Vulnerability disclosure keeps setting records. The National Institute of Standards and Technology (NIST) reports that CVE submissions rose 263% from 2020 to 2025, and the first three months of 2026 already tracked nearly one-third higher than the same period a year earlier. Every security team feels that curve in its backlog.
The curve is not what decides outcomes, though. Arctic Wolf® Incident Response data points somewhere less flattering and more useful.
The vulnerabilities getting exploited are old
The top 10 most exploited CVEs over the last 12 months all had patches available. None of them were novel zero-days. They persisted on assets that security teams never had a chance to protect, because those assets were not in the vulnerability management tool in the first place.
The 2026 Arctic Wolf Threat Report puts numbers on how attackers actually get in. Abuse of external remote access services such as RDP, VPN and RMM tools accounted for 65% of non-BEC incident response cases. Exploitation of known vulnerabilities with patches already available accounted for another 11%, and trusted relationships and misconfigurations accounted for 8%.
Read that together and a pattern emerges. The failure is rarely that a scanner missed a flaw. It is that nobody knew the asset existed, or nobody could say which findings in a queue of tens of thousands actually mattered this week.
Speed has changed the math
Google reported that the average time attackers take to exploit a vulnerability collapsed to five days in 2023. Its threat intelligence group went further for 2024, observing a negative average time-to-exploit of minus one day, meaning some vulnerabilities are exploited before the organizations running them know they exist. Against that clock, a quarterly scan cadence is a decision to be late.
What actually separates one solution from another
Most vulnerability management tools find vulnerabilities competently. The differences that show up in practice sit elsewhere.
- Coverage of the assets your scanner never sees. Arctic Wolf attack surface research found 17% of assets were invisible to legacy vulnerability management tooling. A tool that starts from the assets it already knows will confirm a blind spot rather than close it.
- Prioritization built on more than severity. Ask what feeds the ranking. Observed exploitation in the wild, CISA KEV listing, whether the asset is internet-facing, how critical the system is to the business and whether a compensating control is already in place.
- Integration breadth instead of rip-and-replace. A platform that only ingests data from its own stack cannot capture the full range of risk signals in a real environment. The attack surface does not respect product categories.
- Remediation you can act on. Findings become outcomes through patch deployment, ITSM workflow and clear ownership assignment, not through a longer report.
- Verification that risk actually fell. Closing a ticket does not prove risk was reduced. In one organization that migrated off end-of-life systems, business units confirmed the project complete. A follow-up scan found 8% of assets still unsupported.
Three questions worth asking first
Before comparing feature grids, it helps to sit with the questions a vulnerability management program exists to answer. What do I have. Where am I exposed. What do I fix first. A solution that cannot answer the first question with confidence should not be trusted on the third.
That sequence is also the honest test of a shortlist. Coverage first, then context, then proof that remediation worked.
The takeaway
Volume will keep climbing. The vulnerabilities that end up in incident response reports will keep being the ones that were patchable all along, sitting on assets nobody had inventoried. Choosing for coverage, context and verification matters more than choosing for scan speed or finding counts.
Arctic Wolf's guide to selecting a vulnerability management solution walks through the evaluation criteria in detail, including the questions worth putting to any vendor before a decision.