Jerry Gamblin

@jgamblin.bsky.social

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

"Are we covered for this one?" is the first question after a CVE is assigned to the CISA KEV list. 60% of cases, there is no public rule to detect it. 329 of 554 KEV CVEs published since Aug 2023 have no open rule carrying the CVE ID. Apple has none.

Bild

July 2026 closed with 9,775 published CVEs, up from 3,776 in July 2025 (+158.9%). That puts 2026 at 45,626 CVEs year to date, +66.4% year over year, and 215 CVEs published a day so far this year. July 21 alone accounted for 1,474 of them, 1,097 of which were from Oracle.

Line chart titled "Cumulative CVEs Published, 2026 vs 2025", through July 31, 2026. Two rising lines from January to July: 2026 in red, 2025 in dashed grey. The lines track together through February, then 2026 pulls steadily ahead and the gap widens all year. 2026 ends July at 45,626 cumulative CVEs against 27,426 in 2025, a gap of 18,200 or 66.4 percent. Daily average 215 CVEs. Busiest completed month July with 9,775, quietest January with 4,305. Source: NVD, excluding rejected CVEs.

CVSS is a severity label the industry treats like a priority list. This year 4,719 CVEs scored CVSS v3 9.0+, and half carry the identical 9.8. Only nine distinct scores exist in that band: no 9.5, no 9.7. What would your tooling sort them on?

Bild

By July 16, the 2026 CVE count hit 39,952, the entire 2024 total, with the year barely half over. Each year now clears the two-years-earlier total sooner: mid-November in 2020, mid-August in 2025, mid-July in 2026. The earliest in this series.

Bild

CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication. But 16% were more than three years old when they hit the list.

Bild

The bugs you see most are not the bugs that get exploited. I mapped every CVE on CISA's list of exploited vulnerabilities to its corresponding CWE. What attackers actually use: memory corruption and injection. XSS is the most common bug on the internet, and it barely shows up.

Bild

Stop triaging by bug class. The 10 most common CWEs and their CVSS scores. But every one of the 10 has vulnerabilities in the same 6.3-7.1 band. The class does not tell you the severity.

Bild

A CVSS score is not a fact about a bug. It is an opinion with a decimal point. 13 orgs scored XSS: averages range from 3.4 to 6.7, mostly because VulDB sits at the bottom. The biggest reason is not the metric people argue about (Scope). That one call is worth ~1.4 points, double Scope.

Bild

For years, MITRE, the nonprofit that runs the CVE program, was its #1 issuer almost every month. Not anymore. GitHub has been #1 every month of 2026. MITRE has slid to about #7.

Bild

Paid $25 on eBay for a 1943 cryptography book. It arrived signed by LTC George R. Eckman, the Executive Officer of the Alsos Mission, the WWII task force that hunted Nazi nuclear scientists across Europe. It's going to the U.S. Army Intelligence Hall of Fame. Some books belong in archives. 🔐

Bild

March 2026 was a brutal month for vulnerabilities. 🛡️ Here is the damage: • 6,246 new CVEs (+55.7% Over Last March) • 169 new vulns per day 🤯 • 7.1 median CVSS severity (High) The Top 3 Culprits: 🥇 XSS (730) 🥈 SQLi (325) 🥉 Missing Auth (292) 2026 is already up 27% YoY.

Bild

February 2026 CVE Growth Report: YTD (February): ▸ 8,932 total CVEs (+12.4% vs 2025 YTD) ▸ 151 new vulnerabilities per day ▸ +982 more CVEs than 2025 through February February alone: ▸ 4,619 CVEs (+25.7% vs February 2025)

The @openclaw project has exploded this month. 🛡️ Since I've given it deep local access, I’m tracking its security in real-time. 📈 92 Advisories 🚨 55 High/Critical 🔄 Hourly V5 sync Link: github.com/jgamblin/Ope... Plot twist: I had OpenClaw build the tracker for me. 🤖

GitHub - jgamblin/OpenClawCVEs: Tracking OpenClaw CVEs

Tracking OpenClaw CVEs. Contribute to jgamblin/OpenClawCVEs development by creating an account on GitHub.

github.com