threat report 5 min read

The Front Door Moved: Reading the 2026 Verizon DBIR

For the first time in 19 years, attackers' favourite way in isn't a stolen password – it's an unpatched vulnerability. Three shifts from this year's Verizon DBIR, and what they mean for exposure management.

By Cyvance Intelligence

For eighteen editions, the Verizon Data Breach Investigations Report told a story that began with a person – a clicked link, a reused password, a moment of misplaced trust. The 2026 edition breaks the pattern. For the first time in the report's 19-year history, the most common way into a breach is no longer a stolen credential. It's an unpatched vulnerability.

31%
of breaches started with a software vulnerability – now the #1 way in
▲ from 18%
48%
of breaches involved ransomware
▲ from 44%
48%
of breaches involved a third party
▲ 60% year over year
26%
of "known exploited" vulnerabilities were fully remediated
▼ from 38%

The way in changed

Exploited software vulnerabilities were the starting point for 31% of breaches – up from 18% a year earlier – pushing credential abuse (13%) out of the top spot it had held since the report began. Attackers didn't stop stealing passwords; credentials still surface across roughly a third of breaches later in the chain. But the front door is now the software itself.

How attackers got in – 2026

Share of breaches by initial-access vector

2026 initial-access vectors Vulnerability exploitation 31% Credential abuse 13%

First time in the DBIR's 19-year history that software vulnerabilities beat stolen credentials as the #1 initial-access vector.

Ransomware is a coin-flip

Ransomware appeared in 48% of all breaches, up from 44%. The bright spot: 69% of victims refused to pay – a sign that backups, segmentation and rehearsed response are working. But nearly half of every breach analysed still ended in extortion.

Ransomware's share of breaches

Present in nearly one in two breaches

48%
of all breaches analysed in the 2026 DBIR involved ransomware.
44% → 48%  year over year 69%  of victims refused to pay

Your attack surface now includes everyone you rely on

Third-party involvement reached 48% of breaches – a 60% jump in a single year, and roughly triple where it sat two reports ago. A supplier's unpatched edge device, a partner's leaked token, a dependency's known flaw: increasingly, that's your breach, on your front page.

Third-party involvement in breaches

Across the last three DBIR editions

Third-party involvement over three reports 15% 2024 30% 2025 48% 2026 ▲ 60% year over year

The problem isn't patching. It's capacity.

Here's the figure that ties it together: only 26% of the vulnerabilities on CISA's Known Exploited list were fully remediated last year – down from 38% – and the median time to close one stretched to 43 days. As the DBIR puts it, patching is becoming a capacity problem as much as a technical one. You cannot fix everything. The organisations that come out ahead decide what to fix first – and they're right more often than not.

What this means for exposure management

The industry is naming the shift out loud: from managing vulnerabilities to managing exposure. Three implications we take seriously at Cyvance:

  • Prioritise the exploited few, not the theoretical thousands. When 31% of breaches start with a known vulnerability and only a quarter get patched in time, ranking by real-world exploitation and asset exposure – not raw CVSS – is the difference between fixing forty things and drowning in forty thousand.
  • Discover before you defend. Ransomware and third-party intrusions ride in through internet-facing assets you may not know you own. Continuous discovery of what's actually exposed comes before any patch queue.
  • Extend the picture to your dependencies. With third parties in nearly half of all breaches, the health of the software you rely on is part of your exposure – so we score it alongside your own.
Cyvance Technologies
363K vulnerabilities. We find the 47 that matter.

Agent-native Continuous Threat Exposure Management – signed telemetry, exploit-evidence prioritisation, verifiable remediation. Built for the reality above.

Source: Verizon 2026 Data Breach Investigations Report (DBIR). All figures are Verizon's; the analysis and visualisations are Cyvance's own. Read the full report at verizon.com/business/resources/reports/dbir.