Intel Node
The Q1 vulnerability pulse
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Thor provides an overview of the Q1 2026 vulnerability statistics, highlighting key trends in legacy CVEs and the evolving impact of AI on the threat landscape.
Welcome to this week’s edition of the Threat Source newsletter.   The first quarter of 2026 passed faster than a misconfigured firewall rule gets exploited — and the last few weeks have been firmly stamped with the "software supply chain compromise" label, with headlines surrounding incidents involving  Trivy , Checkmark ,  LiteLLM ,  telnyx  and  axios . This edition stays focused on vulnerability statistics, although you can view  Dave  and  Nick's  Talos blogs for more information about these incidents.
  Known Exploited Vulnerabilities (KEVs) stayed roughly in line with 2025 numbers — no dramatic spike, but no room for relief either. What  does  stand out? Networking gear accounted for 20% of KEV-related vulnerabilities, and that number is expected to climb as the year progresses.