Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

Patch Management Statistics 2026: Remediation Speed, Mandated Deadlines, and the Patch Deficit Gap

Patch management statistics 2026 chart comparing the 43-day median vulnerability remediation time against the 14-day federal remediation deadline Patch Deficit Gap by asset class showing a three-day mandated patch window for network edge devices against a 43-day mean time to patch.

Patch Management Statistics 2026

By Axis Intelligence Research

Co-author: Marcus Chen | Last updated: August 13, 2026 | License: CC BY 4.0

Two clocks govern vulnerability remediation, and they are moving in opposite directions. The deadline set by the U.S. federal government has fallen from 21 days to 14. The time organizations actually take has risen from 32 days to 43. Axis Intelligence Research measures the distance between them at 22 days for 2025 — double the 2024 figure.


Quick Answer

The median organization now takes 43 days to fully remediate a known exploited vulnerability, up from 32 days a year earlier, while only 26% of those vulnerabilities are fully remediated at all. Against that, Axis Intelligence Research finds the median federal remediation deadline attached to a new CISA KEV entry has fallen to 14 days in 2026, down from a flat 21 days that governed every year from 2022 through 2025. The Patch Deficit Gap (PDG™) — the distance between the mandated window and observed remediation speed — reached 22 days in 2025, twice the 11-day gap in 2024.

Key Findings

  1. Axis Intelligence Research finds the median federal remediation window attached to a new CISA KEV entry fell to 14 days across 181 additions in 2026, against a flat 21-day median in each of the four preceding years.
  2. Axis Intelligence Research measures the Patch Deficit Gap (PDG™) at 22 days for 2025 — the Verizon-reported 43-day median remediation time minus the 21-day median mandated window — up from 11 days in 2024.
  3. Axis Intelligence Research finds that network-edge products carry a median 3-day federal remediation deadline in 2026, against 14 days for operating systems and endpoints, producing an asset-class Patch Deficit Gap of 40 days for firewalls and VPN appliances.
  4. Axis Intelligence Research calculates that the median organization now carries approximately 11.8 unremediated known exploited vulnerabilities at any point, up from 6.8 a year earlier — a backlog increase of five per organization.
  5. Axis Intelligence Research finds that 83 KEV entries — 4.98% of the catalog — prescribe disconnection rather than patching, because the affected product has reached end of life and no fix will ever ship.

How Long Does It Actually Take to Patch a Known Exploited Vulnerability?

Forty-three days. That is the median time to full resolution across a study of more than 13,000 organizations in the Verizon 2026 Data Breach Investigations Report, covering incidents from November 2024 through October 2025. The prior year’s figure was 32 days.

The direction is the finding. Every headline patch management metric moved the wrong way at once.

Field Remediation Performance, Year Over Year

Metric2024 dataset2025 datasetChangeSource
Median days to full KEV remediation3243+34.4%Verizon 2026 DBIR
KEV vulnerabilities fully remediated38%26%−12 pointsVerizon 2026 DBIR
KEV vulnerabilities left unremediated12%16%+4 pointsVerizon 2026 DBIR
Median KEV vulnerabilities per organization1116+45.5%Verizon 2026 DBIR
KEV instances still open at day 2827%35%+8 pointsVerizon 2026 DBIR
Vulnerabilities remediated before KEV listing17%12%−5 pointsVerizon 2026 DBIR

More to patch, longer to patch it, fewer fully cleared. The mean time to patch did not drift — it moved 34.4% in twelve months, which is the kind of change that usually signals a capacity ceiling rather than a discipline failure.

The volume data supports that reading. Verizon’s survival analysis draws on 527,255,454 vulnerability detection records for 2025, against 68,697,749 in the 2022 dataset — roughly an eightfold increase in the same pipeline. At day 28, the 35% still open translates to 184 million open vulnerability instances, up from 31 million in 2022. The long tail settles at 9%, which Verizon puts at 47 million instances with no realistic path to closure under current operating models.

