Detectify: Critical Vulnerabilities Remain Exposed for Over 90 Days
Nine in ten critical and high-severity vulnerabilities remain exposed for over 90 days, according to Detectify's new report. Remediation of vulnerabilities in AI tooling is slower than the average.

Nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days across organizations analyzed in Detectify's H2 2026 Cyber Hygiene Index. The report, based on data from 1,300 organizations in the US, UK, and Nordics, indicates that greater visibility into cyber exposure is not consistently translating into faster remediation.
Organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base. This finding highlights a growing challenge in securing emerging technologies against cyber threats.
"This index reveals that even as organizations gain more visibility into their cyber exposure, the speed at which they remediate high-risk vulnerabilities remains too slow," said Jens Lindström, CTO at Detectify. "Securing AI technologies, in particular, requires more focus and resources to ensure we are not building the future on an insecure foundation."
The study analyzed security data from 1,300 organizations. The findings suggest a broader need for companies to improve their cybersecurity processes and prioritize faster remediation, especially when implementing new technologies.