Provides macro-level statistics on CVE volume and remediation speed, highlighting the 23-day 'Exploit-before-CVE' window that threat actors systematically exploit.
The National Vulnerability Database (NVD) and CVE list contain over 176,000 recorded vulnerabilities, with a record 26,447 disclosed in 2023—representing a consistent annual upward trend. While 11% of all CVEs carry a critical CVSS score of 9.0-10.0, research shows that 75% of attacks in 2020 utilized vulnerabilities at least two years old, with 18% leveraging flaws from 2013 or earlier. The mean time to remediation (MTTR) for internet-facing vulnerabilities is approximately 58 days, though this varies by industry, from 44 days in healthcare to 92 days in public administration. Most critically, 80% of public exploits are published an average of 23 days before the corresponding CVE is officially disclosed, giving attackers a significant head start in targeting unpatched infrastructure.
75% of attacks in 2020 used vulnerabilities at least two years old with patches long available, indicating systemic downstream remediation failure.
catastrophic compromise from long-standing, well-known vulnerabilities that should have been patched years ago
packages with historically slow remediation cycles perpetuate the 'legacy exploit' trend where attackers rely on years-old flaws with available but unapplied patches.
80% of public exploits are published before the CVEs are published... an exploit is published 23 days before the CVE.
Risk Guard relies on formal CVE data but does not detect 'Pre-CVE' exploits that exist for an average of 23 days before formal disclosure.
Risk Guard would be better if it integrated a 'Pre-CVE Threat Feed' that identified components with public exploits that have not yet been assigned a CVE number.