Marcus Chen: The comfortable story here is that defenders got lazy. The data says the opposite. Preemptive remediation — patching a vulnerability before CISA ever lists it — covered 63.7 million instances in 2025, a 30% increase in absolute terms over 2024’s 48.9 million. Teams did more work and finished a smaller fraction of it, because the denominator grew faster than any headcount plan. That distinction matters when you are deciding whether to buy training or buy capacity.

There is also a hard ceiling in the data that no amount of tooling has moved. Between 60% and 70% of KEV vulnerabilities remain open at day 7 regardless of year, volume, or organizational maturity. The best-performing organizations close 30% to 40% of instances in that first week. Three years of process investment and mandate pressure barely shifted that first-week number.

What Is the Patch Deficit Gap (PDG™)?

PDG™ — the Patch Deficit Gap — is an Axis Intelligence Research metric measuring the distance, in calendar days, between the remediation deadline a vulnerability carries and the time organizations actually take to close it. It is a benchmark, not a compliance rate: it asks how far the standard has drifted from the practice.

PDG™ formula and inputs

PDG = Observed median days to full KEV remediation − Median mandated federal remediation window

Both inputs are single, primary, directly observed figures:

InputValueSource
Observed median days to full remediation, 202543Verizon 2026 DBIR (n=10,597 company-CVE observations)
Observed median days to full remediation, 202432Verizon 2026 DBIR
Median mandated window, KEV entries added 202521Axis calculation on CISA KEV Catalog v2026.08.11
Median mandated window, KEV entries added 202421Axis calculation on CISA KEV Catalog v2026.08.11
Median mandated window, KEV entries added 202614Axis calculation on CISA KEV Catalog v2026.08.11

The mandated window is computed as dueDate − dateAdded in calendar days for every entry in the CISA Known Exploited Vulnerabilities Catalog, retrieved at catalog version 2026.08.11 via CISA’s own kev-data repository.

PDG™ readings — baseline

YearObserved median (days)Mandated median (days)PDG™ (days)PDG™ ratio
20243221111.52
20254321222.05
2026 (mandated measured; observed held at 2025 pace)4314293.07

This is the baseline reading of PDG™; no prior readings exist, and the metric makes no claim about a history it has not computed. The 2026 row is explicitly an estimate — the mandated median is measured from the catalog, the observed median is held constant at the 2025 figure because 2026 field remediation has not yet been published.

Scope. PDG compares two populations that are not identical. The mandated window binds Federal Civilian Executive Branch agencies; the observed median comes from cross-industry scanner telemetry across more than 13,000 organizations, most of which have no federal obligation at all. Axis Intelligence Research publishes the two side by side rather than merging them into a single compliance figure, because averaging a policy deadline with a telemetry measurement would produce a number that means nothing. PDG is the distance between the standard and the practice — which is precisely the quantity a security leader is asked about in a board meeting, and precisely the quantity nobody had put a number on.

Marcus Chen: Twenty-two days is the honest version of “we’re behind.” It is not a compliance failure, because most of the organizations in the denominator are not bound by the deadline. It is a benchmark drift number, and it doubled in a year — not because remediation slowed by eleven days, but because the deadline held still while remediation slowed. In 2026 the deadline moves too, and it moves the other way. That is the first year in which both terms of the subtraction work against the defender at the same time.

How Fast Does CISA Now Require Federal Agencies to Patch?

The flat clock is gone. On June 10, 2026, CISA issued BOD 26-04: Prioritizing Security Updates Based on Risk, which supersedes and revokes both BOD 19-02 and BOD 22-01. Where BOD 22-01 applied one deadline to every KEV entry, BOD 26-04 derives the deadline from four binary variables — asset exposure, KEV status, exploit automation, and post-exploitation technical impact — mapped across Table 1: Remediation Timelines.

That change is legible in the catalog, and Axis Intelligence Research measured it.

