Skip to content
feed: live
>_ 0dayNews
threat intel
Analysis

Q2 2026 Vuln Stats: You Can't Patch Everything

Talos Q2 2026 data makes the case for prioritization over volume, framing 2026 as an artificial buffer before conditions shift.

Q2 2026 Vuln Stats: You Can't Patch Everything
Image: 0dayNews / 0dayNews Editorial · All rights reserved
kilobaud Dave "Kilobaud" Ferris · Published · 3 min read

Quarterly vulnerability statistics from Talos, and the headline Thorsten reaches for isn’t a number. It’s a refusal: don’t swing at everything. The argument is as simple as it keeps having to be. The volume of vulnerabilities disclosed per quarter now reliably exceeds what most operations teams can remediate on any meaningful timeline, which means a policy of “patch what we hear about” is functionally indistinguishable from not having a policy.

The industry has been told this, in roughly those terms, since the mid-2010s. The same mistake keeps looking different because the surface changes.

What Talos adds this cycle is a framing that deserves to sit a bit: the piece describes Q2 2026 as part of what it calls an “artificial buffer zone.” The suggestion is that this year’s aggregate activity — disclosure rates, exploitation volume, incident cadence — reads quieter than the trajectory heading into it, and that mistaking relative quiet for genuine relief is its own risk. Organizations that let patch cadence soften during a buffer period will find out what the buffer was absorbing when it ends. The Talos analysis doesn’t predict when that is. It observes the pattern and lets you do the arithmetic.

The method that works, and the one that feels like it does

A team that genuinely triages against exploitation likelihood has a defensible position. EPSS scores model exploitation probability, not just theoretical severity. CISA’s Known Exploited Vulnerabilities catalog surfaces what’s being actively used against real targets. Public proof-of-concept availability narrows the window between disclosure and exploitation for specific CVEs. Whether the affected product sits on an internet-facing edge or behind seven layers of compensating controls tells you what the actual exposure is. None of that is exotic.

A team working off a CVSS severity list sorted high to low has a system that looks disciplined and often isn’t, because CVSS severity is a measure of theoretical worst-case impact, not a model of how attackers currently prioritize targets. The two things are correlated enough that the confusion persists and different enough that it costs people.

Talos’s point intersects with what Picus found in their n-hour patching analysis from last week — covered here. The narrow window between disclosure and exploitation is real, but it applies to a specific subset of vulnerabilities, not the CVE catalog as a whole. Treating every disclosed CVE as if it falls in the high-velocity subset is how you exhaust a team’s sprint capacity chasing something that won’t see active exploitation for a year, while the one that actually warrants urgency waits behind it.

The gap

The practical read for a security organization from Q2 data is the same one the data has been pointing at for a while. Run patch decisions against KEV status first. Layer EPSS scores on top for CVEs that haven’t reached KEV yet. Review external attack surface for anything that drops into either category on a short cycle. Treat everything else as genuine backlog — not failure, backlog — and work it at a cadence your team can actually sustain.

Federal agencies have a legal basis for the KEV-first framing under BOD 22-01. The prioritization logic is sound for anyone else regardless.

The reason Talos is still writing this in Q2 2026 is the same reason the Mythos exposure-window triage analysis last week had to be written at all: the available information and tooling to do prioritized patching well has been in place for years. The organizations learning this from incidents rather than from quarterly analysis reports are still in the majority. The tools improved; the habit didn’t follow.

That’s the gap. Not the information — the habit.

Found this useful? Share it.