SHARE
Facebook X Pinterest WhatsApp

55 Software Vulnerabilities Reported Every Day

SAN JOSE, Calif. — A new cybersecurity report is showing “the exploitability of entire organizations” in terms of software vulnerability. With an average of 55 new software vulnerabilities published every day in 2021, IT teams “cannot fix all of the vulnerabilities across their infrastructures,” according to Cisco this month.  The findings are based on a […]

Written By
thumbnail Chris Ehrlich
Chris Ehrlich
Jan 31, 2022
Datamation content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

SAN JOSE, Calif. — A new cybersecurity report is showing “the exploitability of entire organizations” in terms of software vulnerability.

With an average of 55 new software vulnerabilities published every day in 2021, IT teams “cannot fix all of the vulnerabilities across their infrastructures,” according to Cisco this month. 

The findings are based on a report by Cisco’s Kenna Security, “Prioritization to Prediction, Volume 8: Measuring and Minimizing Exploitability,” with research also conducted by the Cyentia Institute.

The report shows that prioritizing vulnerabilities to fix is more effective than increasing an organization’s capacity to patch them — but having both can achieve a 29 times reduction in an organization’s measured exploitability.

The team’s research confirms a recent Cybersecurity and Infrastructure Security Agency (CISA) directive that suggests it’s wiser to move away from prioritizing fixing of vulnerabilities based on CVSS scores and instead focus on high-risk vulnerabilities, according to Cisco.

Analysis shows that factors like exploit code and even Twitter mentions are “better signals than CVSS scores.”

See more: The Cybersecurity Market

Key findings

  • Nearly all (95%) IT assets have at least one highly exploitable vulnerability
  • Prioritizing vulnerabilities with exploit code is 11 times more effective than CVSS in minimizing exploitability
  • Most (87%) organizations have open vulnerabilities in at least a quarter of their active assets, and 41% of them show vulnerabilities in three of every four assets
  • A strong 62% majority of vulnerabilities have less than a 1% chance of exploitation. Only 5% of CVEs exceed 10% probability.

See more: Top 10 Cybersecurity Threats

Exploitability was determined using the open Exploit Prediction Scoring System (EPSS), a cross-industry effort, including Kenna Security and the Cyentia Institute, that is maintained by FIRST.org.

“Exploitations in the wild used to be the best indicator for which vulnerabilities security teams should prioritize,” said Ed Bellis, co-founder and CTO of Kenna Security.

“Now we can show the likelihood of a particular organization being exploited, which is what we’ve always wanted to do.”

See more: Top Cybersecurity Companies

Cybersecurity threats on the rise

The report is the latest in a string of cybersecurity reports conducted by various organizations, including companies in the market.

The reports show cyber threats grew significantly over the past year, across a variety of metrics, as well as internal cyber vulnerabilities.

For instance, Trend Micro reports a 47% increase in blocked cyber threats, and Thales says 83% of companies don’t encrypt all sensitive data in cloud.

thumbnail Chris Ehrlich

Chris Ehrlich is the managing editor of several web properties in the TechnologyAdvice network. He has over 20 years of experience delivering content-based results across journalism and communications, including on B2B technologies. As a leader in digital journalism, he’s driven targeted content that resonates with audiences and increases key metrics. As a leader in branded communications, he’s driven multi-channel content for clients that spreads their messages and generates measurable returns. He holds a B.A. in English and political science from Denison University in Ohio.

Recommended for you...

AI in Cybersecurity: The Comprehensive Guide to Modern Security
Liz Ticong
Apr 29, 2024
What Is Cybersecurity? Definitions, Practices, Threats
Liz Ticong
Apr 8, 2024
How to Secure a Network: 9 Key Actions to Secure Your Data
Liz Ticong
Mar 21, 2024
7 Best Data Security Software: Solutions For 2024
Datamation Logo

Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.