VulnCheck White logo (600 x 150 px)
Research Report

The 1H 2026 State of Exploitation Report 

Every year, the headlines about AI-accelerated attacks get louder. This report puts that narrative to the test using six months of Known Exploited Vulnerabilities (KEV) data, exploitation timing, targeted technology trends, and source reporting patterns from 1H 2026. The takeaway: the volume of vulnerability noise is climbing, but actual exploitation tells a more measured story, defenders need real data, not headlines, to navigate.

495 CVEs were identified with first-time exploitation evidence in 1H 2026, a KEV-to-CVE ratio of just 1.4%, continuing a decline from 1.9% in 1H 2025.

Only 1.3% of CVEs discovered using AI tools (14 of 1,061) have shown evidence of real-world exploitation, a strong signal that AI-assisted vulnerability discovery hasn't yet translated into a wave of AI-driven attacks.

A growing patch gap: of 1,611 AI-discovered findings tracked against a 90-day disclosure deadline, only 27 patches had been released as of July 21, 2026.

CMS platforms remain the top target (163 KEVs), with AI products now a measurable category of their own (28 KEVs).

The full report breaks down 1H 2026 exploitation trends by technology category, time-to-exploitation, threat source, and how AI-discovered vulnerabilities compare to real-world exploitation. If your visibility into exploitation risk depends on CISA KEV alone, this research shows exactly what you are missing.

Download the 1H 2026 State of Exploitation Report to see the complete picture.

Authored by

Patrick Garrity

Security Researcher, VulnCheck

patrick headshot

Download the Report