Skip to content

Stop Chasing CVEs: Attackers Repeatedly Target a Surprisingly Concentrated Set of Vendors and Vulnerability Classes

The cybersecurity industry has spent decades getting better at finding vulnerabilities.

Security teams now have scanners that can discover thousands of vulnerabilities in minutes, databases that track hundreds of thousands of CVEs, scoring systems that assign a number to nearly every known flaw, and dashboards that turn the results into remediation queues.

Yet attackers do not treat that enormous CVE population as one giant pool of equally attractive targets.

For The Vulnpocalypse Report, we analyzed 253,912 CVEs published between January 2018 and July 2026. We found 3,769 CVEs with confirmed exploitation in the wild, which represents 1.48% of the total. We found no evidence of exploitation for the other 98.5% in the data we analyzed.

The 3,769 exploited vulnerabilities reveal another important pattern, which is that attackers repeatedly return to certain vendors and certain vulnerability classes.

Microsoft ranked first in n-day exploitation counts for nine consecutive years. OS command injection, path traversal and SQL injection have remained among the leading exploited vulnerability classes since 2018.

Attackers also exploit vulnerabilities in some vendors’ products much faster than others. In 2026, vulnerabilities in Cisco products had a median 11-day gap between patch availability and confirmed exploitation. Microsoft vulnerabilities had a 31-day median gap. Oracle, SonicWall and D-Link vulnerabilities in our analysis had median gaps of roughly 225 to 235 days.

Those numbers describe very different attacker behavior.

Attackers don't treat every CVE equally

Vulnerability management programs have traditionally treated every CVE as something that needs to be evaluated and ranked.

That approach made sense when organizations could keep their vulnerability backlogs small enough to manage. Today, security teams can face enormous numbers of findings, while attackers exploit only a small fraction of the vulnerabilities disclosed each year.

Attackers have already made many prioritization decisions for us. They have limited time and expertise. They reuse established tools and techniques. They pursue targets that offer a practical path to whatever they are trying to accomplish. When a technique works, attackers have little reason to abandon it.

Millions of attacks have produced a visible record of those choices. The same vendors keep appearing. The same vulnerability classes keep appearing. Attackers continue to find the same types of weaknesses useful.

Security teams should pay much more attention to those repeated choices.

A CVE is not an attacker decision

A CVE tells us that someone found and disclosed a vulnerability. It does not tell us that an attacker cares about it.

A vulnerability can have a high CVSS score, allow remote exploitation and affect a critical system. Attackers can still ignore it.

Another vulnerability with the same score can affect a vendor and vulnerability class that attackers repeatedly target.

A dashboard can make those two vulnerabilities look similar, but their histories and outcomes vary wildly.

CVSS describes characteristics of a vulnerability. It does not describe what attackers have actually done with that vulnerability or with similar vulnerabilities.

Security teams need both pieces of information.

Concentration matters

The CVE count can make the vulnerability problem look much larger than the exploitation problem.

The industry now tracks hundreds of thousands of vulnerabilities because that is the number researchers have disclosed. However, attackers use a far smaller population.

Some vulnerabilities attackers exploit are part of the larger CVE population. Most are not. Attackers narrow that population even further when they repeatedly select certain vendors and vulnerability classes.

The exploitation timelines make the vendor differences especially clear. Cisco and Microsoft vulnerabilities in the 2026 analysis were exploited much sooner after patch availability than Oracle, SonicWall or D-Link vulnerabilities.

That does not mean every Cisco vulnerability deserves immediate remediation or that every Oracle vulnerability can wait. It means attackers have demonstrated different levels of interest in vulnerabilities affecting those vendors, and security teams should include that history when they prioritize remediation.

The vulnerability-class data tells a similar story. OS command injection, path traversal and SQL injection have remained among the leading exploited classes across the period we studied.

Attackers are not discovering these weaknesses for the first time. They keep finding familiar vulnerabilities useful. Security teams can use that history instead of treating every CVE as an isolated event.

The n-day story matters here too

Attackers do not need a brand-new vulnerability to compromise an organization. Of the 3,769 confirmed exploited CVEs in our dataset, 3,058 had a patch available before exploitation and we classified those vulnerabilities as n-days. The remaining 711 were confirmed zero-days. Zero-days matter, but most of the exploitation we observed involved vulnerabilities that defenders already had an opportunity to fix. That makes attacker behavior especially useful for remediation.

When attackers repeatedly target a vendor, repeatedly exploit a particular vulnerability class and then find an unpatched instance, security teams have more information than a CVSS score provides. They have a history of actual exploitation.

That history shows what attackers have done in the real world.

We have been measuring the wrong population

For years, vulnerability management has focused on the population of vulnerabilities that exist. However, attackers work with a different population, which is the set of vulnerabilities they can use to accomplish something.

Some vulnerabilities attackers exploit are part of the larger CVE population, but most are not.

Vulnerability researchers continue to discover more flaws every year. The Vulnpocalypse data shows record CVE growth without a corresponding explosion in exploitation. During every complete year from 2018 through 2025, fewer than 2.2% of newly published CVEs had confirmed exploitation, even as annual CVE volume grew roughly 2.5 times.

Security teams should not respond to a growing CVE population by simply building bigger queues. A bigger queue does not tell a security team which vulnerabilities attackers repeatedly use. A larger scanner output does not tell a CISO where remediation will reduce the most risk.

Security teams need evidence about attacker behavior alongside the information they already collect about their own environments.

Follow the attackers

The exploitation record gives security teams something the CVE count cannot.

Researchers know which vulnerabilities attackers have exploited. They know when exploitation occurred. They know whether a patch existed. They can also see which vendors appear repeatedly and which vulnerability classes continue to show up in attacks.

The exploitation timelines also show that attackers do not behave uniformly across vendors. Cisco vulnerabilities had an 11-day median exploitation window in 2026, while vulnerabilities from Oracle, SonicWall and D-Link had median windows of roughly 225 to 235 days. A remediation program that treats those vulnerabilities primarily as CVSS scores throws away information about how attackers have actually behaved.

Security teams should use that information when they decide where to spend limited remediation time and resources. A vulnerability with no history of exploitation does not necessarily deserve the same attention as one that sits alongside a recurring pattern of attacker behavior. History may not repeat itself but it does rhyme as the saying goes. A vulnerability class that repeatedly gives attackers an effective path into organizations deserves more scrutiny than one that exists mostly as a theoretical possibility.

This approach does not require anyone to predict the future perfectly. It requires us to start with what attackers have already demonstrated. That means actuarial loss data, not theoretical scores that aren’t even in agreement with one another between whomever rates them.

As I said in the beginning, cybersecurity has spent decades getting better at finding more vulnerabilities. Now we need to get much better at recognizing the vulnerabilities attackers actually use.

Download a copy of The Vulnpocalypse Report for more details on this research

← All posts