Attackers Are Already Exploiting These Vulnerabilities. Three Out of Four Still Aren't Fully Fixed


New Research
Patch Priority
September 2026  ·  7 min read

Imagine the police handed you a list of five doors burglars were actively using to break into houses in your neighborhood. You checked your house. One of those doors was yours. Six weeks later, it still wasn't completely locked. That sounds absurd. It's also close to what Verizon's newest breach research found is actually happening across thousands of businesses right now.


Imagine the police gave you a list of five doors burglars were actively using to break into houses in your neighborhood.

You checked your house. One of those doors was yours.

Six weeks later, it still wasn't completely locked.

That scenario sounds like a plot hole. Nobody would leave a known, actively-used entry point open for six weeks after being told about it directly. And yet Verizon's 2026 breach research, drawn from more than 13,000 organizations and over 527 million vulnerability instances, found something remarkably close to exactly that, playing out at scale across the businesses it studied.

The list already exists. Most people just aren't finishing the job.

The US government's Cybersecurity and Infrastructure Security Agency maintains a list called the Known Exploited Vulnerabilities catalog, or KEV. It's worth being precise about what that list actually is, because the word "known" is doing real work in that name. KEV isn't a list of vulnerabilities that might someday be dangerous. As we covered in an earlier explainer on this blog, it's a list of flaws CISA has confirmed are already being used in real attacks, right now. It's the closest thing security has to a police report naming the doors burglars are actually using.

74%

of confirmed, actively-exploited vulnerabilities were NOT fully fixed by the organizations Verizon studied

Only 26% of vulnerabilities on the KEV list were fully remediated in 2025 — down sharply from 38% the year before. This isn't a list of theoretical risks getting deprioritized. It's the confirmed, currently-in-use list, and roughly three out of four instances of it were left partially fixed or entirely open across the environments Verizon examined.

43 days median time to fully remediate a known-exploited vulnerability, up from 32 days the year before — moving in the wrong direction Verizon 2026 DBIR
60–70% of known-exploited vulnerabilities were still open at just 7 days after detection, regardless of an organization's size or tooling Verizon 2026 DBIR
11 → 16 the median number of confirmed-exploited vulnerabilities an organization had to patch in a year — roughly a 50% jump Verizon 2026 DBIR

The second contradiction, and it's worse than the first

Here's what makes this finding land harder than a routine patching statistic. In the same report, for the first time in the Data Breach Investigations Report's nineteen-year history, exploiting a vulnerability overtook stolen or compromised credentials as the single most common way attackers actually get into a network — now present in 31% of breaches, up from 20% the year before.

Put the two findings next to each other and the shape of the problem is unmistakable. Attackers are increasingly walking in through vulnerabilities at exactly the moment defenders are getting slower, not faster, at closing the ones already confirmed to be in active use. That's not two separate trends. It's one trend, told from both sides of the same door.

Why this is getting worse, not better

The honest answer isn't complacency. It's volume. The median number of confirmed-exploited vulnerabilities an organization had to deal with in a year rose from 11 to 16, roughly a 50% increase, and that's layered on top of the broader explosion in total vulnerability disclosures this year that we covered in an earlier post. Even businesses trying in good faith to keep up are working against a list that keeps growing faster than any reasonable patch cycle can clear it.

Verizon's own conclusion, stripped of jargon, is direct: choosing the correct vulnerabilities to patch is the actual strategy, not attempting to patch everything. That's the same argument our earlier explainer on CVSS, EPSS, and KEV made using different numbers. This year's data is the clearest evidence yet for why that argument matters in practice, not just in theory.

The SMB translation: why "117 findings" isn't an answer

Run a vulnerability scan against almost any small business network and you'll get a list. It might have a hundred items on it. It might have several hundred. That list, on its own, isn't useful — it's just noise with a number attached, and a business owner staring at it has no real way to know where to start.

Severity tells you how bad a vulnerability could theoretically be. Threat intelligence tells you whether attackers are actually using it right now. Those are two different questions, and this year's data is the clearest proof yet that answering only the first one, and skipping the second, is exactly how three out of four confirmed-active threats end up sitting unfixed for weeks.

A KEV listing is, in effect, the sharpest possible filter available for free: not "this could be bad," but "this is confirmed to be in active use, right now, somewhere." Treating that list as the starting point, rather than one more entry among hundreds ranked by severity score alone, is the single highest-leverage change most small businesses could make to how they patch.

This is precisely the philosophy behind the ThreatAngel CyberScore's approach to vulnerability findings. Rather than handing you a raw list ranked by theoretical severity, it's built to draw on sources including CISA's KEV catalog and the broader vulnerability landscape to help surface what's confirmed to matter today. A hundred findings isn't useful on its own. Knowing which three of them attackers are actually exploiting is the whole point.

The short version

Attackers didn't have to discover a secret weakness to drive vulnerability exploitation past stolen credentials as the top way into a business for the first time in nineteen years of this report existing. In many cases, the weakness was already published, already confirmed, and already sitting on a government list built for exactly this purpose. The police handed businesses the list of doors. Three out of four of those doors are still not fully locked, six weeks on average after anyone found out. The fix isn't a bigger security budget. It's starting with the list that's already confirmed, instead of the one that only looks scary.

See which of your vulnerabilities are actually confirmed to be under attack, not just theoretically severe.

View the Threat Intelligence feed → Find Out More About ThreatAngel →
TA
ThreatAngel Team AI-powered cyber risk clarity for SMBs  ·  threatangel.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.