200 New CVEs Daily: The Challenge of Effective Patch Management

www.news4hackers.com-200-new-cves-daily-the-challenge-of-effective-patch-management-200-new-cves-daily-the-challenge-of-effective-patch-management

200 new CVEs a day and no realistic way to patch them all

Challenges of Tracking and Mitigating Vulnerabilities

Ryan Dewhurst, CEO at KEVIntel, outlines the challenges of tracking and mitigating vulnerabilities in an environment where exploitation often outpaces official reporting. His team employs a global honeypot sensor network, AI-driven triage, and manual verification to identify vulnerabilities before they appear in public databases. This process includes analyzing CISA’s catalog of known exploited vulnerabilities (KEVs) and addressing gaps in its coverage.

CISA’s BOD 26-04 Directive

CISA’s BOD 26-04 directive mandates that federal agencies address actively exploited KEVs within three days, creating pressure to prioritize high-risk vulnerabilities. However, the private sector must interpret this data carefully, as CISA’s catalog is not a comprehensive list of all exploited vulnerabilities. The agency’s focus on U.S. federal agencies and its operational constraints mean that some threats may go unlisted.

The Volume of New Vulnerabilities

The volume of newly disclosed vulnerabilities continues to rise, with approximately 200 CVEs released daily. This trend is accelerating due to advancements in AI, making it impractical to patch all critical and high-severity flaws. Patching processes involve multiple stakeholders and are often delayed by organizational complexities, such as asset inventory management.

AI and Exploitation Dynamics

Attackers, meanwhile, leverage AI to reverse-engineer patches and exploit vulnerabilities rapidly. Virtual patching, such as deploying web application firewall (WAF) rules, offers temporary mitigation but is not a long-term solution. For example, WAF rules have been used to block exploitation of a recent WordPress Core remote code execution (RCE) chain. However, this approach requires ongoing maintenance and does not address underlying vulnerabilities.

Vendor Claims and Verification

Vendors may inflate or downplay the severity of vulnerabilities, creating confusion for defenders. Some claim vulnerabilities require authentication to exploit, only for analysis to reveal unauthenticated access paths. Others omit evidence of real-world exploitation while including indicators of compromise (IoCs) in advisories. These discrepancies place the burden on customers to verify claims independently.

AI-Generated Proof-of-Concept Code

AI-generated proof-of-concept (PoC) code further complicates threat detection. Researchers often use large language models to generate PoCs based on limited details, resulting in non-functional or misleading outputs. For instance, AI-generated PoCs for CVE-2026-25089, an OS command injection flaw in Fortinet FortiSandbox, appeared valid but failed to exploit the vulnerability.

Validating Threat Signals

Distinguishing between genuine exploits and AI-generated noise requires technical validation, including manual reproduction and scrutiny of documentation quality. Defenders should prioritize threat signals based on reliability. Incident reports provide actionable technical details but indicate active exploitation. Honeypot hits, when validated as genuine KEVs, signal imminent threats. Internet-wide scanning data can reveal patterns, such as spikes in probing before mass exploitation.

KEVIntel’s Approach to Unlisted Vulnerabilities

KEVIntel identifies exploited vulnerabilities not listed in CISA’s catalog through its global honeypot network and monitoring of vendor advisories and researcher reports. Sensors deployed in regions like Australia, Canada, Europe, and the Middle East capture attacker behavior, while AI analysis filters out noise. Human verification ensures accuracy, with researchers replicating attacks in controlled environments.

Targeted Exploitation and Vendor Disclosures

In cases where exploitation is highly targeted, vendors may disclose IoCs directly, prompting KEVIntel to add the vulnerability to its public feed. The challenge of managing vulnerabilities in a rapidly evolving threat landscape underscores the need for adaptive strategies. Organizations must balance immediate mitigation with long-term patching efforts while remaining vigilant against deceptive tactics.

Ryan Dewhurst, CEO at KEVIntel, outlines the challenges of tracking and mitigating vulnerabilities in an environment where exploitation often outpaces official reporting.

Conclusion

Organizations must balance immediate mitigation with long-term patching efforts while remaining vigilant against deceptive tactics. The evolving threat landscape demands continuous adaptation and reliance on advanced tools like honeypots, AI, and manual verification to stay ahead of emerging risks.


Blog Image

About Author

en_USEnglish