> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# You Can’t Patch Your Way Out of the Vulnerability Backlog
- URL: https://www.cybrsecmedia.com/you-cant-patch-your-way-out-of-the-vulnerability-backlog/
- Published: 2026-09-01T21:04:43.000Z
- Updated: 2026-09-01T21:05:44.000Z
- Description: Applications average 22 critical vulnerabilities while teams fix just 3.4 per month, exposing a widening AppSec gap that AI is making harder to close.
- Author: George V. Hulme
- Tags: AI and Vulnerability Management, Vulnerability Management, Article

The vulnerability remediation math just doesn’t add up. The average application carries 22 critical vulnerabilities, while security and development teams close 3.4 per month, a recent research analysis has found. When a critical flaw is located within an organization's environment, remediation takes, on average, 92 days. With that long of a runway from vulnerability publication through remediation, it’s no wonder that more than half of the Common Vulnerabilities and Exposures (CVEs) instances running in production environments were published over a year ago. 

While these challenges are not new, AI is exacerbating the situation.

These figures come from Contrast Security's AppSec Overflow 2026 [report](https://www.contrastsecurity.com/appsec-overflow-2026-report?ref=cybrsecmedia.com), drawn from runtime telemetry across hundreds of thousands of production applications and APIs. The findings show that teams can’t outpace their vulnerabilities, as new vulnerabilities will certainly outpace running patching efforts.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

The conventional plan: patch faster, scan more often, and closing more tickets won’t get an organization caught up. "Nobody patches their way to secure. A report full of closed tickets tells you how busy the team was, not how exposed you are," said David Lindner, chief information security officer (CISO) at Contrast Security.

At a pace of 3.4 vulnerabilities closed per application per month against a static inventory of 22 serious vulnerabilities, a team takes more than six months to clear their backlog. That’s assuming no new critical vulnerabilities enter the scene in the meantime. 

However, they always do. Patching a production system requires change management, dependency analysis, regression testing, and coordination across development, operations, and security teams. And while maintenance windows are limited, risk never sleeps.

"The result is that too few vulnerabilities are being addressed, over too long a time," Lindner said. "What is protecting that application on day 3 of a 92-day fix?"

Contrast's telemetry also shows 54% of CVE instances observed in production environments were published more than a year ago. The presence of Log4Shell in monitored environments in 2026, more than four years after disclosure, reflects the supply chain complexity of modern Java applications, where dependencies bundle vulnerabilities without the application team's knowledge. 

**Related:**

[High-Risk Vulnerabilities with LLMs at Nearly Triple the Rate of Traditional Software, New Cobalt Report FindsExecutives think their teams are fixing critical vulnerabilities. Their security practitioners disagree by 42 percentage points.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-10dc1f09-3381-4c15-ac95-d5ead6b3c747.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/d2338410-5d3c-4145-a0fb-643a4cb886d3-e549531b-1ac5-4ac6-aadd-a9a901e263b2.png)](https://www.cybrsecmedia.com/high-risk-vulnerabilities-with-llms-at-nearly-triple-the-rate-of-traditional-software-new-cobalt-report-finds/)

[AI Vulnerability Patches Fail More Than Half the TimeNew 1Password research found AI-generated vulnerability patches failed to fully fix complex software flaws 53.9% of the time, reinforcing the need for expert human review.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-c6fadc3f-b4ff-4859-9c56-5c878c82512e.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/adeb5f66-f4c3-4010-a991-650c5ea34d74-bd3d56b1-f901-4081-addc-e0041e31778e.png)](https://www.cybrsecmedia.com/ai-generated-vulnerability-patches-fail-more-than-half-the-time-1password-research-finds/)

## The window of vulnerability widens

The vulnerability disclosure-to-active-exploit clock is tightening. The [Zero Day Clock](https://zerodayclock.com/?ref=cybrsecmedia.com), which aggregates exploit signals across more than 83,000 CVEs, shows that in 2018 the average time from CVE disclosure to first observed exploit was more than two years. By 2025, most exploited vulnerabilities were weaponized within three weeks. In 2026, that window has compressed to hours. Research from VulnCheck's *State of Exploitation 2026* [report](https://www.vulncheck.com/blog/state-of-exploitation-2026?ref=cybrsecmedia.com) found that 29% of exploited CVEs in 2025 were weaponized on or before the day they were published.

When vulnerabilities are being announced or discussed in the media, they’re already old news to the adversary. "A third of the time you're reading about something people are already exploiting," Lindner said. "If nothing moves in your program until an ID shows up, you're late."

## Current prioritization efforts remain broken

The Common Vulnerability Scoring System (CVSS) was designed with environmental and temporal scoring components that allow organizations to calibrate severity against their own infrastructure, accounting for compensating controls, asset criticality, and network context. 

In practice, almost nobody uses them. Most organizations rely on the generic base score, which is scored against worst-case assumptions that rarely reflect what production environments look like. The result is inflated severity ratings across the board, making it genuinely difficult to separate vulnerabilities that are dangerous in your specific environment from ones that are merely theoretical in it. 

The Exploit Prediction Scoring System (EPSS) takes a different score. The EPSS estimates the probability that a given vulnerability will be actively exploited within the next 30 days. More useful in principle, but it carries its own blind spots. Contrast's data includes CVE-2023-38180 (a .NET and Visual Studio denial-of-service), a vulnerability confirmed on CISA's Known Exploited Vulnerabilities list, which means active exploitation in the wild has been verified. Its EPSS score was 0.88% at the time of Contrast's analysis. Any program running a 90% EPSS threshold as a triage filter never looks at it.

Linder advised enterprises to use both scores to sort their pile of vulnerabilities and identify which are running in their environments and taking traffic.

The implication for program design is not that patching should stop; rather, patching alone won’t get the job done. The goal is to ensure that the vulnerabilities attackers are most likely to reach and exploit are addressed first, and that production applications are defended even while remediation is still in progress. 

A strategy built primarily on patch velocity will keep teams busy. It will not keep applications protected. The question every security leader should be asking is not how many vulnerabilities were closed last quarter. It is what is protecting that application on day one of a 92-day vulnerability remediation lifecycle.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)