Skip to main content

CNiC Solutions

IT professional analyzing network data on a large digital screen in a data center.

In 2025 the average high or critical software flaw took 54.81 days to patch, while attackers reached mass exploitation of newly disclosed vulnerabilities in a median of just 5 days. That gap, weeks of exposure on flaws criminals are already using, is the core patch management story of 2026.

Key takeaways

  • The volume is unmanageable by hand: a record 48,185 CVEs were published in 2025 (about 131 per day), up from 40,009 in 2024. (Edgescan, NIST)
  • Fixing takes weeks, not days: average MTTR for a high or critical application and API flaw was 54.81 days in 2025; complex enterprise apps averaged 5 months and 10 days. (Edgescan, Qualys)
  • Even known-exploited flaws linger: only 38% of CISA Known Exploited Vulnerabilities were fully remediated, and about 1 in 3 edge KEVs were never fixed. (Verizon 2025 DBIR)
  • Attackers move first: the median time from disclosure to mass exploitation was 5 days overall and 0 days for edge devices. (Verizon 2025 DBIR)
  • The stakes are rising: vulnerability exploitation appeared in 1 in 5 breaches, a 34% year-over-year jump, and was the most common root cause of ransomware at 32%. (Verizon, Sophos)
  • Backlogs are the norm: large enterprises left 45.4% of discovered vulnerabilities unresolved within 12 months. (Edgescan)
  • Small businesses feel it hardest: ransomware was present in 88% of small-business breaches versus 39% at large organizations. (Verizon 2025 DBIR)

 

 

Infographic of 2026 patch management statistics: 54.8-day fix time, 5-day exploit time, 38% KEV remediation, 48,185 CVEs
Four headline figures show the 2026 patch gap between defenders and attackers (Verizon DBIR, Edgescan, NIST).

 

 

What’s in This Report

1 The Vulnerability Flood: How Many Patches We Face

Patch management starts with a supply problem. The number of vulnerabilities disclosed every year has reached a level no team can address one at a time, which is why remediation now depends on prioritization rather than brute force.

48,185
CVEs published in 2025, a record, working out to roughly 131 new vulnerabilities every day.Edgescan 2026 Vulnerability Statistics Report / NIST NVD
1,139
CVEs Microsoft alone patched across its 2025 Patch Tuesday releases, including 41 zero-days, 24 of them exploited in the wild.Tenable, Microsoft Patch Tuesday 2025 Year in Review
28%
Share of incoming CVEs the National Vulnerability Database was able to fully enrich in 2025, leaving teams to triage the rest with less official context.NIST

CVE Publication Volume by Year

2025
48,185
2024
40,009

2025 set a record for published CVEs, a roughly 20% increase over the prior year. Source: Edgescan 2026 Vulnerability Statistics Report; NIST NVD.

The takeaway for any business is simple: no in-house team patches 48,000 flaws a year. The job is to find the small fraction that actually threatens your systems and fix those first, which is exactly what a disciplined managed vulnerability and patching program is built to do. Our companion breakdown of exploited CVEs and zero-day timing digs deeper into which of those flaws attackers weaponize.

Source: Edgescan Vulnerability Statistics Report | NIST National Vulnerability Database | Tenable Patch Tuesday 2025 Review

2 Mean Time to Remediate: How Long Patching Really Takes

Mean time to remediate, or MTTR, is the average number of days between discovering a vulnerability and fully fixing it. It is the metric that matters most in patch management because it measures how long an exploitable hole stays open. In 2025 those windows stayed stubbornly wide.

54.8 days
Average MTTR for a high or critical application and API vulnerability in 2025.Edgescan 2026 Vulnerability Statistics Report
38 days
Median time to remediate a vulnerability already listed in the CISA Known Exploited Vulnerabilities catalog.Verizon 2025 DBIR
5 mo 10 d
Average MTTR for complex enterprise applications such as Java, .NET, and Citrix, where compatibility testing slows every deployment.Qualys 2026 Enterprise Patch & Remediation Benchmark

Mean Time to Remediate by Vulnerability Type (Days)

Complex apps (Qualys)
~160
High/critical app & API
54.8
All known-exploited (KEV)
38
Edge-device KEV
32

Even the fastest category, actively exploited edge-device flaws, still averages a month to fix. Sources: Edgescan, Verizon 2025 DBIR, Qualys.