Mandated Remediation Window on New KEV Entries

Year addedMedian window≤3 days14 days21 daysOtherTotalSource
202221 days08840364555Axis calculation on CISA KEV Catalog
202321 days0017710187Axis calculation on CISA KEV Catalog
202421 days1017510186Axis calculation on CISA KEV Catalog
202521 days7022612245Axis calculation on CISA KEV Catalog
2026 (to Aug 11)14 days7561441181Axis calculation on CISA KEV Catalog

In 2026, 41.4% of new KEV entries carry a deadline of three days or less. Another 33.7% carry fourteen days. The 21-day window that governed 226 of 245 additions in 2025 now covers 24.3%.

The short deadline is not brand new — it is newly systematic. A three-day window appears once in 2024 and seven times in 2025, alongside a handful of other off-schedule dates, as an emergency exception to an otherwise uniform 21-day clock. In 2026 it becomes a tier: 75 entries, issued continuously, with the 14-day band appearing alongside it for the first time since the 2022 backfill period. That is the shape of a graduated policy replacing a flat one, and it is visible in the catalog before it is visible in any compliance report.

At the bottom of the scale, BOD 26-04 also introduced relief that gets less attention than the three-day tier: the lowest-risk combinations wait for the next scheduled system upgrade, and where CISA’s Vulnrichment data is not yet available the timeline defaults to 60 days. The implementation guidance is explicit that these are maximum durations, not targets, and that agencies with lower risk tolerance may set shorter ones. Agencies have 180 days from issuance to comply.

The reach extends past federal civilian agencies. FedRAMP’s public notice on BOD 26-04 sets December 7, 2026 as the mandatory adoption deadline for its aligned Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules, which pulls authorized cloud service providers onto the same clock and, through them, their federal customers’ supply chains.

Our CISA KEV statistics analysis covers catalog growth, vendor concentration, and ransomware linkage in the same dataset.

Which Assets Get the Shortest Patch Window?

This is where the 2026 data says something nobody has published. The three-day tier is not distributed evenly across the technology stack — it is concentrated almost entirely on the network edge.

Axis Intelligence Research classified every 2026 KEV addition into three asset classes and computed the mandated window for each.

Median Mandated Window by Asset Class, 2026 Additions

Asset classEntriesMedian windowShare at ≤3-day tierPDG™ (days)Source
Network edge (firewall, VPN, remote access, router)353 days82.9%40Axis calculation on CISA KEV Catalog
Enterprise application and other9714 days40.2%29Axis calculation on CISA KEV Catalog
Operating system and endpoint4914 days14.3%29Axis calculation on CISA KEV Catalog

Four in five network-edge entries land on the fastest tier. Only one in seven operating-system entries does. And 38.7% of every three-day deadline issued in 2026 belongs to a network-edge product, despite that class supplying just 19.3% of the year’s additions.

The asset-class Patch Deficit Gap follows directly. A firewall vulnerability carries a three-day deadline against a 43-day observed median — a 40-day gap, and a ratio of more than fourteen to one. The same arithmetic on a Windows flaw gives 29 days.

Marcus Chen: Read the three-day tier as an exposure statement, not a patching schedule. Nobody regression-tests firewall firmware across an enterprise in seventy-two hours, and CISA knows it — which is why the same tier requires forensic triage and why taking the box off the internet is an accepted way to stop the clock. The variable driving the tier is public exposure, and it is the one variable the agency owns rather than receives. What separates the organizations that will hit three days from the ones that will not is whether they can enumerate internet-facing assets from an inventory instead of a scan. Patching capacity is the second constraint. Asset knowledge is the first.

How Many Unpatched Known Exploited Vulnerabilities Does a Typical Organization Carry?

Roughly twelve. The DBIR reports two figures that are usually quoted separately: the median organization faces 16 KEV vulnerabilities, and 26% are fully remediated.

Axis calculation: 16 median KEV vulnerabilities × (1 − 0.26 full remediation rate) = 11.8 unremediated known exploited vulnerabilities per organization, as of the 2025 reporting dataset. The same arithmetic on 2024 inputs (11 × [1 − 0.38]) gives 6.8. The backlog grew by five per organization in one year. Both inputs are direct observations from the Verizon 2026 DBIR; neither is an estimate.

