Skip to main content

Cybersecurity statistics / Vulnerabilities

Of the 48,000+ CVEs published in 2025, only 58 represented a genuine, discoverable, and exploitable threat to enterprise supply chains.

PublisherBlack Kite
Report2026 Supply Chain Vulnerability Report
Published19 May 2026
TopicsVulnerabilities, Supply Chain, Cybersecurity

Published by Black Kite in 2026 Supply Chain Vulnerability Report, 19 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Compare this across sources

12 sources answer what share of organisations have an ai governance policy in place. They report between 18% and 44%, with a median of 36.5%.

See all 12 sources

Related statistics

Apache Log4j2 generated 13.8 million detection events on manufacturing networks, more than four years after the vulnerability was first disclosed.
SonicWall, 25/07/2026
Forty-six percent of additions to CISA’s Known Exploited Vulnerabilities catalog were CVEs that were published prior to 2026.
Forescout Technologies, 25/07/2026
30.8% of ransomware victims carried KEV exposure.
Black Kite, 25/07/2026
43.5% of victims still carried critical patch vulnerabilities in the latest assessment.
Black Kite, 25/07/2026
The Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260) generated 43 million hits in H1 2026, the single largest IoT attack signature across any industry SonicWall tracks.
SonicWall, 25/07/2026
Published vulnerabilities increased 51% year-over-year to 37,137 during the first half of 2026, with more than half rated high or critical severity.
Forescout Technologies, 25/07/2026

Get the newsletter

Weekly cybersecurity statistics by email.