Security professional under an umbrella as CVE vulnerabilities rain down, illustrating vulnerability prioritization during a surge in disclosures.

Feds Can’t Keep Pace With CVE Tsunami, Leaving Defenders to Triage in the Dark

A Flashpoint report reveals nearly one-third of disclosed vulnerabilities in 2026 lacked timely federal analysis, leaving security teams struggling to prioritize patching amidst rapidly evolving AI-driven threats.

Nearly a third of the vulnerabilities disclosed in the first half of 2026 never got timely federal analysis translating into defenders left partially in the dark to defend against the threats.

Security teams lean heavily on the National Vulnerability Database for guidance on how to prioritize patching against low, high and critical threats. But according to a mid-year report by Flashpoint, by the time defenders receive Common Vulnerabilities and Exposures (CVE) details they’ve already behind on 6,800 flaws.

The numbers come from Flashpoint’s 2026 Global Threat Intelligence Report: Midyear Edition, released Thursday. Flashpoint tracked 21,667 vulnerability disclosures between January and June (an 8% increase over the same period last year) and found that 6,808 of them, or 31%, went public before NVD enrichment caught up.

Beyond the Break weekly cybersecurity newsletter — Subscribe

That gap can last days or weeks, according the report, with some vulnerabilities appearing in NVD intelligence reports as much as two weeks before public sources catch up.

The report highlights a growing information gap for security teams deciding what to patch first. It also underscores an already well-known defender challenge; AI is creating a machine-speed whack-a-mole battle between adversaries and defenders when it comes to bad guys creating vulnerabilities and good guys patching them.

“AI is compressing the time between opportunity and exploitation. Capabilities that once took significant expertise, coordination, and time to develop are becoming faster to build, easier to scale, and harder to detect,” said Josh Lefkowitz, Co-Founder and CEO of Flashpoint.

Security teams are up against adversaries who can now use AI to iterate at speeds never seen before, he said. The only way to stay ahead is intelligence drawn directly from primary sources, catching adversary behavior before an attack actually happens.

NVD Far from First and Last Word

NVD enrichment includes CVE assignment, CVSS scoring, affected-version detail, and disclosure specifics, making it easy for security teams to search, sort, and compare threats. However, NVD enrichment is not the only factor defenders use to determine risk.

Defenders also consider active exploitation status and presence on a Known Exploited Vulnerabilities list, EPSS probability scores, whether a vendor patch or mitigation already exists, exposure and criticality of the affected asset, evidence of exploit sales or chatter in threat-actor communities, and whether the defender already has mitigations in place to blunt the risk.

Teams that do treat NVD status as a prerequisite for triage are choosing to be blind to a third of this year’s disclosures until the paperwork catches up. It’s a structural blind spot, Flashpoint reports, leaving targets open during the exact window – sometimes as short as 24 hours – when a flaw is most likely to be weaponized.

Efforts shore up the gap are fast and furious.

Mind the Gap

The federal government is already trying to shore up that gap.

In April NIST said it had begun scaling back the additional analysis it provides for many CVE records after vulnerability submissions jumped 263% between 2020 and 2025. Rather than enrich every vulnerability equally, NIST said it would concentrate on flaws already known to be exploited, software used by the federal government and other critical software. Lower-priority records could be marked “Not Scheduled” for enrichment.

That does not mean published CVEs simply vanish from federal view. NIST says the National Vulnerability Database ingests new CVE records through automated systems within roughly an hour. The bottleneck comes afterward, when analysts add information such as severity scores, affected product versions and other context that vulnerability-management tools and security teams use to decide what deserves attention first.

Now NIST is looking for a bigger fix.

In a request for information published Wednesday, NIST asked industry how the NVD should be rebuilt for an era of AI-assisted vulnerability discovery, exploitation and remediation. The agency specifically called out growing disclosure volume, demand for near-real-time vulnerability enrichment and the resource constraints involved in analyzing vulnerabilities at scale. It is also asking what information defenders need to prioritize vulnerabilities accurately in production environments.

This is essentially the same fix for the information deficit highlighted by Flashpoint’s data.

Karthik Swarnam, chief security and trust officer at ArmorCode, said the challenge has moved beyond simply finding more flaws.

“The industry no longer has a vulnerability identification problem; we have a prioritization, context and remediation problem,” Swarnam said.

He argues NVD modernization should push beyond static severity scores and incorporate changing signals such as active exploitation, threat intelligence and remediation status. A technically severe vulnerability, he said, may pose little immediate danger in one environment, while a lower-severity flaw exposed to the internet and under active attack could demand immediate action.

Contrary to how Flashpoint paints the core problem, he said AI can help uncover vulnerabilities faster than ever. The harder problem is giving defenders enough information, quickly enough, to know which of those vulnerabilities actually matter.

Other Mid-Year Findings

Flashpoint’s report also tracked more than 22 million illicit discussions involving AI tools across underground forums and marketplaces in the first half of 2026 and found that threat actors are increasingly moving away from those same forums, shifting toward safeguard-free, locally hosted language models running on private infrastructure.

The implication is that the trend is eroding the visibility that deep- and dark-web monitoring has long provided defenders, making some of the earliest warning signs of an attack harder to see just as attacks are accelerating.

Credential theft also outpaced expectations. Infostealer malware compromised 7.4 million hosts and harvested roughly 1.7 billion credentials in six months alone, reinforcing a trend security teams have watched build for years. That is, attackers increasingly don’t need to break in at all. They log in, using stolen session tokens and valid credentials to move past defenses built to stop technical exploitation rather than identity abuse.

Ransomware, meanwhile, told a split story. Victim counts rose 45% to 6,256 – a record high – but total on-chain revenue fell 8% to $820 million, and the share of victims paying ransom demands dropped to a record-low 28%. Rather than retreating, ransomware operators appear to be compensating by demanding larger sums from the victims who do pay and by driving down the cost of initial access – which fell 69% in a year, from $1,427 to $439 – letting a wider range of less-sophisticated actors into the game.

Total
0
Shares
Previous Article
Hand holding a smartphone displaying the Zoom app sign-in screen

Zoom and Gloom as Researchers Uncover RCE Flaw in Conferencing App

Next Article
Open back door bearing the WordPress logo with an ominous red glow inside

WordPress ‘Link Factory’ Plugin Wasn’t Vulnerable. It Was a Backdoor, Researcher says

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading