Nine in ten critical vulnerabilities sit open for over 90 days. Why do teams let them linger?

Security teams have spent years investing in visibility. The assumption was simple: find the exposure, and the fixing will follow.

Detectify’s H2 2026 Cyber Hygiene Index suggests it isn’t working out that way. Based on a sample of 1,300 organisations across the US, UK and Nordics, the report finds that nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days. Greater visibility into cyber exposure, the Swedish application security company concludes, is not consistently translating into faster remediation.

The pattern held in every market studied. In the Nordics, 97% of open critical and high-severity vulnerabilities had been exposed for more than three months. In the UK the figure was 92%, and in the US 86%. No region comes out looking comfortable.

The danger of a quiet backlog

The most striking part of the report is less a statistic than an explanation of why the numbers look the way they do. Rickard Carlsson, Detectify’s CEO and co-founder, argues that the problem is psychological as much as technical.

“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days,” he said. “But organisationally, that is often what happens – the longer a known issue remains open without an incident, the easier it becomes to treat it as normal.”

The risk, in his telling, is that exposure gets accepted by default. “Exposure can effectively become accepted without anyone ever making a conscious decision to accept it,” Carlsson said. “The absence of an incident starts to feel like evidence that the risk is tolerable, even though nothing about the vulnerability itself has changed.”

Anyone who has managed a security backlog will recognize the dynamic. Each week without a breach quietly lowers the urgency, and a finding that once triggered alarm becomes background noise. The danger is that the logic is circular: the lack of an incident is read as proof of safety, which justifies leaving the issue open, which prolongs the exposure.

It would be easy to dismiss a backlog number as inflated by low-quality alerts. Detectify’s methodology makes that harder. Because the assessments test real-world exploitability through a 100% payload-based approach, the open items in the data are verified risks rather than scanner guesses.

That matters, because the usual defense of a long backlog is that most of it is noise. Here, the report describes exploit-verified known critical risks that have gone unresolved for months, at a time when AI is speeding up both software development and threat activity. The zero-day clock keeps ticking down, with the exploit window shrinking toward zero. A 90-day-old critical flaw is increasingly an invitation to attackers who can move far faster than that.

There is an important caveat, and the report states it plainly. A delayed fix does not always mean inaction. A technically critical vulnerability on a low-sensitivity asset, or one sitting behind compensating controls, may reflect a deliberate business decision to deprioritize it based on internal context. The distinction is what separates risk acceptance from risk neglect: the former is a decision someone made and can defend, while the latter is simply what happens when no one decided anything. The data cannot say how many of the open findings fall on which side, but Carlsson’s warning is aimed squarely at the second kind.

Shadow AI adds a new blind spot

The report also identifies what it calls a new frontier in cyber hygiene: Shadow AI. As organisations adopt AI tools and applications faster than security teams can track them, some end up exposed to the internet without anyone in security knowing.

Detectify says it is increasingly finding publicly exposed instances of self-hosted AI platforms and AI-built applications across its customer base. And the consequence shows up in the remediation data: organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

The report does not claim that AI tooling causes slower fixes, and the correlation could run in several directions. Organisations that deploy AI tools quickly may also be the ones stretched thinnest on security capacity. But the pairing is a useful warning sign. Teams that cannot see or control what AI their business is running are poorly placed to fix what that AI exposes.

Closing the gap between finding and fixing

If visibility alone does not produce results, what does? Detectify’s findings point to three ways organisations can shorten the distance between discovery and remediation.

The first is continuous discovery of new internet-facing assets. An attack surface that changes weekly cannot be defended with quarterly inventories, and the rise of Shadow AI makes the case stronger. The second is making findings actionable. A critical alert that arrives without context on exposure and ownership tends to stall, while one that tells an engineer what is affected, who owns it and why it matters can be acted on quickly. The third is verification: confirming that a fix has actually removed the risk, rather than assuming a closed ticket means a closed hole.

Increasingly, parts of that loop, including prioritization, re-testing and verification, can be automated. That is significant for teams already struggling to keep pace as attack surfaces grow and agentic software development accelerates. When developers, and soon software agents, ship changes continuously, a remediation process that depends on manual triage will fall further behind each quarter.

The bottom line

The headline figure should concern any executive responsible for risk, but the deeper lesson is about how organizations behave once they know. Finding vulnerabilities is no longer the hard part. The harder work is refusing to let a known critical issue become normal, deciding deliberately which risks to accept and which to fix, and making sure the pace of remediation matches a threat landscape that is moving faster every year.

Enterprise Security
Comments (0)
Add Comment