Most Critical Vulnerabilities Remain Unpatched Beyond 90 Days

www.news4hackers.com-most-critical-vulnerabilities-remain-unpatched-beyond-90-days-most-critical-vulnerabilities-remain-unpatched-beyond-90-days

Most open critical and high-severity vulnerabilities remain unaddressed for over 90 days, according to a report analyzing exposure data from 1,293 organizations across the US, UK, and Nordic countries.

Regional Analysis of Vulnerability Resolution

Detify’s findings reveal that a significant majority of these issues persist on internet-facing systems for extended periods. In the Nordics, 97% of critical and high-severity vulnerabilities identified in a single snapshot had been exposed for more than 90 days, compared to 92% in the UK and 86% in the US. The data highlights a persistent backlog of unresolved security gaps despite awareness of the risks.

Methodology and Key Observations

Detify’s analysis relies on payload-based testing, which simulates real-world attacks to confirm exploitability. The results indicate that many of these vulnerabilities are not newly discovered but have remained unpatched for months. In the most efficient market, less than 15% of critical or high-severity findings were under three months old. However, the 90-day metric reflects a snapshot of the backlog on a specific day rather than a measure of patching speed.

Long-standing legacy issues can disproportionately influence the data, even in organizations where most vulnerabilities are resolved quickly. The report also notes that some critical vulnerabilities may reside on low-value assets, behind additional security layers, or on systems scheduled for decommissioning. In such cases, leaving the flaw unaddressed may be a deliberate risk management decision.

Public Sector Challenges and Sector-Specific Data

Public-sector organizations face the greatest challenges in resolving vulnerabilities. They addressed only 8.3% of critical and high-severity findings, the lowest rate among five sectors analyzed. Consumer goods and brand companies resolved 46.2% of issues, followed by technology firms at 37.4%, financial institutions at 30.6%, and manufacturing at 23.9%. Public bodies resolved 4.3% of vulnerabilities in the Nordics and 2.3% in the US within 90 days of detection.

Rickard Carlsson, CEO of Detectify, attributed the difficulties in public-sector remediation to factors such as legacy infrastructure, fragmented ownership, lengthy procurement processes, and limited technical resources. He emphasized that even when security teams identify risks, organizational constraints—such as interdepartmental ownership, reliance on outdated vendors, or critical system downtime—can delay fixes.

Monitoring and Resolution Rates Across Regions

The UK demonstrates higher monitoring rates but lower resolution rates compared to other regions. While 72.4% of verified internet-facing domains are actively monitored, UK organizations closed only 18.6% of critical and high-severity findings over the lifetime of their accounts. This contrasts with the Nordics, where 31.9% of such issues were resolved, despite the region having the oldest backlog.

The US, which maintains the largest attack surface, monitors the smallest proportion of its internet-facing assets. US domains grew by 20% over 12 months, adding over 100,000 new systems, while UK and Nordic domains expanded by 14% and 3.4%, respectively.

Exposure of AI Tools and Governance Gaps

Exposure of AI tools presents additional challenges. Detectify identified publicly accessible AI platforms, including Lovable and Base44, with organizations managing these systems resolving critical and high-severity flaws at less than half the rate of the broader customer base. While the data does not confirm whether these tools represent “shadow AI,” the CEO noted an association between exposed AI infrastructure and gaps in asset visibility and governance.

Tools like Open WebUI or LibreChat, deployed by individual teams without formal oversight, may contribute to this issue. Carlsson stressed that the risk lies not in AI experimentation itself but in its integration into unmanaged infrastructure. Organizations must ensure visibility into AI systems, establish ownership, and apply standard vulnerability management practices to these assets.

Conclusion and Recommendations

The report underscores the need for improved governance as AI adoption accelerates. The findings highlight systemic challenges in vulnerability management across industries and geographies, emphasizing the importance of proactive risk assessment, resource allocation, and cross-functional collaboration to address persistent security gaps.



About Author

en_USEnglish