Uploaded May 2026 | Updated September 2026, 7 hours ago
Scott Moore (VulnCheck, US)
The prevailing myth in cybersecurity circles—that the escalating number of vulnerabilities indicates a fundamental decline in software security—deserves scrutiny, as it often oversimplifies complex dynamics. While Common Vulnerabilities and Exposures (CVEs) did increase 20% from 40,000 in 2024 and over 50,000 by the end of 2025, this uptick is frequently misconstrued by speculation in blogs, media outlets and annual cyber security trend and insight reports. This trend is amplified by a rising volume of CVEs in non-enterprise and academic initiatives even as major vendors' vulnerability counts hold relatively steady. Flawed incentives in reporting mechanisms promote the logging of minor or spurious issues for prestige, artificially inflating figures without correlating to actual threats fuels undue panic, misallocates remediation efforts, and eclipses genuine strides in secure coding practices. Debunking it calls for a shift toward risk-centric vulnerability management, emphasizing exploit potential over raw quantity to cultivate a more informed perspective on evolving cyber risks.
---
Scott Moore has been archiving vulnerability data for 30 years. Creator of the Internet Security Systems X-Force Vulnerability Database, an original source for the creation of the CVE program. CVE Numbering Authority for IBM for 15 years with 9500 CVE assignments. Currently a Security Researcher at VulnCheck.
Scott Moore (VulnCheck, US)
The prevailing myth in cybersecurity circles—that the escalating number of vulnerabilities indicates a fundamental decline in software security—deserves scrutiny, as it often oversimplifies complex dynamics. While Common Vulnerabilities and Exposures (CVEs) did increase 20% from 40,000 in 2024 and over 50,000 by the end of 2025, this uptick is frequently misconstrued by speculation in blogs, media outlets and annual cyber security trend and insight reports. This trend is amplified by a rising volume of CVEs in non-enterprise and academic initiatives even as major vendors' vulnerability counts hold relatively steady. Flawed incentives in reporting mechanisms promote the logging of minor or spurious issues for prestige, artificially inflating figures without correlating to actual threats fuels undue panic, misallocates remediation efforts, and eclipses genuine strides in secure coding practices. Debunking it calls for a shift toward risk-centric vulnerability management, emphasizing exploit potential over raw quantity to cultivate a more informed perspective on evolving cyber risks.
---
Scott Moore has been archiving vulnerability data for 30 years. Creator of the Internet Security Systems X-Force Vulnerability Database, an original source for the creation of the CVE program. CVE Numbering Authority for IBM for 15 years with 9500 CVE assignments. Currently a Security Researcher at VulnCheck.