Every one of those carries confirmed exploitation in the wild. Not a theoretical CVSS score — an observation that someone, somewhere, has already used it successfully.

For scale on the denominator: the KEV catalog held 1,665 entries at version 2026.08.11 against 376,310 CVE records in the NIST National Vulnerability Database as of August 12, 2026, or 0.44% of every CVE ever published. Exploitation-based prioritization is not a refinement of severity-based patching; it is a different queue with a two-hundred-fold smaller front. Our CVE statistics page covers publication volume and the scoring backlog behind that denominator.

What Share of Actively Exploited Vulnerabilities Can Be Patched at All?

Not all of them, and the exception is worth naming precisely. Axis Intelligence Research finds 83 KEV entries — 4.98% of the catalog — where CISA’s required action is disconnection rather than remediation, because the product has reached end of life or end of service and no fix will ever ship.

End-of-Life Entries in the KEV Catalog

AttributeValueSource
Entries prescribing disconnection83Axis calculation on CISA KEV Catalog
Share of full catalog4.98%Axis calculation on CISA KEV Catalog
Distinct vendors affected19Axis calculation on CISA KEV Catalog
Adobe entries in subset36Axis calculation on CISA KEV Catalog
D-Link entries in subset14Axis calculation on CISA KEV Catalog
Ransomware-linked share of subset18.1%Axis calculation on CISA KEV Catalog

For these, patch management is the wrong discipline entirely — the answer is asset retirement, and the deadline is a decommissioning date wearing a remediation label.

The field data shows the same problem at scale outside the catalog. Verizon’s internet scanning validated between 45,000 and 50,000 end-of-life wireless modem devices exposing an accessible ACEmanager interface between June and October 2025, concentrated in mining, oil and gas, and utilities. Those devices were installed to connect remote sensors and are being repurposed as operational relay boxes for attacker infrastructure. No patch exists. Segmentation is the mitigation, and replacement is the fix.

One thing the catalog does not say

A caution on a finding that looks tempting and is wrong. In 2021, 99.4% of KEV entries carried the required action “Apply updates per vendor instructions.” In 2025 and 2026, that phrasing appears on zero entries; 96.7% now read “Apply mitigations per vendor instructions, follow applicable guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

Year added“Apply updates” share“Apply mitigations” shareSource
202199.4%0.0%Axis calculation on CISA KEV Catalog
202290.1%0.0%Axis calculation on CISA KEV Catalog
202354.5%39.6%Axis calculation on CISA KEV Catalog
20241.6%87.6%Axis calculation on CISA KEV Catalog
20250.0%96.7%Axis calculation on CISA KEV Catalog
20260.0%96.7%Axis calculation on CISA KEV Catalog

That transition is a change in CISA’s boilerplate, not a collapse in patch availability. Read literally, it would suggest that no actively exploited vulnerability has shipped a vendor patch since 2024, which is false. Axis Intelligence Research publishes the distribution because it is a real, checkable property of the dataset and because anyone parsing the requiredAction field for patch-availability signal will find it and misread it. The end-of-life subset above is the substantive signal; the wording shift is not.

What Kinds of Flaws Are Organizations Actually Patching?

Memory safety, still, thirty years on. Verizon’s detection data across 12,208 organizations ranks weakness categories by how many organizations had at least one detected KEV instance of each.

CWE categoryOrganizations affectedSource
CWE-1399 — Memory Safety89%Verizon 2026 DBIR
CWE-1396 — Access Control85%Verizon 2026 DBIR
CWE-1416 — Resource Lifecycle Management80%Verizon 2026 DBIR
CWE-1407 — Improper Neutralization77%Verizon 2026 DBIR
CWE-1404 — File Handling77%Verizon 2026 DBIR

At the individual weakness level, out-of-bounds read (CWE-125) was detected in 79% of organizations, with heap-based buffer overflow, use-after-free, and external control of file name or path each at 77%.

