On 10 June 2026, CISA issued Binding Operational Directive 26-04, which revokes BOD 22-01 and BOD 19-02, drops CVSS as the required federal prioritisation input, and imposes a three-day remediation deadline on the highest-risk combinations, together with a forensic triage in the same window. The stated rationale is explicit: artificial intelligence is said to be compressing the interval between the publication of a vulnerability and the availability of a working exploit. The Cloud Security Alliance puts that interval at ten to fifteen minutes, at roughly one dollar per attempt.
A binding directive that mandates a three-day clock and a standing forensic collection capability deserves scrutiny of the measurement it rests on. Two public datasets make that possible. The first is the CISA KEV catalogue itself; the extraction used here, dated 16 September 2026, holds 1,711 entries across twelve columns going back to November 2021. The second is the VulnCheck catalogue, built on a far broader perimeter and accompanied by quantified half-yearly reports.
The two can be reconciled. For 2025, the CISA extraction yields 245 entries across 99 vendors and 146 products, which are exactly the figures VulnCheck publishes for the same period. The counts that follow are therefore directly comparable.
What the CISA catalogue shows
Comparing full calendar years would distort the reading, since 2026 stops at the extraction date. On an identical window, 1 January to 16 September, the series gives 519 entries in 2022, 130 in 2023, 118 in 2024, 175 in 2025 and 227 in 2026.
Of the 555 entries added during calendar year 2022, only 16.4% carry a CVE identifier from that same year, and their median age at inclusion reaches four years. That is the documentary backfill which followed the creation of the catalogue, not a wave of exploitation. Set 2022 aside and the series reads cleanly: a trough of 118 entries in 2024, then 175 in 2025 and 227 in 2026, a rise of 48% and then 30%. The monthly detail for 2026 ranges from 17 to 31 entries, with no spike, including after the directive was published.
The workload carried by remediation teams has therefore roughly doubled since 2024. But a continuous slope is not a break, and more importantly this count does not measure exploitation: it measures the cataloguing activity of a US federal agency across its own perimeter. That is the limitation the second dataset allows us to work around.
What the CISA catalogue does not see
VulnCheck maintains a catalogue of exploited vulnerabilities built without sector or geographic restriction, fed by more than a hundred first-reporting sources. The coverage gap is substantial.
In 2025, VulnCheck recorded 884 exploited vulnerabilities across 518 vendors and 672 products, against 245 across 99 vendors and 146 products for CISA. The gap holds in the first half of 2026: 495 against 146. The CISA catalogue therefore covers between a quarter and a third of what broad monitoring observes, and it does so late, VulnCheck reporting that it supplies exploitation evidence earlier in more than 85% of cases.
Three examples make that gap concrete for an operational team. Of the 61 vulnerabilities VulnCheck observed being exploited against its own exposed vulnerable hosts in the first half of 2026, only 12 appear in the CISA catalogue. The two Langflow vulnerabilities used for initial access, CVE-2026-0769 and CVE-2026-5027, are not listed, even though four other vulnerabilities in the same product were added between March and July 2026. And the single AI-discovered vulnerability with confirmed exploitation, CVE-2026-26980, is absent as well.
KEV listing is one of the four variables that determine the deadline imposed by BOD 26-04, alongside public exposure, exploit automation and technical impact. A vulnerability that is being exploited but is not listed therefore triggers no three-day clock at all. CVE-2026-26980 is the textbook case: the one AI-discovered vulnerability with confirmed in-the-wild exploitation falls outside the mechanism designed to answer the threat AI is said to create.
Speed, measured where it can be measured
Volume says nothing about speed. The CISA catalogue does not carry the CVE publication date, which rules out measuring time-to-exploitation within it. VulnCheck publishes that measurement, and it yields three indicators that do not point the same way.
| Indicator | 2024 | 2025 | 1H 2026 |
|---|---|---|---|
| Exploited on or before the day the CVE was published | 23.6% | 28.93% | 23.43% |
| Median time from CVE publication to evidence of exploitation | not published | 120 days | 80 days |
| Vulnerabilities exploited within 31 days of publication | 196 | 194 | around 200 |
| Ratio of exploited vulnerabilities to published CVEs | declining | declining | 1.4% |
The share of vulnerabilities exploited on or before the day the CVE was published is falling, from 28.93% in 2025 to 23.43% in the first half of 2026, after 23.6% in 2024. In absolute terms, the front of the curve is flat: around 200 vulnerabilities reach exploited status within 31 days in the first half of 2026, a level VulnCheck describes as in line with the 196 and 194 of the two preceding years. Over the same period, published CVE volume grew by 45% in six months against 10% for exploited vulnerabilities, which drives the ratio between the two down to 1.4%, from a peak of 2.7% in late 2023.
