FoxPointe Security Hub

Patch all Critical Vulnerabilities First. Right?

July 24, 2026 by James Farr

Whether your organization’s patching program is documented or performed ad hoc, you still need resources to fix those vulnerabilities.  The IT environment may include applications, cloud systems, endpoints, remote access, and servers, and IT teams are often left with long lists of findings and a familiar question: What should we fix first?

According to Verizon’s 2026 Data Breach Investigations Report[i], the exploitation of vulnerabilities is now the most common initial access vector for breaches, rising to 31% of the reporting dataset.  The same report found that only 26% of critical vulnerabilities in the CISA Known Exploited Vulnerabilities (CISA KEV) catalog[ii] were fully remediated by organizations in 2025.  The IBM X-Force report[iii] identified a 44% increase in attacks that began with exploitation of public-facing applications and found that vulnerability exploitation accounted for 40% of incidents it observed in 2025.

With limited organizational resources, the key question is: What risk are you reducing?

Traditional Patching Shortfalls

Some standards, such as the Payment Card Industry Data Security Standard (PCI DSS), require critical and high-risk vulnerabilities to be patched within 30 days of release.  However, this approach may not work for every organization.

Consider where the vulnerabilities are found.  Is the critical vulnerability on the internal test server as important as the high severity vulnerability found on a public-facing production server?  Attackers consider system availability, exposure, known exploitable vulnerabilities, and weaknesses that can be replicated across other systems.

Risk Based Vulnerability Management

A Common Vulnerability Scoring System (CVSS) score tells only part of the story.  Understanding how a vulnerable asset supports the business provides the context needed to prioritize remediation efforts.  This approach aligns with CISA BOD 26-04[iv]’s guidance, which emphasizes prioritizing security updates based on exposure, exploitability, and impact.

When determining vulnerability remediation priority, consider the following:

  • Is the system reachable (especially from the internet)?
  • Is it actively exploited as listed in the CISA KEV Catalog?
  • Can it be exploited at scale?
  • What happens if a system is compromised?

This approach shifts the focus from counting vulnerabilities to understanding which vulnerabilities present the greatest risk to the organization.

Next Steps

  • Build a reliable asset inventory.
    • Know what you have, what’s exposed, and what matters most to the business.
  • Combine severity with context.
    • Incorporate exposure, known exploitation (e.g., CISA KEV catalog), and business criticality.
  • Prioritize attacker entry points.
    • Focus on internet-facing systems, known exploited vulnerabilities, and critical services.
  • Validate remediation.
    • Confirm fixes through rescanning or testing, not just closing a ticket.
  • Add real-world testing.
    • Vulnerability scans identify potential weaknesses, while penetration testing demonstrates which weaknesses could be used to compromise critical systems. Combined with risk assessments, these activities help organizations focus remediation efforts where they will have the greatest business impact.

Questions Executives Should Ask

  • Which vulnerabilities affect internet-facing systems?
  • Which vulnerabilities are/can be actively exploited?
  • What critical services are at risk?
  • Are issues fixed within defined timelines?
  • Are fixes validated, or just marked complete?
  • What risks have you accepted—and why?

Summary

Organizations should strive to remediate all identified vulnerabilities, but not all vulnerabilities require the same level of urgency.  Effective vulnerability management considers severity, exposure, exploitability, and business impact to ensure that remediation efforts are focused where they reduce risk the most.

[i] https://www.verizon.com/business/resources/T158/reports/2026-dbir-data-breach-investigations-report.pdf

[ii] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

[iii] https://newsroom.ibm.com/2026-02-25-ibm-2026-x-force-threat-index-ai-driven-attacks-are-escalating-as-basic-security-gaps-leave-enterprises-exposed

[iv] https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk

Written By

cropped favicon.png
James Farr
Consulting Manager

Topics