They are not old bugs: they are old classes of bug. We ran the numbers on CISA's catalogue
We downloaded CISA's Known Exploited Vulnerabilities catalogue and counted its 1,685 entries. Of the 201 added in 2026, 123 carry an identifier from this same year and the median gap is zero: what is old is not the individual bug but the class. We measured that too, using the file's own cwes field: CWE-20, improper input validation, tops the catalogue with 118 entries, followed by command injection and out-of-bounds write. And something turned up that we were not looking for: on 10 June directive BOD 26-04 revoked BOD 22-01, and since then 81% of what goes in arrives with a three-day deadline instead of the previous 23%.