Teams do triage the scariest flaws faster: an internet-facing device with a known exploit gets fixed in about 32 days, roughly three weeks quicker than an average high-risk application bug. But “faster” is relative. A month is still a long time to leave a door open when attackers are already walking through it, a gap we quantify in the exploitation section below.

See how managed IT keeps patching on schedule

Source: Edgescan Vulnerability Statistics Report | Verizon 2025 Data Breach Investigations Report | Qualys 2026 Patch Benchmark

3 Patch Backlogs: The Vulnerabilities Left Behind

Because disclosure outpaces remediation, unfixed findings pile up. The patch backlog, the set of known issues a business has not yet closed, is now a permanent feature of enterprise security rather than a temporary lapse.

45.4%
Share of discovered vulnerabilities that large enterprises left unresolved within a 12-month period, concentrated in the network and device layer.Edgescan 2025 Vulnerability Statistics Report
33%+
Proportion of all discovered vulnerabilities rated critical or high severity, so a large slice of the backlog is genuinely dangerous.Edgescan 2025 Vulnerability Statistics Report
62%
Share of catalogued known-exploited vulnerabilities NOT fully remediated (only 38% were fully fixed).Verizon 2025 DBIR
Backlog metric Figure What it means
Vulnerabilities unresolved within 12 months (large enterprises) 45.4% Nearly half of findings age past a year
Discovered vulnerabilities rated critical or high Over 33% A third of the backlog is high-stakes
All KEVs fully remediated 38% Most known-exploited flaws stay open
Edge-device KEVs fully remediated 54% Better, but nearly half remain
Edge-device KEVs left fully unremediated ~33% Highest non-remediation rate in the DBIR

Myth: “We ran a scan, so we are covered.” A scan only produces a list. The Verizon and Edgescan data show that discovery is the easy half; the hard half is closing findings before they age out. An organization that scans monthly but remediates 38% of known-exploited flaws is documenting its exposure, not reducing it. Remediation, not detection, is where patch programs succeed or fail.

Get a free security audit to size your backlog

Source: Edgescan Vulnerability Statistics Report | Verizon 2025 Data Breach Investigations Report

 

CNiC Solutions — Cybersecurity

 

4 Remediation Rates by Severity, Asset and Industry

Headline averages hide big differences. How fast a flaw gets fixed depends on how dangerous it is, where it lives, and what industry runs the system. These cuts of the data explain why two businesses can face the same vulnerability yet carry very different risk.

63 days
Fastest sector MTTR, achieved by software companies, the industry most practiced at shipping fixes.Edgescan 2025 Vulnerability Statistics Report
104 days
Slowest sector MTTR, in construction, where operational systems are hard to take offline for patching.Edgescan 2025 Vulnerability Statistics Report
32 vs 38
Days to remediate an edge-device KEV versus all KEVs: internet-facing assets get prioritized, but only by about a week.Verizon 2025 DBIR

Mean Time to Remediate by Industry, Fastest vs Slowest (Days)

Construction (slowest)
104
Software (fastest)
63

The slowest sector takes over 40 days longer than the fastest to fix the same class of flaw. Source: Edgescan 2025 Vulnerability Statistics Report.

The pattern holds across the data: severity and internet exposure pull remediation faster, while operational complexity and legacy hardware push it slower. Regulated small and midsize businesses, in healthcare, finance, and manufacturing, often sit on the slow end because their systems cannot simply be rebooted mid-shift. That is where a documented patch strategy, often owned by a virtual CIO, closes the gap without disrupting operations.

Modernize the infrastructure behind slow patch cycles

Source: Edgescan Vulnerability Statistics Report | Verizon 2025 Data Breach Investigations Report

5 The Race Against Exploitation: Why the Clock Matters

Patch metrics only matter because attackers are racing the same clock. In 2026 the data shows they are winning the opening laps: exploitation now begins before, or at the moment, most defenders even start.

5 days
Median time from public disclosure to mass exploitation across all known-exploited vulnerabilities; for edge devices it was zero days.Verizon 2025 DBIR
1 in 5
Breaches that involved vulnerability exploitation, a 34% jump year over year and the second-most-common breach path.Verizon 2025 DBIR
33%
Share of intrusions that began with an exploit, the single most common initial infection vector for the fifth year running.Mandiant M-Trends 2025

 

 

Timeline infographic showing attackers exploit flaws in 5 days while fixes take 54.8 days, a 50-day exposure window
Attackers reach mass exploitation in a median of 5 days; the average high-risk fix takes 54.8 days (Verizon DBIR, Edgescan).

