CVE submissions rose approximately 263% between 2020 and 2025, with first-quarter 2026 submissions tracking about 33% higher than the same period a year earlier.
The number is real and the interpretation usually attached to it is not quite right.
Four Different Things Are Producing The Growth
There is more software, and more of it is internet-facing. There are more researchers, and more automated discovery producing findings at machine rate.
There are more organisations authorised to issue identifiers, which mechanically increases issuance. And there is a counting convention: one defect in a widely used library can generate an identifier for each affected downstream package.
Only the first of those is straightforwardly bad news. The middle two are the ecosystem working. The last is an artefact.
Why It Matters That The Metric Is Noisy
A rising CVE count is routinely cited as evidence that software is getting less secure. It may be, but this measure cannot establish it, because the measurement apparatus changed at the same time.
What the count does reliably measure is workload — on the enrichment pipeline filed at 26-0405, and on every security team that has to triage the output. That load is real regardless of what is causing it.
The Metric That Would Help
Exploitation, not disclosure. The proportion of published vulnerabilities that are ever observed in use is small, and it is the number that determines how much of this volume matters.
That is precisely what the known-exploited catalogue tracks, and it is why the triage prioritisation in 26-0412 chose it — a decision that looks better the more closely you examine the raw submission figures.
This is an analysis file built on published statistics, listed below. Growth figures are as reported; the decomposition of causes is ours and labelled as such. Corrections: corrections@forensicpost.com.