-

Nine in Ten Open Critical and High-Severity Vulnerabilities Remain Exposed for More Than 90 Days, Detectify Finds

Detectify’s H2 2026 Cyber Hygiene Index, based on a sample of 1,300 organizations across the US, UK and Nordics, shows that greater visibility into cyber exposure is not consistently translating into faster remediation, and organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

STOCKHOLM--(BUSINESS WIRE)--Nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days across organizations analyzed in the H2 2026 Cyber Hygiene Index from Detectify, the Swedish application security platform built and trusted by hackers. The problem was consistent across every market: 97% of open critical and high-severity vulnerabilities in the Nordics, 92% in the UK and 86% in the US had remained exposed for more than three months.

“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days. But that is often what happens - the longer a known issue remains open without an incident, the easier it becomes to treat it as normal."

Share

Cyber hygiene, as this index defines it, measures whether organizations know what's exposed on their attack surface and how quickly they act on it. On top of the challenge posed by unresolved exposure, Shadow AI is emerging as a new frontier in cyber hygiene, as organizations adopt AI tools and applications that may not be fully visible or controlled by security teams. Detectify is increasingly identifying publicly exposed instances of self-hosted AI platforms and AI-built applications across its customer base. Organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days. But organizationally, that is often what happens - the longer a known issue remains open without an incident, the easier it becomes to treat it as normal,” said Rickard Carlsson, CEO and co-founder of Detectify. “That is the risk in a stale backlog. Exposure can effectively become accepted without anyone ever making a conscious decision to accept it. The absence of an incident starts to feel like evidence that the risk is tolerable, even though nothing about the vulnerability itself has changed.”

Detectify’s data points to a mounting challenge for security teams. Exploit-verified known critical risks already remain unresolved for months, even as AI further accelerates the pace of software development and cyber threat activity. Meanwhile, the zero-day clock keeps ticking down, with the exploit window shrinking toward zero.

Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.

The findings point to three ways organizations can shorten the distance between discovery and remediation, from continuously discovering new internet-facing assets to giving critical findings enough context around exposure and ownership for engineers to act quickly and verifying that fixes have actually removed the risk. Increasingly, parts of that loop – including prioritization, re-testing and verification – can be automated, allowing security teams to keep pace as attack surfaces keep growing and agentic software development accelerates.

To learn more, access the full report here. For more information about Detectify, visit detectify.com.

About Detectify

Founded by ethical hackers in 2013, Stockholm-based Detectify is an application security platform trusted by over 2,100 organizations globally, from high-growth startups to the world’s largest enterprises and public institutions. Detectify equips modern security teams with clarity and control over their attack surface. Fueled by real-world validated payloads from its global community of elite ethical hackers and scaled through its own AI-driven engines, Detectify enables organizations and their agents to identify and fix truly exploitable vulnerabilities before attackers do.

Contacts

Media contacts
​​Jorge Vicente, ​​PR & Communications at Detectify | ​press@detectify.com | ​+46 76-114 63 50
Rachel McIntosh, San Francisco PR for Detectify | rachel@sanfrancisco.fi | +358 41 313 0441

Detectify


Release Versions

Contacts

Media contacts
​​Jorge Vicente, ​​PR & Communications at Detectify | ​press@detectify.com | ​+46 76-114 63 50
Rachel McIntosh, San Francisco PR for Detectify | rachel@sanfrancisco.fi | +358 41 313 0441

Social Media Profiles
More News From Detectify

Detectify Positioned as a Major Player in the 2026 IDC MarketScape for Dynamic Application Security Testing (DAST)

STOCKHOLM--(BUSINESS WIRE)--Detectify, the application security platform built and trusted by ethical hackers, today announced that it has been positioned in the Major Player Category in the IDC MarketScape: Worldwide Dynamic Application Security Testing (DAST) 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluates suppliers across a comprehensive framework of quantitative and qualitative criteria, measuring short-term technical execution and long-term product s...

Detectify Launches MCP Server to Secure the Autonomous Coding Loop

STOCKHOLM--(BUSINESS WIRE)--Detectify, the Swedish application security platform built and trusted by hackers, today announced the launch of the Detectify MCP (Model Context Protocol) Server, a new integration layer that brings Detectify’s security testing engines directly into AI-driven development workflows, helping coding agents find and validate exploitable vulnerabilities and interpret attack surface data with unprecedented precision. As organizations increasingly rely on AI agents to writ...

Detectify Launches IP Range Scanning to Uncover Hidden Infrastructure Before Attackers Do

STOCKHOLM--(BUSINESS WIRE)--Detectify, the Swedish application security testing platform built and trusted by hackers, has launched IP Range Scanning to continuously discover and monitor entire blocks of IP addresses, helping security teams find forgotten assets and hidden risks before attackers exploit them. Many organizations are sitting on forgotten IP addresses that have become entry points for cyberattacks. While millions have been spent securing public-facing websites, legacy tools can mi...
Back to Newsroom