Nine in ten open critical and high-severity vulnerabilities remain exposed for more than 90 days, Detectify finds
Detectify’s H2 2026 Cyber Hygiene Index, based on a sample of 1,300 organizations across the US, UK and , shows that greater visibility into cyber exposure is not consistently translating into faster remediation, and organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base.

STOCKHOLM, SEPTEMBER 29, 2026 — Nine in ten open critical and high-severity vulnerabilities have remained exposed for more than 90 days across organizations analyzed in the H2 2026 Cyber Hygiene Index from Detectify, the Swedish application security platform built and trusted by hackers. The problem was consistent across every market: 97% of open critical and high-severity vulnerabilities in the Nordics, 92% in the UK and 86% in the US had remained exposed for more than three months.
Cyber hygiene, as this index defines it, measures whether organizations know what's exposed on their attack surface and how quickly they act on it. On top of the challenge posed by unresolved exposure, Shadow AI is emerging as a new frontier in cyber hygiene, as organizations adopt AI tools and applications that may not be fully visible or controlled by security teams. Detectify is increasingly identifying publicly exposed instances of self-hosted AI platforms and AI-built applications, such as Open WebUI, Lovable, LibreChat, or Base44, across its customer base.
Organizations with exposed AI tooling tend to resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base. Shadow AI is emerging as an additional challenge alongside the broader issue of unresolved exposure. As AI use expands and attack surfaces evolve, maintaining cyber hygiene will increasingly mean knowing what AI assets are exposed and maintaining control over them.
“A critical vulnerability does not become less dangerous because it has been sitting there for 90 days. But organizationally, that is often what happens - the longer a known issue remains open without an incident, the easier it becomes to treat it as normal,” said Rickard Carlsson, CEO and co-founder of Detectify. “That is the risk in a stale backlog. Exposure can effectively become accepted without anyone ever making a conscious decision to accept it. The absence of an incident starts to feel like evidence that the risk is tolerable, even though nothing about the vulnerability itself has changed.”
Detectify’s data points to a mounting challenge for security teams. Exploit-verified known critical risks already remain unresolved for months, even as AI further accelerates the pace of software development and cyber threat activity. Meanwhile, the zero-day clock keeps ticking down, with the exploit window shrinking toward zero.
Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.
The UK offers the clearest example of the gap: organizations monitor 72% of verified domains, more than double the rate in the Nordics (32%) and US (29%), yet record the lowest critical and high-severity vulnerability resolution rate of the three markets. Among organizations using Detectify for at least 12 months, verified domains grew about 20% year over year in the US, 14% in the UK, and 3.4% in the Nordics over the past year.
The sector data points to a similar pattern. Consumer packaged goods and brands carried large vulnerability backlogs, yet they resolved critical and high-severity vulnerabilities at the highest rate of any sector, at 46%. Public-sector organizations sat at the opposite end, resolving 8%, less than one-fifth the rate of consumer brands.
“When a team is staring at thousands of open findings, the challenge is not always identifying which ones are critical. It’s whether the finding arrives with enough context for an engineer to act. Can the asset be reached? Is the vulnerability realistically exploitable? And who’s responsible for fixing it?” said Danwei Tran Luciani, Chief Product Officer at Detectify. “The fastest-moving teams reduce that translation step. The more context that travels with the finding, the less time teams spend re-investigating the problem before they can fix it.”
The findings point to three ways organizations can shorten the distance between discovery and remediation, from continuously discovering new internet-facing assets to giving critical findings enough context around exposure and ownership for engineers to act quickly and verifying that fixes have actually removed the risk. Increasingly, parts of that loop – including prioritization, re-testing and verification – can be automated, allowing security teams to keep pace as attack surfaces keep growing and agentic software development accelerates.
To learn more, access the full report here. For more information about Detectify, visit detectify.com.