HackRead

Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated


A recent Verizon study found that vulnerability exploitation became the most common initial access vector, appearing in 31% of breaches. Credential abuse accounted for 13%, while ransomware appeared in 48% of breaches, up from 44% the previous year.

The Access Route Got Older, Not Smarter

Much of the current security discussion centres on AI-related threats, but Verizon’s data shows that known and unpatched vulnerabilities remain a common entry point. These flaws are documented, catalogued and often left unresolved for weeks. Securing AI systems matters, but organizations are still being breached through weaknesses for which fixes already exist.

The remediation numbers make the mechanism plain. Verizon found that only 26% of detected vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalogue were fully remediated, down from 38% the previous year. The median time to full resolution also increased from 32 to 43 days.

The median organization was carrying 50% more critical vulnerabilities than it had been twelve months earlier.

TrendAI found that 70.14% of requested exploits targeted vulnerabilities disclosed more than two years earlier, while nearly 8% involved flaws between 10 and 15 years old. It also found that 31% of requested exploits concerned vulnerabilities already listed in CISA’s KEV catalogue. Separately, more than 270,000 systems remained exposed to CVE-2020-0796 as of February 2026, six years after its disclosure.

What sits between those two facts is an interval. A vulnerability gets published, catalogued and understood, and then nothing changes on the fleet for weeks.

“Manual work is the new attack surface,” says Ryan Braunstein, Security Manager at Automox. “Every manual task, whether it’s managing tickets, tracking spreadsheets, or manually patching systems, provides extra time for an attacker to exploit something.”

A remediation window isn’t a project timeline. It’s a period during which a documented, publicly enumerated weakness stays available to anyone reading the same catalog defenders read. The asymmetry here is that attackers can act faster than defenders.

That interval is measurable, and it’s long. Automox’s 2026 survey of IT professionals discovered that 51% take five or more days to patch on average or don’t know their mean time to patch at all. Roughly 1 in 10 reported an MTTP of under a day.

Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated

Volume Is the Reason Triage Stopped Working

The prioritization bottleneck is a volume problem before it’s a judgment problem. Beazley Security’s Q2 2026 analysis found disclosed vulnerabilities rose 36% quarter over quarter, following an 18.5% rise the quarter before. Vulnerabilities confirmed as actively exploited and added to CISA’s catalog rose 10% over the same period.

That gap is the prioritization problem stated numerically. The same analysis notes that NIST no longer enriches every new CVE, which quietly removes a triage input a lot of programs were built on.

The queue outgrew the people working it, at least that’s what Automox data shows. The company’s survey found that 43% of teams spend 10 or more hours a week on manual endpoint tasks and 6% spend more than 40. Only 6% describe their organization as fully automated and 42% still track patch and vulnerability status in spreadsheets or dashboards. Asked which single task they’d automate first, 39% chose patch installation.

With disclosed vulnerability volume up 36% during Q2 and many triage processes still dependent on manual work, the volume of findings can exceed what existing teams can process.

In July 2026, Automox placed an integration with Tenable Vulnerability Management into limited beta. It imports selected findings, matches affected assets with Automox-managed endpoints and separates the results into patchable findings, unmatched findings and unmanaged devices. Patch and restart actions still require review and confirmation, while assets outside Automox remain visible as coverage gaps.

Automox has also applied this model to vulnerabilities without an available patch. In September, the company introduced an AI-drafted Mitigation Worklet pipeline that produces configuration changes and temporary workarounds. Automox says each draft passes more than a dozen automated checks and human review before entering its Worklet Catalog, with customers deciding whether to deploy it. The company acknowledges that the system cannot address every vulnerability.

The system reads new disclosures and drafts configuration changes or temporary workarounds, each of which clears a dozen or so automated checks and a human review before it lands in the Worklet Catalog, and customers still choose what runs.

Automox says its pipeline applies more than a dozen automated checks followed by human review, with draft mitigations produced in minutes or hours. The company also acknowledges that the system cannot address every vulnerability.

Patching does not close every route into an organization. Sophos’s State of Ransomware 2026 reported that compromised identities featured in 79% of ransomware attacks, while malicious email (26%) and phishing (24%) were the two most commonly reported root causes. Exploited vulnerabilities were no longer the leading answer among respondents.

These figures are not directly comparable with Verizon’s breach-wide findings. Sophos surveyed 2,158 organizations that had experienced ransomware during the previous year, all with 100 to 5,000 employees, while Verizon analyzed confirmed breaches across a much broader dataset. Together, the findings show that patching reduces one major entry route but does not address identity compromise, malicious email or phishing.

Where machine speed is being applied, it’s mostly not being applied here. IBM’s Cost of a Data Breach Report 2026 found 50% of organizations now deploy AI agents somewhere in the security operations center, but only 18% apply them to vulnerability scanning and management. Another 37% say they plan to.

Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated

The Boring Investment Is the Defensible One

The most defensible security spending of the AI era may be the least interesting. The catalog of what attackers are actually using is published, free, and updated continuously. 

Finding a vulnerability is only the first step. The remaining risk depends on whether affected systems are identified, prioritised and changed before attackers exploit them.





Source link