Vulnerability disclosure keeps setting records. The National Institute of Standards and Technology (NIST) reports that CVE submissions rose 263% from 2020 to 2025, and the first three months of 2026 already tracked nearly one-third higher than the same period a year earlier. Every security team feels that curve in its backlog.
The curve is not what decides outcomes, though. Arctic Wolf ® Incident Response data points somewhere less flattering and more useful.
The top 10 most exploited CVEs over the last 12 months all had patches available. None of them were novel zero-days. They persisted on assets that security teams never had a chance to protect, because those assets were not in the vulnerability management tool in the first place.
The 2026 Arctic Wolf Threat Report puts numbers on how attackers actually get in. Abuse of external remote access services such as RDP, VPN and RMM tools accounted for 65% of non-BEC incident response cases . Exploitation of known vulnerabilities with patches already available accounted for another 11%, and trusted relationships and misconfigurations accounted for 8%.
Read that together and a pattern emerges. The failure is rarely that a scanner missed a flaw. It is that nobody knew the asset existed, or nobody could say which findings in a queue of tens of thousands actually mattered this week.
Google reported that the average time attackers take to exploit a vulnerability collapsed to five days in 2023. Its threat intelligence group went further for 2024, observing a negative average time-to-exploit of minus one day , meaning some vulnerabilities are exploited before the organizations running them know they exist. Against that clock, a quarterly scan cadence is a decision to be late.
Most vulnerability management tools find vulnerabilities competently. The differences that show up in practice sit elsewhere.
Before comparing feature grids, it helps to sit with the questions a vulnerability management program exists to answer. What do I have. Where am I exposed. What do I fix first. A solution that cannot answer the first question with confidence should not be trusted on the third.
That sequence is also the honest test of a shortlist. Coverage first, then context, then proof that remediation worked.
Volume will keep climbing. The vulnerabilities that end up in incident response reports will keep being the ones that were patchable all along, sitting on assets nobody had inventoried. Choosing for coverage, context and verification matters more than choosing for scan speed or finding counts.
Arctic Wolf's guide to selecting a vulnerability management solution walks through the evaluation criteria in detail, including the questions worth putting to any vendor before a decision.