Skip to content

TechChannels Network:      Whitepaper Library      Webinars         Virtual Events      Research & Reports

×
Internet of Things (IoT)

Over 37,000 New Vulnerabilities: What the 2026 Threat Landscape Means for IoT Security

Forescout counted 37,137 newly published vulnerabilities in the first half of 2026, up 51 percent on the previous year. 55 percent carried high or critical severity ratings, and 54 had already been exploited as zero-days (Forescout, 2026). The volume is significant across every technology estate. It is especially consequential for IoT, OT and connected medical environments, where remediation often depends on more than a patch window.

A vulnerability in a laptop is usually an endpoint-management issue. A vulnerability in a connected device may involve a clinical engineer, a facilities team, an operational manager, an equipment supplier and a maintenance schedule. The device may run a customized operating system, rely on a vendor-controlled update process or support a function that cannot be interrupted during working hours. Connected-device security therefore depends as much on operational ownership and change control as it does on technical remediation.

The result is a large population of devices that are known but hard to change, alongside another population that is simply poorly understood. Network-connected cameras, smart building controls, badge readers, industrial gateways, diagnostic equipment and sensors often accumulate over years through different procurement decisions. They may share a network with more sensitive systems, retain vendor remote access and lack complete asset records. An organization can have sophisticated cloud controls while still being unable to determine which devices are communicating across a particular operational network.

Nearly half, or 46 percent of the CVEs added to CISA’s Known Exploited Vulnerabilities catalog during the reporting period had been disclosed before 2026. Attackers continue to use older flaws because older devices remain available to exploit. The security gap is created less by ignorance of the CVE and more by the gap between knowing a weakness exists and being able to remove it without affecting a service, production line or healthcare workflow.

That makes patching only one part of the response. A device awaiting a patch still requires controls around it: separation from corporate IT, restricted internet exposure, tightly managed remote access and monitoring for anomalous traffic. The aim is to reduce the paths an attacker can use while the organization works through the operational constraints around remediation.

Well, the pressure is rising because discovery is accelerating. Forescout stops short of attributing the 51% increase in published vulnerabilities directly to AI, but its researchers point to AI-assisted vulnerability research as a factor in the faster pace of discovery and disclosure. Google recently reported what it assessed to be the first use of an AI-generated zero-day exploit in a real-world campaign, involving a two-factor authentication bypass in open-source administration software (IANS Research, 2026). AI does not eliminate the need for attackers to find exposed systems. It makes the search more scalable.

Meanwhile, ransomware claims rose 25 percent to 4,544 in six months, or about 25 attacks per day. The number of active ransomware groups reached 103. Security programs need a clearer view of device exposure, network relationships and operational consequences, especially where patching cannot happen quickly.



 

Share on

More News