The global CVE dataset — and why it's rising
Every CVE published, 2016 to 2026, from CVE.org / NVD cross-checked against Jerry Gamblin's annual reviews. Publication has gone near-vertical since 2023 — but the honest read is that the vulnerability-counting pipeline changed more than the vulnerability landscape did.
Annual CVE publication, 2016–2026
One line, a decade of disclosure. 2026 = H1 actuals (35,364), annualized ~59k–72k depending on method.
The dataset, year by year
| Year | CVEs published | YoY growth | Note |
|---|---|---|---|
| 2016 | 6,449 | — | single-source year |
| 2017 | 14,643 | +127.1% | Step-change: CNA program expansion |
| 2018 | 16,510 | +12.8% | single-source year |
| 2019 | 17,305 | +4.8% | single-source year |
| 2020 | 18,323 | +5.9% | single-source year |
| 2021 | 20,153 | +10% | single-source year |
| 2022 | 25,084 | +24.5% | — |
| 2023 | 28,902 | +15.2% | — |
| 2024 | 39,962 | +38.3% | First ~40K record year |
| 2025 | 48,185 | +20.6% | New record; 308,920 cumulative since 1999 |
| 2026* | 35,364 | — | H1 only · annualized ~71k |
Three things inflate the count before AI enters the picture
More issuers, mechanically
CVE submissions rose 263% from 2020–2025 as the number of CNAs (organizations allowed to assign CVEs) grew from ~346 to ~484. More issuers means more IDs, independent of how many bugs exist. The 2017 near-doubling was the earlier version of this same effect.
The Hacker News / NIST, Apr 2026The Linux-kernel firehose
The Linux kernel became a CNA in Feb 2024 and immediately became the single largest publisher — 4,325 CVEs in 2024, 10.8% of the entire year — by assigning IDs to routine bug fixes. That's a policy change, not a security regression.
Stingrai vulnerability stats 2026The 'WordPress effect'
Patchstack alone published 7,007 CVEs in 2025 — more than Microsoft or Google — with Wordfence adding 3,451. Third-party plugin ecosystems, not core operating systems, now drive raw volume.
Jerry Gamblin 2025 reviewAnd the data got less usable as it got bigger
On Feb 12, 2024, NIST's National Vulnerability Database abruptly stopped enriching most new CVEs — the CVSS severity scores, product mappings, and weakness classifications that let anyone prioritize. A contract lapsed, budgets were cut. By April 2026, facing a 263% surge, NIST formally stopped scheduling enrichment for most CVEs, restricting it to actively-exploited and federal 'critical' software.
So the headline "record CVE counts" coincides with a collapse in the data needed to act on them. Any analysis that reads the rising line as "the world is getting more dangerous, and AI is why" is skipping this. VulnCheck / NIST NVD updates, 2024–2026
Microsoft's own numbers tell the same story — and 2026 broke the pattern
Across 24 months of Patch Tuesday, the monthly range held between 56 and 172 CVEs for eighteen months straight — then 2026 broke it: April 163, June 200, and July 2026's 569, the largest Patch Tuesday ever recorded. One record month isn't a trend, and the cause (AI-assisted research, more tooling, a reporting change) isn't separable from the public data. The full month-by-month dataset — every count, zero-day, and category split — is its own page.