In Europe, the Middle East and Africa, exploitation of a vulnerability is the most common initial access vector in breaches, at 47%. Phishing is 28%. Credential abuse is 6%. That is the Verizon 2026 Data Breach Investigations Report, on 6,060 EMEA breaches with confirmed data disclosure.
The globally reported figure for the same vector is 31%, and that is the number most coverage of the report has used. The regional cut is higher, and for a company that builds and sells software in Europe it is the more relevant one.
This post is only about that report. Every figure below is quoted with the figure number and the population Verizon states for it, because the populations are not all the same and the differences matter.
Verizon 2026 DBIR, initial access
47% of EMEA breaches start with exploitation of a vulnerability (n=6,060).
31% globally, in non-Error, non-Misuse breaches (Figure 10, n=20,023), up from 20%.
26% of CISA KEV vulnerabilities are fully remediated, down from 38%.
Incidents between 1 November 2024 and 31 October 2025. More than 22,000 confirmed breaches, 145 countries.
Exploitation is now the most common way in
Figure 10 of the report covers "select enumerations in non-Error, non-Misuse breaches (n=20,023)". In it, exploitation of vulnerabilities reaches 31%, up from 20% the year before, which Verizon describes as a 55% increase in this vector. It is the first time in nineteen editions that exploitation, rather than stolen credentials, leads.
Note what the population is. It is not all breaches, and it is not breaches where the entry point happened to be identified. It is breaches that did not stem from an error or from insider misuse. Verizon's own summary page words it more loosely than its figure caption does, and a lot of secondary coverage has inherited the looser version. If you cite the number, cite the caption.
Europe is not the global average
The report's regional section reports EMEA separately: 8,245 incidents, 6,060 with confirmed data disclosure. The initial access vectors there are exploitation of vulnerabilities at 47%, phishing at 28% and credential abuse at 6%. System Intrusion accounts for 57% of EMEA breaches, up from 53%.
Two caveats travel with that 47%. The first is definitional: EMEA in this report follows the UN M49 standard and covers Europe, Eastern Europe, North Africa and Western Asia, so it is wider than the EU. The second is statistical: the global 31% is reported over non-Error, non-Misuse breaches while the regional figure is reported over EMEA breaches, so the two are not exactly like-for-like and the gap between them should not be read as a precise delta. Both are Verizon's figures and both point the same way.
The region also carries more state-affiliated activity: 23% of EMEA breaches involve state-affiliated actors against 14% across the full dataset, and 27% are espionage-motivated against 13% overall.
The fall in credential abuse is partly bookkeeping
Credential abuse dropped from 22% in the 2025 report to 13% in this one, and that looks like a large improvement. The report says plainly that it is not. This year Verizon added Pretexting to the tracked initial access vectors, and pretexting overlaps with credential abuse. Their own correction: "for comparison with the 2025 DBIR results, this value without the addition of Pretexting would have been 16%".
So credential abuse fell from 22% to about 16% on a comparable basis. It did not collapse. Identity controls still matter, and the report is explicit that credentials remain an integral part of the attacker toolkit. What changed is the ranking, and the reason it changed is that exploitation grew.
The patching side has a ceiling
The vulnerability management analysis draws on more than 13,000 organisations and, for the survival analysis, more than a billion anonymised detection records. Three findings stand out.
Fewer known-exploited vulnerabilities get fully fixed: 26% of CISA KEV vulnerabilities were fully remediated, down from 38%. The median time to full remediation rose to 43 days from 32. And the median organisation had 16 KEV vulnerabilities to patch, up from 11, which the report calls almost 50% more in a year.
The most useful finding is the one about limits. At Day 7, the report states that "somewhere between 60% and 70% of KEV vulnerabilities remain open regardless of year, volume or organizational maturity". That first-week rate barely moved across three years of tooling and process investment. Verizon's own conclusion is that "organizations at their very best only get to fix 30%–40% of KEV instances in the first week after detection, so choosing the correct ones to patch really is the key strategy."
Selection, not speed, is where the leverage is. And selection needs evidence about your own environment, not a global catalogue.
What the report says you should do about it
The DBIR includes a section on turning its statistics into something usable for your own organisation. On how to know where you actually stand, it says:
"What attackers find when they test you. Pen test results, red team findings, and bug bounty reports show you what external testers discover about your defenses. If they're finding critical vulnerabilities, that's evidence that you may be more vulnerable than the baseline. If they're coming up mostly empty, that suggests stronger defenses."
That is the report's own recommendation, in the same edition in which exploitation became the leading way in. We did not need to build a bridge from their data to testing; they built it.
What this report does not say
It does not say how fast vulnerabilities get exploited after disclosure. The report is careful here: the CISA KEV catalogue, it notes, "is a timestamp and not a timeline". Figures of that kind circulate widely and they are a patching argument, not a testing-frequency argument.
It does not claim to represent all organisations. Verizon states the limitation directly: "the DBIR only captures organizations that got breached, detected it, and had it reported. This creates selection bias." Every percentage here is a percentage of breaches, not of companies.
And it does not support a widely repeated claim that edge devices and VPNs jumped from 3% to 22% of exploitation-driven breaches. That figure is not in the report. What is in the report is the Network asset rising to 5% of breaches where the asset was known, from 1.5%, with Verizon flagging that they "changed the way we code cases involving remote access from a Server to Network", so part of the rise is reclassification. Separately, unpatched vulnerabilities in edge devices appear as a driver in 29% of ransomware victimisations. We published the 3% to 22% version ourselves before checking it against the report, and we have removed it.
What we changed
One number in this report is directly actionable for a software company: the thing attackers now use most is a weakness in software that is reachable from outside. Whether a weakness in your own application is reachable and exploitable is the question a catalogue cannot answer and a test can.
We sell that test. Since this month it also comes as a series: SQUR Professional runs a full pentest every month on the same application, €995 per app per month, with each run re-testing what the last one left open. The longer argument for a series rather than a single test is in a separate post. This one is just the report.
Source for every figure above: Verizon 2026 Data Breach Investigations Report. Figure numbers and populations are given inline. The report is available at verizon.com/dbir.