October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence

VulnCheck says its $25 million Series B, led by Sorenson Capital, brings total funding to $45 million and will support expansion of its exploit-intelligence capabilities.
From TheFinanceBase Team3 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VulnCheck announced a $25 million Series B on February 17, 2026, led by Sorenson Capital. The company says the financing brings its total funding to $45 million and will help it scale its exploit-intelligence business. For security teams, the product’s central pitch is to prioritize vulnerabilities using evidence of exploitation—not disclosure or severity scores alone.

Who invested in VulnCheck’s Series B?

Sorenson Capital led the $25 million round. National Grid Partners also participated, alongside existing investors Ten Eleven Ventures and In-Q-Tel (IQT), according to VulnCheck’s February 17, 2026 announcement. Axios independently reported the financing.

VulnCheck says the investment brings its total funding to $45 million. The company described the capital as supporting growth and expanded intelligence capabilities for automation and AI-powered emerging-threat detection. Axios additionally reported plans to hire, expand product offerings and deepen the company’s international footprint. These are stated plans, not evidence that the expansion has already occurred.

What does VulnCheck sell?

VulnCheck describes itself as an exploit-intelligence company. Its offering is machine-consumable information about when software vulnerabilities become exploitable and how attackers use them. The intended use is to help enterprise and government security teams sort vulnerability reports across their environments and prioritize response with exploitation evidence and threat context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That approach addresses a practical distinction: a vulnerability’s publication or severity score does not, by itself, establish that attackers are exploiting it. Signals may include disclosure and severity, public exploit or proof-of-concept code, observed exploitation in the wild, and information about threat actors. Teams can assess intelligence products by asking how each signal is sourced and updated, whether data can feed their existing tools, and whether the evidence fits their own assets and response process. The funding sources do not establish that VulnCheck outperforms competing products.

What VulnCheck’s 2025 figures show—and what they do not

VulnCheck’s 2026 Exploit Intelligence Report uses 2025 calendar-year data captured on December 31, 2025. The company says it draws on more than two dozen VulnCheck indices and 500+ sources. It also cautions that attribution can emerge months after an incident or may never be reported. The figures below are VulnCheck’s reported findings, not independently verified, industry-wide measurements. Read the 2026 report.

VulnCheck-reported measure 2025 finding How to interpret it
New CVEs published More than 48,000; 83% had 2025 identifiers Counts published vulnerabilities, not the number known to be exploited.
Exploit development More than 14,400 exploits targeted 10,480 unique 2025 CVEs Exploit development or availability is not the same as observed exploitation in the wild.
CVEs exploited in the wild 1% of 2025 CVEs by the end of 2025 The report distinguishes confirmed in-the-wild exploitation from public proof-of-concept code.
Additions to VulnCheck’s KEV dataset 884 vulnerabilities, based on exploitation evidence from 118 unique sources This is a company dataset measure, not a count of every exploited vulnerability worldwide.
Ransomware-related CVEs discovered through zero-day exploitation 56.4% of 2025 ransomware CVEs The report says financially motivated actors were responsible; attribution caveats apply. It also says one-third of known 2025 ransomware CVEs had no public or commercial exploits available as of January 2026.

The contrast between exploit development and confirmed exploitation is important: code may exist without evidence that attackers have used it in real incidents. Conversely, observed exploitation can be difficult to attribute promptly, so a year-end dataset reflects both its collection methods and the information available by its cutoff.

What the company says about its growth

In its February 2026 announcement, VulnCheck reported year-over-year growth of 557% in enterprise annual recurring revenue (ARR) and 306% in government ARR. Those are company-reported growth rates; the announcement does not establish starting revenue or absolute scale. They should not be read as audited market data or as a measure of customer outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VulnCheck founder and CEO Anthony Bettini told Axios: “The vulnerabilities that are getting exploited typically aren’t zero days.” Sorenson Capital partner Ken Elefant said in the company announcement that exploitability data can help enterprises prioritize severe issues more quickly. Both are attributed views that explain the company’s investment thesis, not independent evaluations of product performance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the funding means for security buyers

The financing gives VulnCheck capital to pursue its stated expansion, but does not by itself establish what the company will deliver or how its product compares with alternatives. Security teams considering exploit intelligence can focus on concrete operational questions:

  • Does the data distinguish proof-of-concept availability from confirmed exploitation?
  • Can the provider show the source and timing behind an exploitation claim?
  • How quickly are indicators updated, and how are late or revised attributions handled?
  • Can the data map to the organization’s software inventory and existing vulnerability workflow?
  • Does the intelligence improve prioritization for the team’s threat model, rather than add alerts without actionable context?

Those questions apply to the product category; the available funding coverage does not provide comparative test results or independent validation of VulnCheck’s answers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.