The other side of that equation sets a floor on how fast the supply of patches can improve. In codebases with mature development lifecycles, the top three weakness categories take a median of six to seven months to resolve 50% of associated flaws. Improper input validation takes just over thirteen months. That is the interval between a developer finding a class of bug and half of its instances being fixed — upstream of any patch reaching a customer, and upstream of any deployment deadline.

Marcus Chen: Six months upstream, forty-three days downstream, three days on the clock. Those three numbers describe one pipeline, and only the last one is set by policy. A three-day federal deadline is a statement about exposure tolerance, not an expectation that anyone’s release engineering got faster. Anyone building a patch management program around the deadline alone is optimizing the shortest segment of the longest process.

Is Unpatched Software Really the Top Way Attackers Get In?

As of the 2026 DBIR, yes — for the first time in the report’s nineteen-year history. Exploitation of vulnerabilities reached 31% of known initial access vectors, up from 20%, a 55% increase in one year. Credential abuse, the previous leader, fell to 13%.

Two qualifications belong with that number, and both come from Verizon itself. First, part of the credential decline is a methodology change: pretexting was added to the tracked list of initial access vectors, and without that addition credential abuse would have been 16% rather than 13%. Second, counting credential abuse at any point in the breach chain rather than only at initial access puts it at 39% — still the most pervasive single technique in the dataset. Exploitation leads the entry point; credentials lead the whole chain.

Taken as an action variety across all breaches rather than as an entry point, exploitation of vulnerabilities appears in 32%, double the 18% recorded a year earlier. Our AI cyberattack statistics and zero-day statistics pages cover the exploitation side of that pipeline; this page covers the remediation side.

Methodology

Collection. Two primary datasets, both retrieved on August 13, 2026.

The complete CISA Known Exploited Vulnerabilities Catalog was retrieved at catalog version 2026.08.11 (dateReleased 2026-08-11T18:59:43Z, count 1665) via CISA’s cisagov/kev-data repository, which mirrors the agency’s published JSON and CSV files with commit history. Every entry’s cveID, vendorProject, dateAdded, dueDate, requiredAction, and knownRansomwareCampaignUse fields were parsed programmatically. No entry was hand-transcribed.

Field remediation figures come from the Verizon 2026 Data Breach Investigations Report, published May 2026, covering incidents from November 1, 2024 through October 31, 2025. The remediation study aggregates more than 13,000 organizations; the median-days figure rests on 10,597 company-CVE observations and the resolution-status distribution on 515,170 records. The survival analysis draws on more than one billion vulnerability detection records across four reporting periods.

Derived fields. Mandated remediation window is computed as (dueDate − dateAdded) in calendar days. Medians are taken across all entries added within each calendar year. Deadline tiers are exact day counts; the “≤3 days” tier comprises 73 entries at three days and two at two days.

PDG™ formula. PDG = observed median days to full KEV remediation (Verizon 2026 DBIR) − median mandated federal remediation window (Axis calculation on CISA KEV Catalog), computed per year against the same calendar year’s inputs. The PDG ratio is the same two inputs divided rather than subtracted. The 2026 reading holds the 2025 observed median constant against the measured 2026 mandated median and is labelled an estimate throughout. A reader with the same catalog version and the same DBIR page can reproduce every reading.

Asset-class classification. Network edge comprises entries whose vendorProject is one of: Ivanti, Fortinet, Citrix, SonicWall, Palo Alto Networks, Cisco, Zyxel, D-Link, Netgear, F5, Check Point, Juniper Networks, Sophos, Barracuda Networks, Array Networks, Pulse Secure, WatchGuard, TP-Link, DrayTek, Progress. Operating system and endpoint comprises Microsoft, Apple, Google, Linux, Red Hat, Android. All remaining vendors fall into enterprise application and other. Classification is by vendor string, so a vendor shipping both appliance and non-appliance products is counted whole — this inflates the network-edge class modestly, most notably for Cisco and Microsoft.

