Threat Intelligence

Vulnerability Discovery Is Outpacing Fixes, Research Shows

Dark Reading · 10 Sept 2026
Key Takeaway Don't assume software is safe just because no vulnerability has been publicly reported; keep systems updated promptly and monitor vendor advisories closely.

New research examining findings from Project Glasswing shows a growing gap between the number of vulnerabilities being discovered and the number actually being disclosed or fixed. Only a small fraction of identified issues have made it through to public disclosure, and an even smaller number have received patches from vendors.

The finding points to a bottleneck in the human processes behind vulnerability management: triage, verification, coordination with vendors, and remediation all take time and resources that have not kept pace with the volume of discoveries. For businesses relying on third-party software, this means known weaknesses may exist in products they use well before, or even without, a public fix ever being released.

While the research focuses on the broader disclosure ecosystem rather than a specific active threat, it is a reminder that patch availability cannot always be assumed to follow quickly after a vulnerability is found.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.