logo

Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacks

ID: 733c3767-1738-54eb-ba79-771dae438afe

STIX ID: report--733c3767-1738-54eb-ba79-771dae438afe

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-02-25

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

VulnCheck's 2025 report finds that of more than 40,000 new vulnerabilities only ~1% (422) were exploited in the wild, with network edge devices and vendors like Microsoft, Ivanti, Fortinet, VMware, SonicWall and Oracle frequently targeted; four SharePoint zero-days were exploited en masse impacting 400+ organizations including U.S. agencies, and the React2Shell flaw accumulated over 200 public exploits—highlighting active, large-scale exploitation, ransomware linkages, and the need to prioritize known-exploited vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.