 

 

Exploitation metric Figure Source
Median disclosure to mass exploitation (all KEV) 5 days Verizon 2025 DBIR
Median disclosure to mass exploitation (edge devices) 0 days Verizon 2025 DBIR
Breaches involving vulnerability exploitation 20% (+34% YoY) Verizon 2025 DBIR
Exploitation breaches that hit edge devices 22% (8x prior year) Verizon 2025 DBIR
Intrusions starting with an exploit 33% Mandiant M-Trends 2025
CVEs first exploited in the wild in 2024 768 Edgescan 2025 Report

Build recovery that survives a missed patch

Source: Verizon 2025 Data Breach Investigations Report | Mandiant M-Trends 2025 | Edgescan Vulnerability Statistics Report

6 What Slow Patching Costs Small Businesses

For a small or midsize business, the patch gap is not an abstract metric. It is the most common way ransomware gets in, and small companies absorb the damage at a far higher rate than large ones.

32%
Ransomware attacks in which an exploited vulnerability was the technical root cause, the top cause for the third year running.Sophos State of Ransomware 2025
88%
Small-business breaches that involved ransomware, compared with just 39% at large organizations.Verizon 2025 DBIR
44%
All analyzed breaches that involved ransomware in 2025, up from 32% the year before.Verizon 2025 DBIR
Why patch gaps hurt SMBs Figure Source
Ransomware root cause that was an exploited flaw 32% Sophos State of Ransomware 2025
SMB breaches involving ransomware 88% Verizon 2025 DBIR
Large-org breaches involving ransomware 39% Verizon 2025 DBIR
All breaches involving ransomware 44% Verizon 2025 DBIR

The reason smaller organizations are hit harder is the same reason their MTTR runs high: fewer hands, slower patch cycles, and thinner incident response. Attackers know it. Closing the exploited-vulnerability path, the entry point in roughly a third of ransomware cases, is the highest-return move a small business can make, and it is almost entirely a patching and configuration discipline.

Get a patch strategy built for your business

Source: Sophos State of Ransomware 2025 | Verizon 2025 Data Breach Investigations Report

7 CISA KEV and Patch Deadlines: The Compliance Benchmark

If 48,000 CVEs a year is too many to chase, the CISA Known Exploited Vulnerabilities catalog is the shortlist that matters. It names the flaws confirmed to be under active attack, and for federal agencies it comes with hard remediation deadlines that private businesses increasingly treat as a benchmark.

1,484
Total entries in the CISA Known Exploited Vulnerabilities catalog by the end of 2025, with 246 added during the year.Edgescan 2026 Vulnerability Statistics Report
246
Vulnerabilities added to the KEV catalog in 2025, each one confirmed as actively exploited, up from 185 added in 2024.Edgescan Vulnerability Statistics Reports
3 days
Remediation deadline CISA has reportedly weighed for KEV flaws, down from an average of two to three weeks under BOD 22-01.SC Media / CISA BOD 22-01

 

 

Infographic showing 38% of all KEVs and 54% of edge KEVs remediated, with the CISA KEV catalog growing to 1,484 entries
Only 38% of known-exploited vulnerabilities were fully remediated in 2025 as the CISA KEV catalog grew to 1,484 entries (Verizon DBIR, CISA).

 

 

CISA KEV metric 2024 2025
Total catalog entries (year end) 1,238 1,484
Vulnerabilities added during the year 185 246
Share of all KEVs fully remediated n/a 38%
Share of edge KEVs fully remediated n/a 54%

Source: CISA Known Exploited Vulnerabilities Catalog | CISA Binding Operational Directive 22-01 | Edgescan Vulnerability Statistics Report

8 Every Patch Management Statistic in One Table

A single reference view of every figure in this report, with its primary source and year. Journalists and analysts are welcome to cite these with attribution.

