What is CVE?
CVE
CVE, or Common Vulnerabilities and Exposures, is a publicly released list of known computer security threats. In security discussions, it serves as a reference point for vulnerabilities, though its role and limitations are debated.
How it developed
- Sep 2026 - Derek Abdine noted that many existing vendors emerged when CVE was in its infancy and CWE didn’t exist, so their vulnerability management often focuses on configuration issues rather than deeper flaws.
- Sep 2026 - Johnny Hands reported that certain numbers have stayed fairly flat, around 1%.
- Aug 2026 - Ashish Rajan said that his team will generate a WAF rule even if a CVE doesn’t impact their environment, because they want the lessons.
- Aug 2026 - Ashish Rajan added that a very specific WAF rule is unlikely to block legitimate traffic.
- Aug 2026 - An unnamed speaker predicted that exploitation time for CVEs would shrink to within minutes by 2027, with same-day exploitation already common.
- Aug 2026 - Dave Bittner observed that product lines repeatedly attract attackers even as individual CVEs change.
In the evidence
Every line below is attributed to a named speaker.
Zero-days, critical CVEs, and those actively exploited in the wild have remained flat at roughly 1% of total CVEs, even as yearly totals hit record highs.
“Those numbers actually have stayed fairly flat. And in fact, those stayed about 1%.”Johnny Hands · 3 Sep 2026
Despite a CVE count on pace to double by 2027, the share of zero-days and actively exploited vulnerabilities stays around 1%, undermining the 'CVE apocalypse' narrative.
“Those numbers actually have stayed fairly flat. And in fact, those stayed about 1%.”Johnny Hands · 3 Sep 2026
Legacy vulnerability management tools conflate configuration weaknesses (world-readable files, certificate issues) with CVE-based vulnerabilities because they were built before CWE existed, creating muddled workflows.
“A lot of the vendors that have existed in the market, they come from a spa a time and space where CVE was in its infancy. CWE didn't exist yet. And so vulnerability management to a lot of these products means that configuration issues like things like world readable files on a file system, certificate problems and CDEs are all kind of mixed up into this idea of what vulnerability is.”Derek Abdine · 2 Sep 2026
Adobe's WAF pipeline generates rules even for CVEs that do not affect its environment, using irrelevant cases as deliberate repetition training for the AI agent.
“We will generate a WAF rule even if the CVE doesn't impact our environment because we would like the lessons.”Ashish Rajan · 4 Aug 2026
A highly specific CVE-targeted WAF rule is unlikely to generate false positives because exploit traffic for a given CVE is itself highly targeted and distinct from legitimate traffic.
“If you create a very specific WAF rule, you are very unlikely to block legit traffic.”Ashish Rajan · 4 Aug 2026
CVE-to-weaponized-exploit time is already same-day and is predicted to shrink to within minutes by 2027.
“Scarily small, same day. and like predicted to be within minutes next year, 2027.”<UNKNOWN> · 14 Aug 2026
Defenders gain more from tracking persistently targeted vendors than from chasing individual CVEs, because attackers repeatedly target whole product lines even as specific vulnerabilities change.
“Product lines that repeatedly attract attackers even as individual CVEes change.”Dave Bittner · 27 Aug 2026