Verizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access Vector

2026-05-20T08:52:13Z4b5a3634cb7b87ff77581509d7b0c7dccc3c7d0f6bad2a0f3b1b6ff3f6164f62
ai-enabled-attacksexchange-serverkernel-vulnerabilitylaw-enforcementlinuxmalware-stealermobile-malwareopen-source-compromisepatch-managementransomware-enablerssbomsupply-chainvulnerability-exploitationzero-day

What happened

A convergence of trends in mid-May 2026: vulnerability exploitation has overtaken credential theft as the leading initial access vector (Verizon DBIR: 31% of breaches began with software flaws). Researchers and attackers disclosed dozens of high-impact zero-days (Pwn2Own: 47 zero-days), multiple new Linux kernel privilege-escalation flaws (including ‘Fragnesia’ and ‘Dirty Frag’ chains), and a severe on‑premises Microsoft Exchange zero-day affecting Exchange Server 2016, 2019 and Subscription Edition. Large-scale supply-chain and code-theft incidents were observed (Grafana source-code theft, Av

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
4b5a3634cb7b87ff77581509d7b0c7dccc3c7d0f6bad2a0f3b1b6ff3f6164f62
Enrichment time
2026-05-20T08:52:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Verizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access Vector · Baitaphish