Skip to content
High Percentage of Critical Vulnerabilities Remain for Over 90 Days

High Percentage of Critical Vulnerabilities Remain for Over 90 Days

First seen 5 Oct 2026, 02:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 03:03 UTC
  • •90% of critical vulnerabilities remain unpatched for over 90 days across multiple regions.
  • •Public sector organizations show the lowest resolution rates for critical vulnerabilities.
  • •Organizational psychology contributes to the normalization of unpatched vulnerabilities.

Detectify's report reveals that 90% of critical and high-severity vulnerabilities across 1,300 organizations in the US, UK, and Nordics remain for over 90 days. The breakdown shows 97% in the Nordics, 92% in the UK, and 86% in the US. The report emphasizes that the longer vulnerabilities remain unaddressed, the more they are normalized within organizations, leading to a dangerous backlog. This situation is exacerbated by the rapid pace of software development and threat activity. Detectify's methodology confirms that these vulnerabilities are verified risks, not just false positives. Public sector organizations are particularly lagging, with only 8.3% of critical findings resolved within 90 days. The report suggests that organizational inertia and risk tolerance drift contribute to this issue, as teams may accept vulnerabilities as a norm without addressing them.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-88771 published
A critical vulnerability with a CVSS score of 9.5 was published, indicating active exploitation.
Helpnetsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What percentage of vulnerabilities are unpatched?
90% of critical and high-severity vulnerabilities remain unpatched for over 90 days.
Which sectors are most affected?
Public sector organizations have the lowest resolution rates, with only 8.3% of critical findings resolved within 90 days.
What contributes to the backlog of vulnerabilities?
Organizational psychology and risk tolerance drift lead teams to normalize unpatched vulnerabilities over time.