Why 70,000 CVEs Is Less Scary Than It Sounds

While 2026 is on pace for nearly 70,000 CVE disclosures - a record surge driven largely by GitHub's expanded advisory program and AI-assisted discovery - the actual exploitable risk has remained flat. Security expert Jerry Gamblin explains that most of the volume represents "old debt" surfacing through automated tooling rather than new dangers. The OWASP Top 10 vulnerabilities remain largely unchanged, and AI is simply finding the same common mistakes at scale. The breakdown of the NVD as a central enrichment authority is forcing a long-overdue shift of responsibility back to CNAs and vendors. Gamblin's key advice for practitioners is to treat CVE data as a paid product, using procurement leverage to demand better records from vendors. He emphasizes that genuinely exploited bugs still target familiar classes like VPN concentrators, and the real unsolved problem remains poor asset inventory - organizations cannot triage what they cannot see. The true AI-driven threat is not mass exploitation but persistent, patient attackers that use automation to loop through networks, making continuous internal visibility more critical than raw CVE counts. 

https://www.resilientcyber.io/p/why-70000-cves-is-less-scary-than

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Open-SPDD proposes an open framework for Spec-Driven Development workflows