Quantifies the escalating frequency of CVE discovery and identifies the 190-day window between patch release and exploitation as the primary risk factor for software consumers.
As of 2025, a new vulnerability (CVE) is discovered every 10 to 20 minutes, resulting in over 40,000 disclosures in 2024 and an 18% increase in volume during early 2025. Despite the availability of patches, nearly half of all vulnerabilities are exploited within 190 days of release, primarily because organizations fail to apply updates at the required speed. The financial stakes of this remediation lag are severe, with the average data breach costing $9.44 million and cloud misconfiguration breaches hitting $4.14 million per incident. The report advocates for shifting from 'community' support to commercial distributions (e.g., Chef Enterprise) to leverage SLA-backed response commitments, proactively hardening infrastructure-as-code pipelines, and automating drift detection to close the critical 190-day exploitation window.
The 190-day average window between patch release and exploitation highlights a pervasive failure in downstream patching speed.
exposure to known, authenticated exploits that have been available to attackers for over six months
measuring the delta between patch availability and implementation is the primary way to manage the 190-day exploitation risk identified by Chef.
Nearly half of all vulnerabilities are exploited within just 190 days of patch release... primarily because affected organizations are not up to speed with the patch.
Risk Guard reports patch status but does not have a 'Remediation Timer' that alerts when an organization has exceeded the critical 190-day exploitation window.
Risk Guard would be better if it provided an 'Exploitation Probability' score that increased as the age of an unpatched vulnerability approached the 190-day threshold.