Unpatched Vulnerabilities Now Top Cause of Breaches, Remediation Rates Falling
The Verizon 2026 Data Breach Investigations Report, analyzing over 22,000 confirmed breaches across 145 countries, found that exploitation of unpatched vulnerabilities now accounts for 31% of initial access — surpassing phishing and stolen credentials for the first time in the report's 19-year history. Remediation rates are worsening: only 26% of vulnerabilities on CISA's Known Exploited Vulnerabilities list were fully resolved in 2025, down from 38% the prior year, while median fix time grew from 32 to 43 days. CVE volume is also accelerating, with 48,185 new vulnerabilities disclosed in 2025 — roughly 131 per day — making backlog management increasingly difficult for security teams. A 2025 Sophos study separately identified exploited software vulnerabilities as the leading root cause of ransomware attacks, responsible for about 32% of incidents. Security leaders now face compounding risks: unresolved vulnerabilities not only raise breach probability but can also trigger compliance violations and cyber insurance claim denials if prior knowledge of a flaw goes undocumented.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in