Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because patching more is not the same as being safer. Verizon’s 2026 Data Breach Investigations Report (DBIR) shows security teams fixing a record volume of vulnerabilities. It also shows the share of the most dangerous flaws that get fully fixed falling, resolution times getting longer, and vulnerability exploitation becoming the most common way into a breach. Incoming flaws, exposed assets and attacker opportunities are growing faster than remediation capacity. This is a capacity and prioritization problem, not proof that patching doesn’t work.

The headline premise also needs one correction. Verizon’s data shows remediation improving through the 2022–2024 periods it analyzed. In 2025 the curve slid back toward 2023 levels as vulnerability volume rose. “Faster than ever” describes the volume of fixes more accurately than it describes speed.

What the 2026 data actually says

Verizon’s 2026 DBIR covers incidents from November 1, 2024 through October 31, 2025. These are the figures that matter for this question, with the measure each one uses.

Measure Figure Source and caveat
Breaches that began with exploitation of a software vulnerability 31%, the most common initial access vector, ahead of credential abuse at 13% Verizon 2026 DBIR; breach dataset, not a share of all organizations
Critical vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) catalog that were fully remediated 26% in 2025, down from 38% in the prior reporting year Verizon 2026 DBIR; KEV-listed flaws only
Median time for full resolution 43 days in 2025, up from 32 days Verizon 2026 DBIR; a dataset median, not a prediction for any one organization
Critical vulnerabilities facing the median organization 50% more in the 2026 dataset Verizon 2026 DBIR
Vulnerability instances proactively patched 63.7 million in 2025, up 30% from 48.9 million in 2024 Verizon 2026 DBIR; absolute volume
Preemptive remediation rate 12% in 2025 Verizon 2026 DBIR; share patched before KEV listing

The last two rows look contradictory, but they measure different things. The absolute number of patched instances rose sharply, while the share of flaws fixed before attackers were known to be using them fell. Teams are doing more work and still falling further behind on the flaws that matter most.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why risk can rise while remediation is happening

Throughput is not coverage

A count of closed tickets measures completed work. It says nothing about what fraction of the exposed, exploitable estate is still open. Verizon’s data separates the number of instances patched from the percentage remediated. It also reports that rising incoming volume is putting pressure on the system. If the inflow grows 50% and your output grows 30%, the backlog still grows.

Volume can erase process improvements

Verizon’s 2026 discussion describes the remediation survival curve improving through the 2024 dataset and then regressing in 2025 as more vulnerabilities flowed through. That is Verizon’s interpretation of the pattern. It is not a controlled experiment showing that volume alone explains all of the added risk, so read it as a strong correlation, not a proven single cause.

Attackers can move faster than the patch cycle

Verizon’s 2024 analysis of KEV entries found it took 55 days to remediate 50% of critical vulnerabilities after a patch became available. The median time to detect mass exploitation of KEVs on the internet was five days. That gap is the core timing problem. It comes from the 2024 analysis, though. It does not mean every exploit appears within five days, and it does not show the same gap today. The 2026 report’s 43-day median full-resolution figure uses different wording and a different cohort, so don’t chart the two as one continuous series.

Risk is contextual, and a sorted list hides it

CISA’s FY2024–2025 Vulnerability Review (its release is dated August 26, 2026) says to prioritize using exposure status, KEV status, potential for automated exploitation and technical impact. A queue sorted only by CVSS score or age can bury a lower-volume, internet-facing asset that has active exploitation evidence under thousands of theoretical findings. Closing those thousands raises your fix count without necessarily lowering your risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some risk sits outside your patch queue

CISA’s review points to simple known flaws, poor patching practices and continued use of end-of-support technology. The last of these cannot be fixed by working harder on patches, because no patches are coming. Supplier software adds another layer. NIST’s guidance on vulnerability management in software supply chains recommends that suppliers maintain vulnerability-disclosure capabilities, publish machine-readable advisories such as VEX, and run dedicated response teams. It also advises buyers to integrate software bills of materials (SBOMs) with vulnerability databases so they get rapid notice of newly released vulnerabilities.

NIST states the underlying premise this way: “In its discussion of Zero Trust Architecture, the EO recognizes that the discovery of vulnerabilities is inevitable, and federal agencies should focus on managing those vulnerabilities efficiently and comprehensively.” (NIST, Software Security in Supply Chains: Vulnerability Management; page created May 3, 2022, updated November 1, 2024.)

Reading the statistics without fooling yourself

Vulnerability statistics are easy to compare badly. One example from Verizon’s own reports: the 2026 DBIR puts exploitation at 31% of breach initial access, while Verizon’s 2025 DBIR release described exploitation of vulnerabilities as 20% of initial attack vectors. These editions cover different periods and may use different definitions or denominators, so treat the jump as a sign of direction, not a precise 11-point rise.

Before comparing programs, vendors or years, align four things:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The measure: median full resolution, share remediated, and time to remediate 50% are different metrics.
  • The population: KEV-listed flaws versus all flaws, and a breach dataset versus a general population of organizations.
  • The period and publication year: each DBIR edition covers a specific reporting window.
  • Exposure and exploitability context: a flaw on an internet-facing system with working exploit code is not equivalent to one on an isolated internal host.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do differently

Prioritize by credible exploitation, not by volume

Start from CISA’s four factors: exposure, KEV listing, automation potential and technical impact. NIST’s CSWP 41, announced May 19, 2025, goes a step further. It proposes a metric that estimates the probability a vulnerability is being exploited, using community-provided probabilities to sharpen prioritization. It is a proposal, so treat it as an emerging input rather than a settled standard. In practice, that means working first on flaws that have credible exploitation, are reachable by an attacker, would cause meaningful damage and can be attacked automatically.

Swap flattering metrics for ones that track exposure

Metric that flatters Metric that informs
Tickets or findings closed this month Share of KEV-listed vulnerabilities on your assets that are fully remediated
Average age of all open findings Time from KEV listing or patch release to full resolution on internet-facing assets
Total instances patched Share patched before exploitation is known (Verizon’s preemptive rate was 12% in 2025)
Scanner coverage of known assets Exposed assets and dependencies still running end-of-support software

These are suggested measures built from the factors in the Verizon and CISA material, not a standard scorecard from either source.

Extend visibility to suppliers and end-of-life software

Follow NIST’s supplier guidance. Ask vendors for advisories that include identifiers, dates, affected products, descriptions, impact, severity, remediation, references, discovery credit, contacts and revision history. Feed SBOMs into your vulnerability tracking so a newly disclosed flaw in a dependency reaches you quickly. Keep a list of end-of-support systems, because patching effort will never reduce that risk. They need replacement, isolation or a documented exception.

Tooling, if you need it

Exposure-management and vulnerability-management platforms can help if they cover your assets and dependencies, bring in exploitation intelligence, connect to ticketing and build pipelines, support remediation workflow and produce evidence for reporting. The sources establish these as the relevant evaluation criteria. They do not rank products, and no tool replaces the prioritization decisions above.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The takeaway

Remediation speed, remediation coverage, vulnerability volume and attacker exploitation are four separate measures, and a dashboard that tracks only the first can look healthy while exposure grows. The 2026 data shows exactly that: record patching effort, a falling share of critical KEV flaws fully fixed, and exploitation as the leading way into breaches. The practical goal is to remove high-risk exposure faster than new exposure arrives, and that is measured by what stays open, not by what closes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.