If you sized your vulnerability management program on 2025's count, you're already a year behind.
September closed at 14,943 published CVEs. That's up 245.8% on September 2025, and it puts 2026 at 72,812 for the year so far, 105.9% ahead of the same nine months last year. Call it 267 a day.
Worth being precise about where that came from. The five busiest CNAs published 7,063 of the month's CVEs, 47.3%, and September 8 alone carried 1,559, with 965 of them from Microsoft. A lot of this is who is publishing, not what is breaking.
Median CVSS v3.x was 7.3 and the 75th percentile 8.1, across the 12,231 of 14,943 CVEs that have a v3.x score. Another 1,266 only have a v4.0 score and 1,446 have none.
Top weaknesses:
XSS (CWE-79): 1,119
Missing Authorization (CWE-862): 797
Improper Access Control (CWE-284): 610
SQL Injection (CWE-89): 494
Use After Free (CWE-416): 469
Last year's total is not a planning number anymore.
Source: NVD, excluding rejected CVEs
#CVE #VulnerabilityManagement #InfoSec



