
A comprehensive security study found that 81% of software flaws exploited in confirmed cyberattacks had already been patched by developers, but affected businesses failed to install the available updates, highlighting a critical gap between available security fixes and actual implementation.
- Root Evidence analyzed 253,912 software flaws from 2018-2026 and found 3,769 used in confirmed attacks, with 81.1% having patches available before exploitation
- In 2026, 131 of 391 previously fixed flaws were exploited within 30 days of patch release, and 32 were attacked the same day updates became available
- Microsoft had the highest number of exploited flaws across all years, followed by Cisco, Fortinet, Apple, Google, and WordPress plugins
- Only 1.48% of all flaws examined were actually used in confirmed attacks, but attackers focus on high-impact vulnerabilities that bypass login, enable remote commands, or access restricted data
- WordPress plugins accounted for 208 of 711 zero-day vulnerabilities since 2018, while the number of zero-days increased to 143 in 2025
A new report is shining a light on the need to small businesses to diligently update business software.
Most software flaws used in confirmed cyberattacks had already been fixed by the developer, but affected businesses had not necessarily installed the available update, according to a new report.
The findings cover the types of technology used across many businesses, including Microsoft software, websites built with WordPress, open-source programs, mobile platforms and commercial systems from companies such as Cisco and Fortinet.
Root Evidence studied 253,912 publicly reported software and hardware flaws from Jan. 1, 2018, to July 15, 2026. Researchers found 3,769 flaws that had been used in confirmed attacks.
In 3,058 cases, or 81.1%, the developer had released an update before the first known attack. The remaining 711 were “zero-days,” meaning no fix was available when attackers first used the flaw.
Some attacks followed an update quickly. Of the 391 previously fixed flaws first attacked in 2026, 131 were used within 30 days of the update becoming available.
Thirty-two were attacked on the same day as the update. Another 99 were attacked between one and 30 days later.
The time available depended heavily on the affected company or software project. In 2026, attackers began using Cisco flaws a median of 11 days after updates became available. The median was 30 days for Apache software and 31 days for Microsoft.
Other flaws sat uncorrected on users’ systems for much longer. A total of 119 of the previously fixed flaws attacked in 2026 were not used until more than one year after an update had been released.
Across all affected products, the median time between the release of an update and the first known attack was 116 days in 2026.
Microsoft had the highest number of previously fixed flaws used in attacks in every year covered by the report. Other recurring targets included Cisco, Fortinet, Apple, Google, WordPress plugins and open-source software distributed through projects such as Apache and GitHub.
Attackers frequently targeted flaws that allowed them to enter a system without valid login information, issue commands remotely, reach restricted files or interfere with a database.
WordPress plugins were prominent among attacks that began before a fix existed. They accounted for 208 of the 711 zero-days identified since 2018.
Microsoft accounted for 132 zero-days, followed by Apple with 64 and Google with 38. Cisco and Fortinet each accounted for 15.
The number of zero-days reached 143 in 2025, up from 125 in 2024 and 118 in 2023. Researchers identified another 71 through July 15, 2026.
The report found no broad increase in attack speed connected to artificial intelligence. The number of reported flaws rose 15% in 2025 and was on pace to increase by almost one-third in 2026, but the share used in confirmed attacks remained small.
Only 1.48% of the 253,912 flaws examined had been used in a recorded attack. The annual rate remained below 2.2% in every complete year from 2018 through 2025.
“Security teams have more vulnerabilities to manage every year, but adversaries continue to focus on just a small fraction of them,” said Jeremiah Grossman, CEO of Root Evidence.
Root Evidence is a Boise, Idaho-based cybersecurity company. It compiled the study using confirmed attack records from the U.S. Cybersecurity and Infrastructure Security Agency and VulnCheck, along with update dates supplied by software developers and other primary sources.


















