Nine in Ten Open Critical and High-Severity Vulnerabilities Remain Exposed for More Than 90 Days, Detectify Finds

ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Detectify’s H2 2026 Cyber Hygiene Index, based on a sample of 1,300 organizations across the US, UK and Nordics, shows that greater visibility into cyber exposure is not consistently translating into faster remediation, and organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

Nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days across organizations analyzed in the H2 2026 Cyber Hygiene Index from Detectify, the Swedish application security platform built and trusted by hackers. The problem was consistent across every market: 97% of open critical and high-severity vulnerabilities in the Nordics, 92% in the UK and 86% in the US had remained exposed for more than three months.

Cyber hygiene, as this index defines it, measures whether organizations know what's exposed on their attack surface and how quickly they act on it. On top of the challenge posed by unresolved exposure, Shadow AI is emerging as a new frontier in cyber hygiene, as organizations adopt AI tools and applications that may not be fully visible or controlled by security teams. Detectify is increasingly identifying publicly exposed instances of self-hosted AI platforms and AI-built applications across its customer base. Organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days. But organizationally, that is often what happens - the longer a known issue remains open without an incident, the easier it becomes to treat it as normal,” said Rickard Carlsson, CEO and co-founder of Detectify. “That is the risk in a stale backlog. Exposure can effectively become accepted without anyone ever making a conscious decision to accept it. The absence of an incident starts to feel like evidence that the risk is tolerable, even though nothing about the vulnerability itself has changed.”

Detectify’s data points to a mounting challenge for security teams. Exploit-verified known critical risks already remain unresolved for months, even as AI further accelerates the pace of software development and cyber threat activity. Meanwhile, the zero-day clock keeps ticking down, with the exploit window shrinking toward zero.

Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.

The findings point to three ways organizations can shorten the distance between discovery and remediation, from continuously discovering new internet-facing assets to giving critical findings enough context around exposure and ownership for engineers to act quickly and verifying that fixes have actually removed the risk. Increasingly, parts of that loop – including prioritization, re-testing and verification – can be automated, allowing security teams to keep pace as attack surfaces keep growing and agentic software development accelerates.

To learn more, access the full report here. For more information about Detectify, visit detectify.com.

About Detectify

Founded by ethical hackers in 2013, Stockholm-based Detectify is an application security platform trusted by over 2,100 organizations globally, from high-growth startups to the world’s largest enterprises and public institutions. Detectify equips modern security teams with clarity and control over their attack surface. Fueled by real-world validated payloads from its global community of elite ethical hackers and scaled through its own AI-driven engines, Detectify enables organizations and their agents to identify and fix truly exploitable vulnerabilities before attackers do.

“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days. But that is often what happens - the longer a known issue remains open without an incident, the easier it becomes to treat it as normal."

Contacts

Media contacts
​​Jorge Vicente, ​​PR & Communications at Detectify | ​press@detectify.com | ​+46 76-114 63 50
Rachel McIntosh, San Francisco PR for Detectify | rachel@sanfrancisco.fi | +358 41 313 0441

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article

More News

View More

Recent Quotes

View More
Symbol Price Change (%)
AMZN  246.67
+0.52 (0.21%)
AAPL  329.40
-9.00 (-2.66%)
AMD  607.57
-0.30 (-0.05%)
BAC  54.96
-0.51 (-0.92%)
GOOG  337.32
-1.84 (-0.54%)
META  738.79
+23.17 (3.24%)
MSFT  508.96
-0.26 (-0.05%)
NVDA  227.21
-1.65 (-0.72%)
ORCL  137.79
+5.19 (3.91%)
TSLA  352.84
-4.61 (-1.29%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.