End-of-life classification. Entries whose requiredAction text cites end-of-life, end-of-service, or disconnection of the affected product. The classification is textual and was reviewed entry by entry against the underlying strings.

Scope. The KEV catalog records confirmed exploitation with a clear remediation action and an assigned CVE; it is not a complete record of exploitation in the wild, and additions reflect CISA analyst capacity as well as attacker behavior. Mandated windows bind Federal Civilian Executive Branch agencies only. The Verizon remediation dataset reflects organizations running commercial vulnerability scanners, which skews toward larger enterprises with existing vulnerability management programs; organizations with no scanning at all are absent from the denominator, which almost certainly makes the observed medians optimistic. Vendor counts in the catalog reflect federal-relevant installed base and CISA visibility, not relative code quality. CISA occasionally removes entries; this snapshot reflects the catalog as published on August 11, 2026.

Verification. Every figure in this article was computed in Python directly from the retrieved catalog and re-run in an independent second pass. The 2026 tier distribution sums to 181, matching the catalog’s own count of 2026 additions. The median mandated window of 21 days for 2022–2025 reconciles with the flat BOD 22-01 deadline described in CISA’s own directive text. Every number in the prose corresponds to a row in the accompanying CSV.

About This Dataset

patch-management-statistics-2026.csv contains 125 observations covering patch and vulnerability remediation from 2021 through August 11, 2026: mandated federal remediation windows by year and by asset class, deadline tier distributions, end-of-life and required-action classifications, field remediation medians and completion rates, survival-analysis milestones, weakness-category detection rates, code-flaw fix times, and all PDG™ readings with their inputs.

Each row carries metric, value, unit, dimension, geography, as_of_date, source_org, source_document, source_url, retrieved_date, is_primary, axis_calculated, method_note, and license. Values are raw — no currency symbols, no percent signs, no thousands separators. Dates are ISO 8601. Rows marked axis_calculated = yes carry a method_note pointing to the formula disclosed above.

License: CC BY 4.0. Free to use, redistribute, and build on with attribution.

Cite This Research

APA Axis Intelligence Research. (2026). Patch management statistics 2026: Remediation speed, mandated deadlines, and the Patch Deficit Gap. https://axis-intelligence.com/patch-management-statistics/

MLA Axis Intelligence Research. “Patch Management Statistics 2026: Remediation Speed, Mandated Deadlines, and the Patch Deficit Gap.” Axis Intelligence, 13 Aug. 2026, axis-intelligence.com/patch-management-statistics/.

Chicago Axis Intelligence Research. “Patch Management Statistics 2026: Remediation Speed, Mandated Deadlines, and the Patch Deficit Gap.” Axis Intelligence, August 13, 2026. https://axis-intelligence.com/patch-management-statistics/.

PDG™ attribution: PDG™ (Patch Deficit Gap) is a proprietary metric of Axis Intelligence Research, licensed CC BY 4.0. Cite as: Axis Intelligence Research, PDG™ baseline reading, August 11, 2026, axis-intelligence.com/patch-management-statistics/.

Frequently Asked Questions

Does a 43-day median remediation time mean my patch SLA should be 43 days?

No — it is a benchmark of what organizations achieve, not a target. Read it against the deadline that applies to the asset. A 43-day median against a three-day federal tier on an internet-facing appliance describes a program that would fail its obligation fourteen times over; the same 43 days against a 60-day default timeline for an unenriched, internally exposed CVE is comfortably inside scope. The median is context-free by construction. Your SLA should not be.

Why did KEV full remediation drop from 38% to 26% if teams patched more instances than ever?

Because the denominator grew faster than the numerator. The median organization faced 16 KEV vulnerabilities in 2025 against 11 in 2024, and the underlying detection dataset grew roughly eightfold since 2022. Absolute preemptive remediation rose 30% year over year, to 63.7 million instances. Completion rate and work volume moved in opposite directions, which is the signature of a capacity constraint rather than a process regression.

How do I calculate my own Patch Deficit Gap?