Statistic Figure Source Year
CVEs published 48,185 Edgescan / NIST NVD 2025
CVEs published (prior year) 40,009 Edgescan 2024
Average new CVEs per day ~131 Edgescan / NIST NVD 2025
CVEs NVD fully enriched 28% NIST 2025
Microsoft CVEs patched (Patch Tuesday) 1,139 Tenable 2025
Microsoft zero-days patched 41 (24 exploited) Tenable 2025
MTTR, high/critical app & API 54.81 days Edgescan 2025
Median MTTR, all KEVs 38 days Verizon DBIR 2025
Median MTTR, edge-device KEVs 32 days Verizon DBIR 2025
MTTR, complex enterprise apps 5 mo 10 d Qualys 2026
MTTR, software sector (fastest) 63 days Edgescan 2024
MTTR, construction sector (slowest) 104 days Edgescan 2024
Vulnerabilities unresolved within 12 months 45.4% Edgescan 2024
Discovered vulnerabilities rated critical/high Over 33% Edgescan 2024
All KEVs fully remediated 38% Verizon DBIR 2025
Edge KEVs fully remediated 54% Verizon DBIR 2025
Edge KEVs left fully unremediated ~33% Verizon DBIR 2025
Median disclosure to mass exploitation (all KEV) 5 days Verizon DBIR 2025
Median disclosure to mass exploitation (edge) 0 days Verizon DBIR 2025
Breaches involving vulnerability exploitation 20% (+34% YoY) Verizon DBIR 2025
Exploitation breaches hitting edge devices 22% (8x) Verizon DBIR 2025
Intrusions starting with an exploit 33% Mandiant M-Trends 2025
Ransomware with an exploited flaw as root cause 32% Sophos 2025
SMB breaches involving ransomware 88% Verizon DBIR 2025
All breaches involving ransomware 44% Verizon DBIR 2025
CISA KEV catalog entries (year end) 1,484 Edgescan 2025
Vulnerabilities added to KEV catalog 246 Edgescan 2025
CVEs first exploited in the wild 768 Edgescan 2024

9 Frequently Asked Questions

What is the average time to patch a vulnerability in 2026?

Edgescan’s 2026 Vulnerability Statistics Report puts the average mean time to remediate (MTTR) a high or critical application and API vulnerability at 54.81 days in 2025. For the specific subset of already-exploited flaws in the CISA Known Exploited Vulnerabilities catalog, Verizon’s 2025 DBIR found a faster median of 38 days across all KEVs and 32 days for internet-facing edge devices. Complex enterprise applications take far longer: Qualys measured an average MTTR of 5 months and 10 days for hard-to-patch software such as Java, .NET, and Citrix.

What is MTTR in patch management?

MTTR stands for mean time to remediate: the average elapsed time between when a vulnerability is discovered on your systems and when it is fully fixed, usually by applying a patch or configuration change. It is the single most watched patch management metric because it measures how long an exploitable flaw stays open on your network. A lower MTTR means a shorter window for attackers to break in.

What percentage of known exploited vulnerabilities actually get patched?

According to Verizon’s 2025 Data Breach Investigations Report, organizations fully remediated only 38% of the vulnerabilities in the CISA Known Exploited Vulnerabilities catalog. Edge and internet-facing devices fared somewhat better at 54% remediated, but roughly one in three edge KEVs were left fully unremediated, the highest non-remediation rate of any category the report tracked.

How fast do attackers exploit a new vulnerability?

The Verizon 2025 DBIR measured a median of just 5 days from public disclosure to mass exploitation across all known exploited vulnerabilities, and zero days for internet-facing edge devices, meaning exploitation was already underway when the flaw became public. Since the typical high-risk fix takes 54.81 days, the average organization is exposed for weeks after attackers begin exploiting a flaw.

Why do patch backlogs happen?

Backlogs form because the volume of new vulnerabilities outpaces the capacity to fix them. A record 48,185 CVEs were published in 2025, about 131 per day, and Edgescan found that large enterprises left 45.4% of discovered vulnerabilities unresolved within a 12-month period. Compatibility testing, change-control windows, legacy systems, and limited staff all slow remediation, so open findings accumulate faster than teams can close them.

10 Methodology and Sources

How this report was compiled

Every figure in this article is drawn from a Tier 1 primary source: government agencies, major analyst and vendor research with disclosed methodology, and annual industry reports. No statistic is sourced from a blog citing another blog, and no figure is invented or estimated except the clearly labeled CNiC Solutions Analysis, which shows its formula and contributing sources. Where a figure describes 2024 rather than 2025, that year is stated alongside it.

Primary sources

 

back to blog