# CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare

DevFeed: [CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare](<https://devfeed.tech/articles/cve-mid-year-2026-check-in-volume-vertical-exploitation-rare-27478.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/07/01/3528/>)

Author: jgamblin

Published: 2026-07-01T15:47:10Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

This mid-year review finds that 35,364 CVEs were published in the first half of 2026, up 49.5% from the same period in 2025, while only 85 had entered CISA's KEV list. The article argues that the main challenge is distinguishing exploitable vulnerabilities from the rapidly growing volume of disclosures.

## Source excerpt

We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published in the first half of 2026 (Jan 1 - Jun 30, 2026), the volume, the severity, what is actually being exploited, and who ... Read more