Skip to main content

Cybersecurity statistics / Vulnerabilities

66% of analyzed CVEs had minimal real-world applicability.

PublisherJFrog
Report2026 Software Supply Chain Security State of the Union
Published20 May 2026
TopicsVulnerabilities, Risk Assessment, CVEs

Published by JFrog in 2026 Software Supply Chain Security State of the Union, 20 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

Apache Log4j2 generated 13.8 million detection events on manufacturing networks, more than four years after the vulnerability was first disclosed.
SonicWall, 25/07/2026
Forty-six percent of additions to CISA’s Known Exploited Vulnerabilities catalog were CVEs that were published prior to 2026.
Forescout Technologies, 25/07/2026
30.8% of ransomware victims carried KEV exposure.
Black Kite, 25/07/2026
43.5% of victims still carried critical patch vulnerabilities in the latest assessment.
Black Kite, 25/07/2026
The Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260) generated 43 million hits in H1 2026, the single largest IoT attack signature across any industry SonicWall tracks.
SonicWall, 25/07/2026
Published vulnerabilities increased 51% year-over-year to 37,137 during the first half of 2026, with more than half rated high or critical severity.
Forescout Technologies, 25/07/2026

Get the newsletter

Weekly cybersecurity statistics by email.