Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk5 min

Security Teams Are Patching More Vulnerabilities—Why Is Software Still Getting Riskier?

Security teams can patch more vulnerabilities while risk rises if new flaws and exposed assets outpace remediation. Verizon’s latest data shows why throughput, coverage and exploitability must be measured separately.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because fixing vulnerabilities faster is not the same as shrinking the amount of dangerous software attackers can reach. Verizon’s 2026 Data Breach Investigations Report (DBIR) found that remediation improved through earlier periods it analyzed, then slipped back toward 2023 levels in its 2025 dataset as vulnerability volume rose. In that same dataset, vulnerability exploitation was the most common initial access vector. The picture is not that patching has stopped helping; it is that incoming flaws, exposed systems and attacker activity can outpace a team’s capacity to remove risk.

What the latest figures say—and what they measure

Verizon’s 2026 DBIR reports on incidents from November 1, 2024, through October 31, 2025. Its measures describe different parts of the vulnerability problem, so a larger number of patches does not automatically mean a larger share of the exposed estate is safe.

As an Amazon Associate I earn from qualifying purchases.

Measure Reported result How to read it
Initial access in breach cases 31% of breaches in the 2026 DBIR dataset began with software vulnerability exploitation; credential abuse accounted for 13%. Exploitation was the most common initial access vector in this dataset. This is a share of reported breaches, not a share of all attacks or all vulnerabilities.
Critical KEV remediation 26% of critical vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully remediated in 2025, down from 38% in the prior reporting year. This concerns the critical KEV cohort, not every vulnerability organizations face.
Time to full resolution The median time for full resolution was 43 days in 2025, versus 32 days in the prior reporting year. This is a dataset median, not a forecast for any one organization. Verizon also says the median organization faced 50% more critical vulnerabilities to patch in the 2026 dataset.
Proactive patch volume 63.7 million vulnerability instances were proactively patched in 2025, a 30% increase from 48.9 million in 2024. Despite the higher volume, the preemptive remediation rate fell to 12% in 2025. The number patched and the share patched before a KEV listing are different measures.

These figures can move in opposite directions without contradicting one another: more fixes can be completed in absolute terms while a smaller proportion of the risky workload is cleared, or while completion takes longer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why software can get riskier even as teams fix more bugs

New work can arrive faster than teams can close it

A patch queue is a flow system. Security teams must identify affected products, determine whether assets are exposed, test fixes, coordinate downtime, and deploy changes. If new vulnerabilities and affected instances arrive faster than those steps can be completed, the open backlog can grow even as the team closes more tickets than before. Verizon’s 2026 report describes remediation improving through the 2024 dataset and then regressing toward 2023 levels in 2025 as vulnerability volume increased. That is a reported pattern, not a controlled experiment proving volume alone caused the change.

Patch counts do not show how much exposure remains

A count of completed fixes measures throughput. It does not tell a company what fraction of internet-facing, business-critical, or otherwise exploitable systems remain unprotected. A high patch total may include many low-impact instances while a small number of reachable, actively exploited flaws remain unresolved. Without asset and dependency coverage, teams cannot reliably connect ticket closure to reduced exposure.

Attackers may move before a normal patch cycle finishes

Verizon’s 2024 analysis found an average of 55 days to remediate half of critical CISA KEV vulnerabilities after patches became available, while its median detection time for mass exploitation of KEVs on the internet was five days. Those figures illustrate a timing mismatch in that analysis; they do not mean every exploit appears in five days, nor do they describe the same measurement or period as the 2026 report’s 43-day median full-resolution time.

Severity scores alone do not describe the risk of a particular system

A vulnerability’s practical urgency depends on where it exists and how it can be used. CISA’s FY2024–2025 Vulnerability Review, released August 26, 2026, points organizations to exposure status, KEV status, potential for automated exploitation, and technical impact. A flaw on a reachable system with credible exploitation evidence may deserve attention before a higher-scoring issue on an isolated asset.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some risk sits outside the team’s own patch queue

Organizations rely on supplier products, open-source dependencies, appliances, and older systems that may be difficult to inventory or update. CISA highlights continued use of end-of-support technology and poor patching as concerns. If a supplier’s component is embedded in a product or service, the customer may need an advisory, a workaround, or a replacement rather than a patch it can deploy directly.

Does faster remediation reduce breach risk?

Yes: when a fix removes an exploitable weakness from a reachable system, it can close an attack path. But speed is only one part of the outcome. Coverage, exposure, exploitability, and whether the fix actually reached affected assets also matter. Verizon’s 2026 finding that 31% of breaches in its dataset began with vulnerability exploitation shows why the work remains consequential; it does not prove that patching faster has no effect.

Verizon’s 2025 DBIR release described vulnerability exploitation as 20% of initial attack vectors, compared with 31% of breaches in the 2026 DBIR dataset. The figures come from different editions and periods and may use different definitions or denominators, so they should not be read as a clean year-over-year increase. The 2025 release is available from Verizon.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How teams can prioritize work that reduces risk

Rank by the conditions that make exploitation consequential

Use CISA’s factors together rather than sorting a large queue by severity score or age alone:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Is the affected asset exposed or reachable?
  • Is the vulnerability listed in CISA’s KEV catalog?
  • Could exploitation be automated?
  • What is the technical impact if the flaw is exploited?

NIST’s May 19, 2025 announcement for proposed CSWP 41 describes using community-provided probabilities to estimate exploitation likelihood and strengthen prioritization. That is an additional signal to consider, not a substitute for knowing which assets are exposed and what an exploit would affect.

Track risk removed, not only work completed

Pair operational counts with measures that connect fixes to the estate they protect. For example, track the share of known affected, exposed assets remediated; how long high-risk exposure remains after a fix or mitigation becomes available; and whether the inventory covers products and dependencies in use. Set targets based on your organization’s exposure and operational constraints rather than treating a published dataset median as a universal service level.

Build a response path for supplier vulnerabilities

NIST’s software supply-chain guidance recommends supplier vulnerability-disclosure capabilities, machine-readable advisories such as Vulnerability Exploitability eXchange (VEX), software bill of materials (SBOM) integration, and dedicated supplier response teams. Advisories should make it possible to identify affected products, understand impact and remediation, and find contacts and revision history. Integrating SBOMs with vulnerability databases and reporting mechanisms can help organizations learn when newly disclosed flaws affect components they use.

NIST’s guidance captures the operational goal: “In its discussion of Zero Trust Architecture, the EO recognizes that the discovery of vulnerabilities is inevitable, and federal agencies should focus on managing those vulnerabilities efficiently and comprehensively.” The practical implication is not to expect a flaw-free software estate, but to know what is deployed, identify what is exposed, and direct limited response capacity toward the vulnerabilities most likely to cause harm.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.