 50,000-CVE milestone is less a signal of sudden collapse than a measure of how much code, connectivity, and scrutiny now exists across the technology stack. For defenders, the takeaway is straightforward: more findings are coming, and the ability to separate noise from urgent risk will matter more than ever.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16