Black Kite Report: Only 58 of 48,000 CVEs Posed Critical Supply Chain Threats in 2025

  • Black Kite's 2026 Supply Chain Vulnerability Report found only 58 of 48,000 CVEs published in 2025 posed genuine supply chain threats.
  • AI adoption accelerated vulnerability discovery, with 2,130 AI-related CVEs reported in 2025, a 200% increase since 2023.
  • Attackers exploited vulnerabilities an average of seven days before public disclosure in 2025, with this window expected to shrink further.
  • Mid-market vendors and open-source maintainers face growing risk due to slower detection (197 days) and remediation (60 days) timelines compared to large enterprises.

Black Kite's findings highlight a critical shift in cyber risk management, where precision in identifying and acting on high-priority vulnerabilities is more essential than ever. The widening gap between organizations with advanced AI-driven security capabilities and those without is reshaping the supply chain risk landscape, with risk increasingly concentrating around smaller vendors. This trend underscores the need for proactive, AI-powered risk management solutions to defend against rapidly evolving threats.

Risk Concentration
How the growing share of exploited vulnerabilities targeting mid-market vendors will impact enterprise supply chains.
AI-Driven Exploitation
The pace at which AI technologies will further compress exploitation timelines and accelerate zero-day vulnerabilities.
Proactive Prioritization
Whether organizations relying solely on the CISA KEV catalog can effectively mitigate threats already being exploited.