< Back to all clusters
[TECHNOLOGY] · 8 sources

started · updated

Check Point Report Finds Critical Vulnerabilities Doubled in 2026

Check Point Software Technologies' 2026 Exposure Gap Report shows that critical vulnerability exposures more than doubled over the past year, making up 42.6% of all critical exposures compared with 18.7% the previous year. Only 7.8% of vulnerability alerts required critical or high‑severity attention, while phishing‑related exposures grew to 10.5% of critical cases. Organizations acted on 85.9% of recommended fixes, demonstrating that exposures can be closed at scale when proper prioritisation and response workflows are in place.

The ASEC Q2 2026 Vulnerability Trends Report recorded 20,701 new CVEs, including 2,317 critical ones (11.2% of the total). Seventy‑five new vulnerabilities were added to the CISA Known Exploited Vulnerabilities list, 39 of them classified as critical. Attackers increasingly target external access points such as firewalls, VPNs and management portals, and supply‑chain attacks against software packages are on the rise. The report notes that AI‑assisted tools are shortening the time between disclosure and exploitation.

In related developments, Swedish cybersecurity firm Outpost24 launched the next‑generation CyberFlex platform, which combines continuous attack‑surface discovery, AI‑driven risk insights and CREST‑certified penetration testing with flexible budget allocation to address the gap between fixed‑scope testing cycles and rapidly changing digital environments. Separately, experts highlighted a “Return on Mitigation” (RoM) metric for industrial‑control‑system security budgeting, quantifying risk reduction in dollar terms to help justify cybersecurity investments.