Desk live·
ForensicPost
Cloud/Vulnerabilities/File 26-0524

CVE Submissions Rose 263% Between 2020 and 2025

CVE submissions rose 263% between 2020 and 2025, with 2026 tracking a third higher again. Some of that is more vulnerable software and some is a counting convention.

Constructed geometry · not a chart of case data
TargetVulnerability disclosure ecosystem
ActorUnattributed
D. Kennedy10 min readConfidence: medium2 sources reviewed

CVE submissions rose approximately 263% between 2020 and 2025, with first-quarter 2026 submissions tracking about 33% higher than the same period a year earlier.

The number is real and the interpretation usually attached to it is not quite right.

Four Different Things Are Producing The Growth

There is more software, and more of it is internet-facing. There are more researchers, and more automated discovery producing findings at machine rate.

There are more organisations authorised to issue identifiers, which mechanically increases issuance. And there is a counting convention: one defect in a widely used library can generate an identifier for each affected downstream package.

Only the first of those is straightforwardly bad news. The middle two are the ecosystem working. The last is an artefact.

Why It Matters That The Metric Is Noisy

A rising CVE count is routinely cited as evidence that software is getting less secure. It may be, but this measure cannot establish it, because the measurement apparatus changed at the same time.

What the count does reliably measure is workload — on the enrichment pipeline filed at 26-0405, and on every security team that has to triage the output. That load is real regardless of what is causing it.

The Metric That Would Help

Exploitation, not disclosure. The proportion of published vulnerabilities that are ever observed in use is small, and it is the number that determines how much of this volume matters.

That is precisely what the known-exploited catalogue tracks, and it is why the triage prioritisation in 26-0412 chose it — a decision that looks better the more closely you examine the raw submission figures.

How we reported this

This is an analysis file built on published statistics, listed below. Growth figures are as reported; the decomposition of causes is ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. CVE statistics 2026: severity distribution and top affected vendorsSQ Magazine
  2. Vulnerability statistics 2026: CVE, KEV, time to exploitStingrai
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary