1 in 4 vulnerabilities is exploited by hackers before disclosure, report reveals
Speed matters more than ever.

Image by Cybernews
- Nearly 1 in 4 vulnerabilities are now exploited within 24 hours of CVE publication by hackers.
- Median exploitation time dropped from 120 days to 80 days in first half of 2026.
- WordPress and content management systems account for one-third of all known exploited vulnerabilities currently.
- AI-discovered vulnerabilities show only 1.3% exploitation rate, benefiting defenders more than attackers for now.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers continue to capitalize on vulnerabilities at an alarming pace, meaning that the window to patch them keeps on shrinking.
According to researchers at the cybersecurity firm VulnCheck, there have been significant changes in vulnerability discovery and disclosure over the past 6 months.
Due to autonomous AI systems, more vulnerabilities are being discovered. This is a good thing because software developers can patch them more swiftly.
On the other hand, hackers are profiting from this as well.
VulnCheck’s State of Exploitation – 1H 2026 report found that roughly 1 in 4 vulnerabilities (23.4%) were exploited within a day of the CVE's publication, indicating that hackers are increasingly using zero-day exploits before blue team defenders and security professionals become aware of them.
Compared to 2025, when 28.9% of all known exploited vulnerabilities were exploited in one day or less, this is a small drop. However, the median time from CVE publication to exploitation fell from 120 days to 80 days, meaning that vulnerabilities are being exploited much faster overall.
According to researchers, content management systems like WordPress remain the most targeted technology category, accounting for one-third of all known exploited vulnerabilities in the first half of 2026.
This corresponds with a warning recently issued by the Australian Cyber Security Centre (ACSC), stating that hackers have launched a global exploitation campaign targeting websites that are built with content management systems like WordPress and Joomla.
Check if your data has been leaked
Network edge devices like VPNs, firewalls, and routers continue to be attackers’ second most favorite target to exploit, including network equipment from Cisco, Palo Alto Networks, CheckPoint, F5, Juniper, Fortinet, SonicWall, Ubiquiti, TOTOLINK, Tenda, D-Link, Netgear, and Linksys.
VulnCheck researchers found that only 14 of the 1,061 vulnerabilities that were discovered by AI systems (or 1.3%) have been confirmed to have been exploited in attacks, roughly matching the overall exploitation rate of all vulnerabilities in the first 6 months of the year.
The researchers note that, for the time being, AI technology appears to be more of an advantage for defenders, as the tools help to find and fix vulnerabilities, rather than enabling attackers to exploit zero-day vulnerabilities.
“With the relatively small volume of AI discovered vulnerabilities with confirmed exploitation, our main observation is that it’s too early to come to any significant conclusions on what vendors or products are most likely to be exploited. However, it’s worth noting that the KEVs include both commercial and open source products,” VulnCheck concludes.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.