Why 70,000 CVEs Is Less Scary Than It Sounds
While 2026 is on pace for nearly 70,000 CVE disclosures - a record surge driven largely by GitHub's expanded advisory program and AI-assisted discovery - the actual exploitable risk has remained flat. Security expert Jerry Gamblin explains that most of the volume represents "old debt" surfacing through automated tooling rather than new dangers. The OWASP Top 10 vulnerabilities remain largely unchanged, and AI is simply finding the same common mistakes at scale. The breakdown of the NVD as a central enrichment authority is forcing a long-overdue shift of responsibility back to CNAs and vendors. Gamblin's key advice for practitioners is to treat CVE data as a paid product, using procurement leverage to demand better records from vendors. He emphasizes that genuinely exploited bugs still target familiar classes like VPN concentrators, and the real unsolved problem remains poor asset inventory - organizations cannot triage what they cannot see. The true AI-driven threat is not mass exploitation but persistent, patient attackers that use automation to loop through networks, making continuous internal visibility more critical than raw CVE counts.
https://www.resilientcyber.io/p/why-70000-cves-is-less-scary-than
Comments
Post a Comment