Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VulnCheck announced a $25 million Series B on February 17, 2026, led by Sorenson Capital. National Grid Partners also participated, alongside existing investors Ten Eleven Ventures and In-Q-Tel. VulnCheck says the financing brings its total funding to $45 million and will help it expand exploit intelligence for security teams.

Who invested in VulnCheck’s Series B?

Sorenson Capital led the round. National Grid Partners joined, as did existing investors Ten Eleven Ventures and In-Q-Tel (IQT), according to VulnCheck’s February 17 announcement. Axios independently reported the $25 million financing and the investor group.

VulnCheck says the Series B brings its total funding to $45 million. The company also reported year-over-year annual recurring revenue growth of 557% in enterprise and 306% in government in its announcement. Those are company-reported growth rates; they do not disclose starting revenue or absolute revenue, and should not be read as independently audited measures of company scale.

What does VulnCheck do?

VulnCheck describes itself as an exploit-intelligence company. Its product supplies evidence-driven, machine-consumable information about whether vulnerabilities are exploitable and how attackers use them. The intended purpose is to help organizations sort vulnerability findings and decide what to address first, adding exploitation evidence and threat context to disclosure dates or broad severity scores. Axios describes the offering as an autonomously updated dataset for enterprise and government customers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is the company’s positioning, not independent proof that its product outperforms other vulnerability-intelligence services. For buyers evaluating this category, useful points of comparison include the evidence behind each signal, how often data is updated, whether feeds integrate with existing security tools, and how well the service fits the organization’s response workflow.

Why prioritize evidence of exploitation?

A disclosed vulnerability, publicly available exploit code, and confirmed exploitation in the wild are different signals. A proof of concept can demonstrate a way to trigger a flaw without showing that attackers are using it against real targets. Conversely, real-world exploitation may be reported after the activity begins, or remain unattributed. Keeping those distinctions clear helps teams avoid treating every disclosed flaw—or every available exploit—as equally urgent.

VulnCheck founder and CEO Anthony Bettini told Axios: “The vulnerabilities that are getting exploited typically aren’t zero days.” The point is that exploitation can matter after a vulnerability has been disclosed, not only before a fix or public disclosure. The quote is the CEO’s view, rather than an independent measurement of all attacks.

What VulnCheck’s 2025 figures show—and what they do not

VulnCheck’s 2026 Exploit Intelligence Report analyzes 2025 calendar-year data captured on December 31, 2025. It draws on more than two dozen VulnCheck indices and more than 500 sources. The company notes that attribution can emerge months after an incident or may never be reported, so the figures are bounded by available evidence and are not universal industry counts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
VulnCheck-reported figure What it means
More than 48,000 new CVEs were published in 2025; 83% had 2025 identifiers. The report’s count of new CVEs for the 2025 calendar year.
More than 14,400 exploits developed in 2025 targeted 10,480 unique 2025 CVEs. Exploit development was spread across a larger set of vulnerabilities than the number confirmed exploited in the wild.
1% of 2025 CVEs had been exploited in the wild by the end of 2025. The report distinguishes observed in-the-wild exploitation from public proof-of-concept code.
884 vulnerabilities were added to VulnCheck’s KEV dataset in 2025, drawing on exploitation evidence from 118 unique sources. A count specific to VulnCheck’s dataset and source methodology.
56.4% of 2025 ransomware CVEs were discovered as a result of zero-day exploitation by financially motivated actors. The report’s ransomware-related finding; its attribution caveats apply.
One-third of known 2025 ransomware CVEs had no public or commercial exploits available as of January 2026. A dated availability observation in the report, not a claim that those vulnerabilities could not be exploited.

These are VulnCheck’s reported statistics, not neutral market-wide measurements. In particular, the reported gap between exploit development and observed in-the-wild use illustrates why exploit-code availability alone should not be treated as confirmation of active attacks.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How VulnCheck says it will use the funding

VulnCheck says the capital will support growth and expand its intelligence capabilities for automation and AI-powered detection of emerging threats. Axios additionally reported plans to hire, broaden product offerings, and deepen the company’s international footprint. These are stated plans, not completed outcomes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.