We're launching Scout, a free tool to check whether the apps deployed across your fleet are running vulnerable versions. Two numbers pushed us to build it: 48,185 flaws published in 2025, and an AI that can dig up holes forgotten for twenty or thirty years in software your teams open every day.
The CVE record climbs every year, and it's speeding up
In 2025, 48,185 CVEs were published, roughly 131 a day. That's 20.6% more than 2024, which had itself jumped 38%. Ninth annual record in a row. Over five years, the volume of disclosed flaws grew by 263%.
The system meant to document them is buckling. In 2025 the NVD fully analyzed only 28% of new CVEs, down from 46% a year earlier. In April 2026 NIST moved to a triage model: it will now enrich only 15 to 20% of incoming flaws, and reclassified nearly 29,000 backlog CVEs as not scheduled.
The catalog of known flaws now grows faster than anyone can track by hand. And the old ones don't fade: more than half of older vulnerabilities are still actively exploited.
Mythos: when AI changed the scale
April 2026. Anthropic unveils Claude Mythos, a model built for cybersecurity. From a single prompt, it autonomously finds thousands of unknown flaws across every major OS and browser, including holes decades of human review had never caught.
The examples are chilling. A 27-year-old denial-of-service flaw in OpenBSD. A 16-year-old defect in FFmpeg's H.264 codec, introduced in 2003, missed by every fuzzer since. In FreeBSD, a 17-year-old remote code execution flaw (CVE-2026-4747) that the model not only found but exploited on its own, all the way to unauthenticated root. In total, 6,202 critical or high-severity flaws hitting more than 1,000 open-source projects.
One thing reassures, another worries. Anthropic didn't open Mythos to the public: it kept the model for major vendors and open-source projects, through Project Glasswing (Apple, Microsoft, Cisco, CrowdStrike, the Linux Foundation), so they could patch before attackers. No general availability is planned. The catch: if a model can surface a 27-year-old flaw in days, that same capability will eventually land in other hands. The idea that software stable for years must be safe no longer holds.
An outdated app or OS is a door, not a detail
Is this really a problem on a mobile fleet? The numbers say yes. Per Verizon's 2026 DBIR, 31% of breaches start with vulnerability exploitation, the top attack vector, up from 20% in the prior edition. Sophos pins unpatched software as the technical root cause of 32% of ransomware attacks in 2025.
On a personal phone, an app updates itself overnight. On a managed fleet, it's another story: updates run through validation cycles, versions sometimes pinned to avoid breaking production, and users who keep postponing the restart. A patch can sit available for weeks without landing on your devices. And attackers know that gap. In 2025 the average time to exploit a flaw dropped to about 5 days, with a record of 51 seconds after disclosure. Nearly 28% of vulnerabilities are exploited the same day, sometimes before a patch even exists. Meanwhile, fixing a critical application vulnerability takes 43 to 74 days on average. That gap, between the patch being available and the patch actually deployed, is where attackers live. 60% of breaches involve a flaw for which a patch already existed but wasn't applied.
On the ground it comes down to obvious things. An outdated PDF reader, browser, or mail client on 200 devices is 200 entry points. On mobile the OS counts double: an iPhone or Android dragging its feet on updates leaves known holes wide open, and your users have no idea.
Scout: see your fleet's versions in plain sight
This is the blind spot Scout tackles. Scout is the CVE watch for your mobile and desktop apps, free to use. It indexes 24,155 CVEs, monitors 8,150 apps across iOS, Android, macOS, and Windows, and specifically tracks the 359 actively exploited flaws listed by CISA. Daily sync with the NVD, hourly updates.

You can use it three ways. Paste an app identifier, say com.microsoft.Office.Outlook, and get an instant verdict: is this version affected by a CVE, and worse, by a flaw already being exploited. Upload your MDM inventory export (Intune or Jamf formats) and Scout generates a compliance report with an SBOM. Or browse the app catalogs and search a vulnerability directly.
One honest caveat the tool owns: Scout is a floor, not a fleet audit. It tells you whether a deployed version is known to be vulnerable. It's not a penetration test or a guarantee of completeness. But for most teams that floor already sits far higher than what they have today, which is nothing. Scout also exposes an API to check deployed versions programmatically and wire the check into your own tools.

Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →From visibility to action
Seeing the problem is half the road. Closing it is the MDM's job. Scout gives you the diagnosis; Appaloosa MDM gives you the means to act: push app updates, enforce a minimum OS version, and gate access to resources on device compliance. Scout raises the alarm, the MDM brings the fleet back in line.
That's the logic behind how Appaloosa builds its offering: give the sysadmin and the CISO a way to measure the risk, then a way to make sure every device in the fleet stays current and compliant.
The bottom line
The question is no longer whether flaws hide in your apps, but which ones are already running on your devices. Scout gives you the answer, at scout.appaloosa.io. Turning that into an up-to-date fleet is exactly what Appaloosa does.
Ready to try Appaloosa? Start free