Expresscomputer.In High Percentage of Critical Vulnerabilities Remain for Over 90 Days
Article Content
- •90% of critical vulnerabilities remain unpatched for over 90 days across multiple regions.
- •Public sector organizations show the lowest resolution rates for critical vulnerabilities.
- •Organizational psychology contributes to the normalization of unpatched vulnerabilities.
Detectify's report reveals that 90% of critical and high-severity vulnerabilities across 1,300 organizations in the US, UK, and Nordics remain for over 90 days. The breakdown shows 97% in the Nordics, 92% in the UK, and 86% in the US. The report emphasizes that the longer vulnerabilities remain unaddressed, the more they are normalized within organizations, leading to a dangerous backlog. This situation is exacerbated by the rapid pace of software development and threat activity. Detectify's methodology confirms that these vulnerabilities are verified risks, not just false positives. Public sector organizations are particularly lagging, with only 8.3% of critical findings resolved within 90 days. The report suggests that organizational inertia and risk tolerance drift contribute to this issue, as teams may accept vulnerabilities as a norm without addressing them.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What percentage of vulnerabilities are unpatched?
Which sectors are most affected?
What contributes to the backlog of vulnerabilities?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…