Nine in Ten Open Critical and High-Severity Vulnerabilities Remain Exposed for More Than 90 Days, Detectify Finds

Nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days across organizations analyzed in the H2 2026 Cyber Hygiene Index from Detectify, the Swedish application security platform built and trusted by hackers. The problem was consistent across every market: 97% of open critical and high-severity vulnerabilities in the Nordics, 92% in the UK and 86% in the US had remained exposed for more than three months.

Cyber hygiene, as this index defines it, measures whether organizations know what’s exposed on their attack surface and how quickly they act on it. On top of the challenge posed by unresolved exposure, Shadow AI is emerging as a new frontier in cyber hygiene, as organizations adopt AI tools and applications that may not be fully visible or controlled by security teams. Detectify is increasingly identifying publicly exposed instances of self-hosted AI platforms and AI-built applications across its customer base. Organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days. But organizationally, that is often what happens – the longer a known issue remains open without an incident, the easier it becomes to treat it as normal,” said Rickard Carlsson, CEO and co-founder of Detectify. “That is the risk in a stale backlog. Exposure can effectively become accepted without anyone ever making a conscious decision to accept it. The absence of an incident starts to feel like evidence that the risk is tolerable, even though nothing about the vulnerability itself has changed.”

Detectify’s data points to a mounting challenge for security teams. Exploit-verified known critical risks already remain unresolved for months, even as AI further accelerates the pace of software development and cyber threat activity. Meanwhile, the zero-day clock keeps ticking down, with the exploit window shrinking toward zero.

Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.

The findings point to three ways organizations can shorten the distance between discovery and remediation, from continuously discovering new internet-facing assets to giving critical findings enough context around exposure and ownership for engineers to act quickly and verifying that fixes have actually removed the risk. Increasingly, parts of that loop – including prioritization, re-testing and verification – can be automated, allowing security teams to keep pace as attack surfaces keep growing and agentic software development accelerates.

To learn more, access the full report here. For more information about Detectify, visit detectify.com.

About Detectify

Founded by ethical hackers in 2013, Stockholm-based Detectify is an application security platform trusted by over 2,100 organizations globally, from high-growth startups to the world’s largest enterprises and public institutions. Detectify equips modern security teams with clarity and control over their attack surface. Fueled by real-world validated payloads from its global community of elite ethical hackers and scaled through its own AI-driven engines, Detectify enables organizations and their agents to identify and fix truly exploitable vulnerabilities before attackers do.

Media gallery