One indicator does support the acceleration case, and it is the most widely quoted: the median time from CVE publication to evidence of exploitation drops from 120 to 80 days. It deserves close reading, because it does not measure what it is made to say.
Why the median falls while the front holds
Two mechanisms are enough to account for the drop in the median without any change in offensive capability.
The first is a composition effect. Content management systems account for one third of the exploited vulnerabilities recorded in the first half of 2026, 163 out of 495, a larger share than anything observed historically. That mass is driven by the WordPress plugin ecosystem, where CVE assignment has been industrialised by Patchstack, Wordfence and WPScan. A WordPress plugin vulnerability is exploited within days by scanning botnets, with no exploit development involved. Feeding that population into the calculation in bulk mechanically lowers the median for the whole set. The signal is not that attackers have become faster: it is that the catalogue has filled up with a category that was always fast and was previously under-documented.
The second is a cohort maturity effect. Evidence of exploitation often surfaces months or years after the CVE is published. Recent cohorts have not finished filling, and VulnCheck flags this explicitly in its analysis. A median computed on a population whose long tail has not yet arrived is structurally pulled downwards. It will rise again as late exploitation evidence accumulates against 2026 CVEs.
The half-year’s first reporters confirm that reading through the composition of the signal: Patchstack with 70 vulnerabilities, CrowdSec with 64, ShadowServer with 57, ahead of VulnCheck with 37, Wordfence with 20 and CISA with 19. What changed in 2026 is first of all the sensors and their coverage.
The direct test: are AI-discovered vulnerabilities exploited more often?
The thesis CISA advances can be tested head-on, by isolating vulnerabilities whose discovery is attributed to AI assistance and checking which ones end up exploited. VulnCheck consolidated two sources for this, the tracking of disclosures credited to Anthropic and the Berkeley Vulnerability Research Initiative, then correlated them with its own catalogue.
Of 1,061 vulnerabilities attributed to AI-assisted discovery, 14 are confirmed as exploited, or 1.3%. That rate matches the one observed across all vulnerabilities in the period, and it is below the historical rate. The products involved are unremarkable, both commercial and open source: Microsoft Windows, BeyondTrust, Ghost, Chef, the Linux kernel.
The Anthropic case is worth setting out, since the announcement of Project Glasswing in April 2026 drove much of the debate. The disclosure ledger published in May claims 23,019 findings. It has never grown beyond the 1,611 entries committed at launch, and more than 150 findings have passed their disclosure deadline without publication. Across the whole set, 126 resulted in a published CVE, and exactly one, CVE-2026-26980, is confirmed as exploited.
23,019 findings claimed, 1,611 entries actually published in the ledger, 126 published CVEs, 1 confirmed exploitation. The ratio between the first figure and the last is 1 in 23,000. That is the order of magnitude worth holding in mind before repeating the ten-to-fifteen-minutes-per-exploit number, which measures code generation under laboratory conditions rather than exploitation observed against a live system.
VulnCheck’s own conclusion is measured and worth taking at face value: AI increases the volume of vulnerabilities discovered, which gives defenders the opportunity to remediate them before attackers find them. Nothing in the available data suggests that an AI-discovered vulnerability is more likely to be exploited than any other.
The profile of exploited flaws points the same way
One further indicator, drawn this time from the CISA catalogue, completes the picture. AI-assisted exploit production is worth more to an attacker the harder a flaw is to weaponise. That describes memory corruption, which demands tuning specific to the version and the environment. If AI were lifting that constraint, the share of such flaws among vulnerabilities actually exploited should rise.
| Weakness class | 2022 | 2023 | 2024 | 2025 | 2026 |
|---|---|---|---|---|---|
| Memory safety defects | 28.5% | 26.2% | 13.3% | 18.7% | 13.2% |
| Authentication bypass and access control | 5.7% | 15.7% | 16.6% | 14.8% | 21.1% |
| Injection and path traversal | 21.9% | 29.7% | 33.7% | 34.3% | 32.2% |
The opposite is happening. The share of memory safety defects halves between 2022 and 2026, while the share of authentication bypasses and access control failures quadruples. Injection and path traversal hold steady at around a third. In 2026, the three most frequent CWEs in the catalogue are code injection with 17 occurrences, improper authentication with 16 and missing authentication for a critical function with 12.
Put plainly, the flaws actually being exploited are shifting towards the classes that demand the least offensive engineering. Missing authentication is exploited with a well-formed request, not with an exploit. This observation does not prove that AI is absent from offensive workflows, and it could not. What it establishes is that the observed rise in volume is not being driven by vulnerabilities for which weaponisation was the bottleneck.
