Some numbers you should track to the decimal point, and some you can round to the nearest trillion without losing anything. Tyler Reguly, associate director of security R&D at Fortra, has spent 20 years thinking about one particular family of numbers — software vulnerability counts — and he has now concluded, on the Fortra blog via Cybersecurity Insiders, that they have crossed into the second category. The number in question: CVEs, the common identifiers assigned to publicly disclosed security flaws. The industry has never published more than 50,000 in a single year. It is October 2026, the year is not over, and the count is closing in on 70,000.

If a company posted growth like that, Reguly notes, its executives would be ecstatic. Year-over-year percentage increases in disclosed vulnerabilities have been steep for several years running, and this isn’t even the record — from 2016 to 2017 the total jumped 126.76%. Drill into a single vendor, Microsoft, and you see the same near-constant climb, with 2021 as the only real outlier. Discovery is happening at a scale the industry has simply never seen before. So the number must matter more than ever, right? Reguly’s argument is the opposite: the number has grown so large that it has stopped mattering.

To see why, it helps to understand what the number was doing when it was small. For years, vulnerability management vendors competed on how many CVEs their products covered, which is the sort of metric that sounds rigorous and is mostly a sales brochure. Enterprises, reading the brochures, demanded 100% CVE coverage. Executives, reading the enterprise policies, demanded that every vulnerability be patched. As long as a few tens of thousands of CVEs came out each year, everyone could pretend this was an achievable goal rather than an impossible one. The number was low enough that nobody had to care about realism. Now it isn’t.

Reguly’s proposed replacement metric is the CISA Known Exploited Vulnerabilities catalog, the U.S. government’s list of flaws that attackers are actually using. And here the picture is strikingly different. The KEV count is not spiking along with the CVE count; it is holding relatively flat, which means that as a percentage of all disclosed vulnerabilities, the share being exploited is actually going down. Vendors can drop 500-fix patch bundles on a single Tuesday, and the list of bugs criminals bother to use barely moves. We have covered a version of this argument before — most ‘critical’ flaws turn out to be theater, and the scarce resource is not vendor coverage but the patch team’s hours.

Now do the arithmetic the way a security team experiences it. Can a team patch 70,000 vulnerabilities in a year? No. Can they patch roughly 165? Yes, and that is about the scale of what CISA says is being exploited. The rest gets partially handled anyway, because bulk cumulative updates tend to sweep up dozens of unrelated fixes as a side effect. The triage insight Reguly is selling is that the exploited list, not the disclosed list, is the workload.

Reguly is admirably honest that his essay contains a lot of numbers and not much revelation, and he boils it down to one takeaway: you cannot patch everything, you will not patch everything, so patch what matters in your environment. It is a reasonable conclusion, with one caveat worth noting — he is making it from a company that sells vulnerability management tools, which now have to find a selling point other than counting. Conveniently, ‘we tell you which of the 70,000 actually matter’ is also a product pitch. That doesn’t make it wrong. It makes it the rare case where the marketing and the math point the same way.