The rapid increase in CVEs and the growing prominence of networking gear KEVs are reshaping the vulnerability landscape. According to recent research, CVE growth has accelerated to 49 percent year on year, while KEVs linked to networking devices have climbed to 24 percent of the total. This highlights the focus keyword: networking gear KEVs.
Sharp Rise in CVEs and Changes in Exploitation Trends
In the second quarter of 2026, vulnerability researchers observed a marked change in the frequency and nature of software vulnerabilities. By the end of June 2026, close to 200 CVEs were being tracked per day, representing a significant 49 percent year-on-year increase. This continued the trend of steep annual growth seen in recent years, though the anticipated exponential surge has yet to materialise.
AI-related vulnerabilities are also on the rise. Using keyword analysis, researchers identified 452 AI-related CVEs reported in 2026 alone. When including the keyword “openclaw,” that number increased by another 536. This demonstrates how sensitive such counts are to evolving industry terminology, making it challenging to maintain consistent metrics for AI-related vulnerabilities over time.
KEVs: Slower Growth but Shifting Focus to Networking Gear
While the total number of CVEs surged, the number of vulnerabilities classified as Known Exploited Vulnerabilities (KEVs) grew by a comparatively modest 13 percent. With the exception of a small spike in April, KEV growth has remained relatively flat compared to the overall rise in CVEs.
However, the composition of KEVs is shifting. Networking gear vulnerabilities now account for 24 percent of all KEVs, up from 20 percent in the previous quarter. This sustained upward trend underscores the increased targeting of network infrastructure by attackers. Enterprises relying on routers, switches and other network devices are seeing these products become a larger portion of actively exploited vulnerabilities.
- KEV growth: 13 percent year on year
- Networking gear KEVs: 24 percent of total, up from 20 percent in Q1
- Trend: Continued increase in network device exploitation
Networking Products and Versions Most Affected
The report does not specify individual vendors or models, but the data aligns with recent advisories affecting widely used platforms such as Cisco, Juniper and other leading network equipment providers. Vulnerabilities in firmware, management interfaces and device operating systems are among the most frequently exploited.
Patch Lag: Old Vulnerabilities Remain a Persistent Threat
Despite rapid discovery of new vulnerabilities, patch deployment cycles have not kept pace. By mid-2026, nearly half (46 percent) of actively exploited KEVs originated in 2025 or earlier. This is significant given that standard enterprise patch cycles are typically 30 to 90 days. The persistence of older vulnerabilities highlights ongoing challenges in vulnerability management and patch application.
- 24 percent of tracked CVEs are from 2024 or earlier
- 46 percent of actively exploited KEVs are from 2025 or earlier
- Patch cycles: Commonly 30-90 days, but lag persists
How Attackers Exploit These Vulnerabilities
Attackers continue to take advantage of unpatched systems by exploiting older, well-documented vulnerabilities. Networking gear, in particular, remains attractive due to its critical role in organisational infrastructure and the slower cadence of firmware updates. Exploits often target authentication bypass, remote code execution and privilege escalation flaws in device management interfaces.
Timeline of Events and Current Exploitation Status
- Q2 2026: Surge in CVE reporting, with 49 percent year-on-year growth
- April 2026: Notable but brief spike in KEV numbers
- End of June 2026: Networking gear KEVs reach 24 percent share
- 181 days into 2026: 46 percent of exploited KEVs remain from prior years
Exploitation of both new and old vulnerabilities remains active. The lag in patch deployment means that even as new CVEs are catalogued at record speed, attackers continue to leverage older flaws, especially those affecting network infrastructure. This trend is expected to persist as vulnerability discovery, often aided by AI-enhanced tools, continues to outpace human-led patch management.
Prioritisation with EPSS: A Data-Driven Approach
The sheer volume of vulnerabilities makes it impractical for organisations to patch every issue immediately. The research highlights the value of the Exploit Prediction Scoring System (EPSS) as a tool for prioritising patch efforts. Unlike traditional CVSS scores, which can mislead teams into chasing high-rated vulnerabilities that may not be actively exploited, EPSS uses real-world exploitation data and machine learning to estimate which CVEs are most likely to be targeted.
- EPSS leverages current exploitation data and predictive analytics
- Helps focus resources on the vulnerabilities most likely to be exploited
- Enables more efficient and effective patch management in the face of accelerating CVE volume
Why This Event Matters
The surge in CVEs, combined with increasing exploitation of network gear and persistent patch lag, signals a significant shift in the threat landscape. Organisations that rely on network infrastructure are at heightened risk from both new and long-standing vulnerabilities.
What Organisations Should Do Now
Security teams should review their patch management processes with an emphasis on network devices and prioritise remediation using data-driven tools like EPSS. Focusing on vulnerabilities with active exploitation evidence, especially in critical infrastructure, will help mitigate the most immediate risks.
Originally reported by blog.talosintelligence.com.