What is actually changing: the attack surface, not the speed
The strongest signal of the half-year concerns perimeter rather than pace. VulnCheck recorded 28 exploited vulnerabilities in AI products, 10 of them with exploitation observed against live hosts: model-building tools, workload-scaling platforms, AI gateways, agents and workflow automation.
The chain observed against Langflow is a conventional compromise applied to a new class of component: initial access through CVE-2026-0769 or CVE-2026-5027, credential harvesting, model service API keys in particular, cryptominer deployment, then attempted lateral movement. The CISA catalogue confirms the trend on its own perimeter, with twenty-five 2026 additions covering development and data tooling: JFrog Artifactory four times, Langflow four, LiteLLM three, GitLab three, alongside Kestra, Gitea, Metabase, TeamCity, Ray and Starlette.
These components share three properties. They hold high-value secrets. They are often deployed by development teams outside the operations pipeline. And they rarely fall within the scanning scope of a vulnerability management function calibrated on servers, endpoints and edge devices.
What the catalogue counts, and what it cannot prove
The catalogue measures a cataloguing activity governed by doctrine, and that doctrine changed during the measurement period. The file preserves the trace. The first three-day deadline appears on 27 January 2026, more than four months before the directive was published. The 21-day tier disappears after March 2026. The required action text switches on 11 June 2026 and has since carried the BOD 26-04 reference on 94 entries. A forensic triage column appears, set to yes on 53 entries, all added in 2026 and all with a three-day deadline. The median interval between addition and due date, stable at 21 days from 2022 to 2025, drops to 3 days after 11 June.
This produces a circularity worth naming. The directive uses KEV listing as an input, and in turn sets the due date CISA writes into that same catalogue. Since June 2026 the catalogue is therefore partly an output of the doctrine that invokes AI to justify itself. It cannot serve to validate that justification.
Four further caveats sit on top of that structural limit. The perimeter is that of products present in US federal civilian agencies, and the absence of a product proves nothing about its exploitation. The ransomware campaign use field is set to unknown on 1,351 entries, 79% of the catalogue, which rules it out as a prioritisation input. The freshness indicator built on the CVE year is coarse and gives a floor rather than a measurement. Finally, exploitation that targets no federal product, that leaves no public trace, or that affects components with no available fix never enters the series at all.
What this changes for a team
The directive binds US federal agencies, but its deadlines are already used as a reference in tenders and compliance reviews, and the question it raises transfers directly to a private group. Four operational conclusions follow from the data examined.
- The CISA catalogue is an attested floor, not a measurement of the threat. Monitoring that stops there misses two thirds of the vulnerabilities with observed exploitation. The VulnCheck catalogue, the Patchstack and Wordfence publications for the WordPress ecosystem, and ShadowServer reporting are free and close most of the gap.
- The problem is not exploitation speed but triage volume. Published CVE volume rises by 45% in six months while observed exploitation rises by 10%. The pressure point is the ability to rule out quickly what is not being exploited, not the ability to patch within three days.
- Content management systems and their plugins are the largest single source of observed exploitation, ahead of edge devices. An uninventoried WordPress estate, even on brochure sites, is a first-order exposure rather than a peripheral nuisance.
- The forensic triage obligation before patching is the genuine novelty in the directive, and the most expensive one. It assumes collection is available in parallel with patching operations, on systems where nothing was watching. That is a tooling and on-call problem, not a vulnerability management one.
On the thesis itself, the honest position is to keep it open. The available data show that AI-assisted discovery is sharply increasing the volume of published vulnerabilities, with no proportional increase in observed exploitation, and with no sign that vulnerabilities found this way are exploited more often than others. They do not show that AI is absent from offensive workflows, and they could not. What they do establish is that, as things stand, the justification advanced in support of a three-day deadline rests on a single indicator, the median, whose decline is explained by the composition of the dataset, while the direct indicators hold steady.
Sources
- CISA • Known Exploited Vulnerabilities Catalog, extraction of 16 September 2026, 1,711 entries • cisa.gov
- CISA • BOD 26-04: Prioritizing Security Updates Based on Risk • 10 June 2026 • cisa.gov
- CISA • BOD 26-04: Implementation Guidance • 10 June 2026 • cisa.gov
- VulnCheck • State of Exploitation 1H-2026, Patrick Garrity • 28 July 2026 • vulncheck.com
- VulnCheck • State of Exploitation 2026, Patrick Garrity • 21 January 2026 • vulncheck.com
- Anthropic • Coordinated disclosure ledger, Project Glasswing • May 2026 • red.anthropic.com
- Australian Signals Directorate • Large scale exploitation campaign targeting website content management systems • July 2026 • cyber.gov.au
- Cloud Security Alliance • Research Note, BOD 26-04, AI-Accelerated Patch Mandate • 13 June 2026 • labs.cloudsecurityalliance.org


