The Front Door Moved: Reading the 2026 Verizon DBIR
For the first time in 19 years, attackers' favourite way in isn't a stolen password – it's an unpatched vulnerability. Three shifts from this year's Verizon DBIR, and what they mean for exposure management.
For eighteen editions, the Verizon Data Breach Investigations Report told a story that began with a person – a clicked link, a reused password, a moment of misplaced trust. The 2026 edition breaks the pattern. For the first time in the report's 19-year history, the most common way into a breach is no longer a stolen credential. It's an unpatched vulnerability.
The way in changed
Exploited software vulnerabilities were the starting point for 31% of breaches – up from 18% a year earlier – pushing credential abuse (13%) out of the top spot it had held since the report began. Attackers didn't stop stealing passwords; credentials still surface across roughly a third of breaches later in the chain. But the front door is now the software itself.
How attackers got in – 2026
Share of breaches by initial-access vector
First time in the DBIR's 19-year history that software vulnerabilities beat stolen credentials as the #1 initial-access vector.
Ransomware is a coin-flip
Ransomware appeared in 48% of all breaches, up from 44%. The bright spot: 69% of victims refused to pay – a sign that backups, segmentation and rehearsed response are working. But nearly half of every breach analysed still ended in extortion.
Ransomware's share of breaches
Present in nearly one in two breaches
Your attack surface now includes everyone you rely on
Third-party involvement reached 48% of breaches – a 60% jump in a single year, and roughly triple where it sat two reports ago. A supplier's unpatched edge device, a partner's leaked token, a dependency's known flaw: increasingly, that's your breach, on your front page.
Third-party involvement in breaches
Across the last three DBIR editions
The problem isn't patching. It's capacity.
Here's the figure that ties it together: only 26% of the vulnerabilities on CISA's Known Exploited list were fully remediated last year – down from 38% – and the median time to close one stretched to 43 days. As the DBIR puts it, patching is becoming a capacity problem as much as a technical one. You cannot fix everything. The organisations that come out ahead decide what to fix first – and they're right more often than not.
What this means for exposure management
The industry is naming the shift out loud: from managing vulnerabilities to managing exposure. Three implications we take seriously at Cyvance:
- Prioritise the exploited few, not the theoretical thousands. When 31% of breaches start with a known vulnerability and only a quarter get patched in time, ranking by real-world exploitation and asset exposure – not raw CVSS – is the difference between fixing forty things and drowning in forty thousand.
- Discover before you defend. Ransomware and third-party intrusions ride in through internet-facing assets you may not know you own. Continuous discovery of what's actually exposed comes before any patch queue.
- Extend the picture to your dependencies. With third parties in nearly half of all breaches, the health of the software you rely on is part of your exposure – so we score it alongside your own.
Agent-native Continuous Threat Exposure Management – signed telemetry, exploit-evidence prioritisation, verifiable remediation. Built for the reality above.
Source: Verizon 2026 Data Breach Investigations Report (DBIR). All figures are Verizon's; the analysis and visualisations are Cyvance's own. Read the full report at verizon.com/business/resources/reports/dbir.