Take your median days-to-close for KEV-listed findings from your scanner’s remediation report, then subtract the deadline that applies to those assets — the BOD 26-04 tier if you are in federal scope, your internal SLA if not. Segment it by asset class before you segment it by anything else: our data shows the mandated window varies by a factor of nearly five between network-edge products and operating systems, so a single organization-wide PDG hides the exposure that actually matters.

Should private-sector organizations adopt the three-day BOD 26-04 tier?

BOD 26-04 binds Federal Civilian Executive Branch agencies. Its practical reach is wider: FedRAMP set December 7, 2026 for adoption of aligned rules, which brings authorized cloud service providers into scope, and contract language increasingly references federal remediation timelines. Whether the tier is achievable depends far more on whether you can enumerate internet-facing assets from an inventory in minutes than on your deployment tooling — public exposure is the one variable of the four that the asset owner supplies.

Why does the mandated window vary so much between a firewall and a Windows server?

Because BOD 26-04 sets deadlines from risk variables, not product categories, and network-edge devices happen to satisfy all four at once: they are publicly exposed by function, they reach the KEV catalog quickly, their exploits are usually automatable, and successful exploitation typically yields total control. In 2026, 82.9% of network-edge KEV entries carry a deadline of three days or less against 14.3% of operating system and endpoint entries. The tier is describing exposure, not vendor quality.

What should I do about a KEV entry where CISA says to disconnect rather than patch?

Treat it as an asset retirement ticket, not a patching ticket, and route it accordingly. Eighty-three catalog entries — 4.98% — fall into this category because the product reached end of life. These do not belong in a patch queue at all: they will sit unremediated forever, degrading your completion metrics while the actual exposure stays open. Segmentation buys time; replacement closes it.

Does patching faster fix the exploitation problem on its own?

The survival data argues it cannot. Between 60% and 70% of KEV instances remain open at day 7 regardless of organizational maturity, and the top performers close only 30% to 40% in that first week — a ceiling that three years of tooling investment barely moved. If exploitation begins inside that window, remediation speed alone cannot be the whole control. The reading the data supports is that patch prioritization decides which vulnerabilities fall inside your capacity, and detection covers the ones that do not.

Is the preemptive remediation rate a better patch management metric than time-to-patch?

It is a useful complement, and it moved in a direction worth watching: 12% of vulnerability instances were remediated before their KEV listing in 2025, down from 17% in 2024. Because it measures fixes applied before any mandate or alert existed, it isolates program maturity from mandate response in a way that mean time to patch cannot. Track both — one measures your reaction, the other measures your baseline hygiene.

Why do memory safety bugs still dominate patch queues in 2026?

Because installed software turns over slowly, and the fix is architectural rather than operational. Verizon’s detection data puts memory safety weaknesses in 89% of organizations. Upstream, the same categories take a median of six to seven months to resolve half of their instances in codebases with mature development lifecycles. Secure-by-design work and memory-safe languages address the supply of these flaws; nothing addresses the installed base except time and replacement cycles.

How often does this dataset change?

The KEV catalog updates in irregular batches with no fixed publication day, so the mandated-window figures move continuously. The Verizon remediation medians update annually, typically in May. Poll the version-stamped KEV JSON and key on catalogVersion rather than assuming a cadence if you are rebuilding these figures yourself.


Related Research

Recent Posts

Multimodal AI Statistics 2026: What Voice, Image and Video Really Cost Per Token

Multimodal AI Statistics 2026 By Axis Intelligence Research Co-author: Sarah Mitchell | Last updated: September 25, 2026

Live Streaming Statistics 2026: Hours Watched, Platform Share & the Viewer Density Gap

Live Streaming Statistics 2026 By Axis Intelligence Research Co-author: Noah Mc | Last updated: September 25, 2026 | Lic

AI Data Center E-Waste Statistics 2026: The 87% Nobody Counted

AI Data Center E-Waste Statistics 2026 By Axis Intelligence Research Co-author: Aidan Jad | Last updated: September 25,

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.