Wednesday, March 25, 2026

Design for Readability: How...

Creating a blog that's easy on the eyes and brain is crucial for...

Human Behavior & Marketing

About the Content Marketing Institute Team The Content Marketing Institute team is a global...

EU Charges Google

Google and EU Regulators: A New Milestone in the Ongoing Conflict The long-brewing conflict...

ChatGPT Adds Shopping Research...

Introduction to Shopping Research in ChatGPT OpenAI has launched a new feature in ChatGPT...
HomeWordpressFuture Cyber Threats...

Future Cyber Threats on the Rise

A New Analysis Predicts a Record Number of Reported Vulnerabilities in 2025

Analysis by FIRST

A new analysis by the Forum of Incident Response and Security Teams (FIRST) predicts that the number of reported vulnerabilities will reach record highs in 2025. The report forecasts almost 50,000 vulnerabilities, an 11% increase from 2024 and a 470% increase from 2023. The analysis suggests that organizations need to shift from reactive security measures to a more strategic approach that prioritizes vulnerabilities based on risk, plans patching efforts efficiently, and prepares for surges in disclosures rather than struggling to keep up after the fact.

Why Are Vulnerabilities Increasing?

1. AI-driven discovery and open-source expansion are accelerating CVE disclosures.

AI is making it easier to detect vulnerabilities in software, leading to more CVE (Common Vulnerabilities and Exposures) reports. AI allows security researchers to scan larger amounts of code to quickly identify flaws that would have gone unnoticed using traditional methods.

“More software, more vulnerabilities: The rapid adoption of open-source software and AI-driven vulnerability discovery has made it easier to identify and report flaws.”

2. Cyber Warfare and State-Sponsored Attacks

State-sponsored attacks are increasing, leading to more security weaknesses being exposed.

“State-sponsored cyber activity: Governments and nation-state actors are increasingly engaging in cyber operations, leading to more security weaknesses being exposed.”

- Advertisement -

3. Shifts in CVE Ecosystem

Patchstack, a WordPress security company, is identifying and patching vulnerabilities. Their work is adding to the number of vulnerabilities discovered every year. Patchstack offers vulnerability detection and virtual patches. Patchstack’s participation in this ecosystem is helping expose more vulnerabilities, particularly those affecting WordPress.

“New contributors to the CVE ecosystem, including Linux and Patchstack, are influencing disclosure patterns and increasing the number of reported vulnerabilities. Patchstack, which focuses on WordPress security, is playing a role in surfacing vulnerabilities that might have previously gone unnoticed. As the CVE ecosystem expands, organizations must adapt their risk assessment strategies to account for this evolving landscape.”

Looking Ahead to 2026 and Beyond

The FIRST forecast predicts that over 51,000 vulnerabilities will be disclosed in 2026, signaling that cybersecurity risks will continue to increase. This underscores the growing need for proactive risk management rather than relying on reactive security measures.

Main Takeaways

  • Vulnerabilities are increasing – FIRST predicts up to 50,000 CVEs in 2025, an 11% rise from 2024 and 470% increase from 2023.
  • AI and open-source adoption are driving more vulnerability disclosures.
  • State-sponsored cyber activity is exposing more security weaknesses.
  • Shifting from reactive to proactive security is essential for managing risks.

Read the 2025 Vulnerability Forecast:

Vulnerability Forecast for 2025

Featured Image by Shutterstock/Gorodenkoff

- Advertisement -

Latest Articles

- Advertisement -

Continue reading

Google Answers Questions About Search Console’s Branded Queries Filter

Introduction to Google Search Console's Branded Queries Filter Google Search Central recently announced that the branded queries filter in Search Console is now available to all eligible sites. This update has led to many questions from SEOs, which Google's John...

ChatGPT’s Default & Premium Models Search The Web Differently

Introduction to ChatGPT Models Ask ChatGPT's default and premium models the same question, and they'll cite almost entirely different sources. A Writesonic analysis found that GPT-5.4 Thinking, ChatGPT's premium model, sent 56% of its citations to brand websites, while GPT-5.3...

WordPress Gutenberg 22.7 Lays Groundwork For AI Publishing

New Updates in Gutenberg 22.7 Introduction to New Features Gutenberg 22.7 has introduced several exciting new features that make it easier for users to work with the platform. One of the key updates is the live preview for style variation transforms,...

WordPress Releases AI Plugins For Anthropic Claude, Google Gemini, And OpenAI

Introduction to WordPress AI Plugins WordPress has created three new plugins that make it easy to add OpenAI, Google Gemini, or Anthropic Claude integration for the PHP AI Client SDK. These plugins enable text, image, function calling, and web search...