Attackers Are Already Exploiting These Vulnerabilities. Three Out of Four Still Aren't Fully Fixed
Imagine the police handed you a list of five doors burglars were actively using to break into houses in your neighborhood. You checked your house. One of those doors was yours. Six weeks later, it still wasn't completely locked. That sounds absurd. It's also close to what Verizon's newest breach research found is actually happening across thousands of businesses right now.
Imagine the police gave you a list of five doors burglars were actively using to break into houses in your neighborhood.
You checked your house. One of those doors was yours.
Six weeks later, it still wasn't completely locked.
That scenario sounds like a plot hole. Nobody would leave a known, actively-used entry point open for six weeks after being told about it directly. And yet Verizon's 2026 breach research, drawn from more than 13,000 organizations and over 527 million vulnerability instances, found something remarkably close to exactly that, playing out at scale across the businesses it studied.
The list already exists. Most people just aren't finishing the job.
The US government's Cybersecurity and Infrastructure Security Agency maintains a list called the Known Exploited Vulnerabilities catalog, or KEV. It's worth being precise about what that list actually is, because the word "known" is doing real work in that name. KEV isn't a list of vulnerabilities that might someday be dangerous. As we covered in an earlier explainer on this blog, it's a list of flaws CISA has confirmed are already being used in real attacks, right now. It's the closest thing security has to a police report naming the doors burglars are actually using.
of confirmed, actively-exploited vulnerabilities were NOT fully fixed by the organizations Verizon studied
Only 26% of vulnerabilities on the KEV list were fully remediated in 2025 — down sharply from 38% the year before. This isn't a list of theoretical risks getting deprioritized. It's the confirmed, currently-in-use list, and roughly three out of four instances of it were left partially fixed or entirely open across the environments Verizon examined.
The second contradiction, and it's worse than the first
Here's what makes this finding land harder than a routine patching statistic. In the same report, for the first time in the Data Breach Investigations Report's nineteen-year history, exploiting a vulnerability overtook stolen or compromised credentials as the single most common way attackers actually get into a network — now present in 31% of breaches, up from 20% the year before.
Why this is getting worse, not better
The honest answer isn't complacency. It's volume. The median number of confirmed-exploited vulnerabilities an organization had to deal with in a year rose from 11 to 16, roughly a 50% increase, and that's layered on top of the broader explosion in total vulnerability disclosures this year that we covered in an earlier post. Even businesses trying in good faith to keep up are working against a list that keeps growing faster than any reasonable patch cycle can clear it.
Verizon's own conclusion, stripped of jargon, is direct: choosing the correct vulnerabilities to patch is the actual strategy, not attempting to patch everything. That's the same argument our earlier explainer on CVSS, EPSS, and KEV made using different numbers. This year's data is the clearest evidence yet for why that argument matters in practice, not just in theory.
The SMB translation: why "117 findings" isn't an answer
Run a vulnerability scan against almost any small business network and you'll get a list. It might have a hundred items on it. It might have several hundred. That list, on its own, isn't useful — it's just noise with a number attached, and a business owner staring at it has no real way to know where to start.
A KEV listing is, in effect, the sharpest possible filter available for free: not "this could be bad," but "this is confirmed to be in active use, right now, somewhere." Treating that list as the starting point, rather than one more entry among hundreds ranked by severity score alone, is the single highest-leverage change most small businesses could make to how they patch.
The short version
Attackers didn't have to discover a secret weakness to drive vulnerability exploitation past stolen credentials as the top way into a business for the first time in nineteen years of this report existing. In many cases, the weakness was already published, already confirmed, and already sitting on a government list built for exactly this purpose. The police handed businesses the list of doors. Three out of four of those doors are still not fully locked, six weeks on average after anyone found out. The fix isn't a bigger security budget. It's starting with the list that's already confirmed, instead of the one that only looks scary.
See which of your vulnerabilities are actually confirmed to be under attack, not just theoretically severe.
View the Threat Intelligence feed → Find Out More About ThreatAngel →📚 Credential Security Series → Read the full series

Comments
Post a Comment