Vast Backlog of Unpatched Critical Vulnerabilities Plagues Organizations
Research reveals a significant backlog of unpatched critical and high-severity vulnerabilities on internet-facing systems, with many flaws remaining open for over 90 days.

A new analysis by Detectify, examining data from 1,293 customers across the US, UK, and Nordics, highlights a pervasive issue with timely patch management. The study found that a substantial majority of critical and high-severity vulnerabilities present on internet-facing systems remain unaddressed for extended periods. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than 90 days at the time of the data snapshot.
These are not unknown issues; Detectify's methodology involves payload-based testing, confirming that the identified vulnerabilities are indeed exploitable. This indicates a systemic problem where organizations are aware of critical security weaknesses but are failing to remediate them promptly. In the best-performing regions, less than 15% of open critical or high findings are less than three months old, underscoring the depth of the patching backlog.
While the 90-day metric provides a snapshot, Detectify acknowledges that not all unpatched vulnerabilities represent immediate risks. Some may reside on low-value assets, be protected by other security controls, or be on systems slated for retirement. However, the report cautions against 'risk tolerance drift,' where long-unaddressed flaws are implicitly accepted by default, potentially leading to a false sense of security.
The public sector appears to be struggling the most with vulnerability remediation, resolving only 8.3% of its critical and high-severity findings within 90 days. This lags significantly behind other sectors such as consumer packaged goods (46.2%), technology (37.4%), financial and banking (30.6%), and manufacturing (23.9%). Public-sector organizations often face challenges like legacy infrastructure, fragmented ownership, lengthy procurement processes, and limited specialist capacity, making timely patching a complex undertaking.
Interestingly, while UK organizations actively monitor a higher percentage of their internet-facing domains (72.4%) compared to the Nordics (31.9%) and the US (28.9%), they have closed the lowest percentage of critical and high findings over time (18.6%). This suggests that while monitoring is robust, the actual remediation rate is lagging, leading to a persistent backlog.
The report also draws attention to the slower remediation rates for exposed AI tools. Organizations with publicly exposed AI platforms are resolving critical and high-severity flaws at less than half the rate of the general customer base. While not definitively attributing this to 'shadow AI,' Detectify suggests it may reflect a common gap in asset visibility and governance, particularly with rapidly deployed tools like Open WebUI or LibreChat that might bypass traditional inventory and security review processes.
Detectify emphasizes the need for organizations to improve asset visibility and governance, especially concerning newer technologies like AI. Knowing what is running, who owns it, and ensuring these systems fall under the same rigorous vulnerability management processes as established assets is crucial. The danger lies not in experimentation, but in experimentation that becomes invisible infrastructure, creating unmanaged risk.
This widespread backlog of unpatched vulnerabilities presents a significant attack surface for threat actors. The failure to address critical and high-severity flaws in a timely manner leaves organizations exposed to potential breaches, data loss, and operational disruption, underscoring the urgent need for improved patch management strategies and better asset visibility across all sectors.