Nine in ten critical vulnerabilities sit open for over 90 days. Why do teams let them linger?
Security teams have spent years investing in visibility. The assumption was simple: find the exposure, and the fixing will follow.
Detectify’s H2 2026 Cyber Hygiene Index suggests it isn’t working out that way. Based on a sample of 1,300 organisations across the US, UK and Nordics, the report finds that nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days. Greater visibility into cyber exposure, the Swedish application security company concludes, is not consistently translating into faster remediation.
The pattern held in every market studied. In the Nordics, 97% of open critical and high-severity vulnerabilities had been exposed for more than three months. In the UK the figure was 92%, and in the US 86%. No region comes out looking comfortable.
The danger of a quiet backlog
The most striking part of the report is less a statistic than an explanation of why the...
Copyright of this story solely belongs to www.expresscomputer.in. To see the full text click HERE