Black Kite Report: Only 58 of 48,000 CVEs Posed Critical Supply Chain Threats in 2025
Event summary
- Black Kite's 2026 Supply Chain Vulnerability Report found only 58 of 48,000 CVEs published in 2025 posed genuine supply chain threats.
- AI adoption accelerated vulnerability discovery, with 2,130 AI-related CVEs reported in 2025, a 200% increase since 2023.
- Attackers exploited vulnerabilities an average of seven days before public disclosure in 2025, with this window expected to shrink further.
- Mid-market vendors and open-source maintainers face growing risk due to slower detection (197 days) and remediation (60 days) timelines compared to large enterprises.
The big picture
Black Kite's findings highlight a critical shift in cyber risk management, where precision in identifying and acting on high-priority vulnerabilities is more essential than ever. The widening gap between organizations with advanced AI-driven security capabilities and those without is reshaping the supply chain risk landscape, with risk increasingly concentrating around smaller vendors. This trend underscores the need for proactive, AI-powered risk management solutions to defend against rapidly evolving threats.
What we're watching
- Risk Concentration
- How the growing share of exploited vulnerabilities targeting mid-market vendors will impact enterprise supply chains.
- AI-Driven Exploitation
- The pace at which AI technologies will further compress exploitation timelines and accelerate zero-day vulnerabilities.
- Proactive Prioritization
- Whether organizations relying solely on the CISA KEV catalog can effectively mitigate threats already being exploited.
Related topics
