Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Critical & High Vulnerabilities Remain Open >90 Days for Most Organizations, Public Sector Lags

Detectify’s analysis of 1,293 firms reveals that the vast majority of critical and high‑severity internet‑facing flaws have been exposed for over three months, with public bodies fixing fewer than 9 % of them. This backlog undermines control‑assurance programs that require timely remediation and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
5 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Most Open Critical & High Vulnerabilities Remain Unpatched for Over 90 Days

What Happened – Detectify’s scan of 1,293 organizations in the US, UK and Nordics shows that 97 % of critical and high‑severity flaws on internet‑facing assets have been exposed for more than 90 days. Public‑sector bodies resolve the fewest findings (under 9 % of critical/high issues), while consumer brands and technology firms perform better but still leave large backlogs.

Why It Matters for Trust & Control Assurance

  • Long‑lived critical flaws indicate a gap in the vulnerability‑management control objective – the very process continuous‑control programs are built to monitor, document and remediate.
  • Without evidence of timely patching, organizations struggle to provide a defensible audit trail for frameworks such as NIST CSF 2.0, which expects measurable remediation cadence.
  • The backlog creates “alternative risk‑tolerance drift,” where unpatched issues become de‑facto accepted risk, eroding the trust signal that continuous monitoring is meant to protect.

Who Is Affected – Government & public‑sector agencies, consumer‑brand companies, technology firms, financial services, manufacturing, and any organization with internet‑facing assets.

Recommended Actions

  • Map your vulnerability‑remediation workflow to the Verisq Trust Center to capture remediation dates, risk‑acceptance decisions, and ownership.
  • Prioritize patches on assets that are high‑value or exposed, and embed patch approval into change‑management tickets with audit‑ready evidence.
  • Establish a 30‑day SLA for critical/high findings and automate status reporting to satisfy continuous‑control monitoring requirements.

Source: Help Net Security article

Technical Notes

  • The data reflects payload‑based testing confirming exploitability of each flaw.
  • No single CVE is highlighted; the issue is systemic – prolonged exposure of critical/high vulnerabilities across sectors.
  • Public‑sector delays stem from legacy infrastructure, fragmented ownership, and lengthy procurement cycles.

Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →