Back to all lessons
Awareness Lessons
last month

Vulnerability Disclosure Bottleneck Leaves Critical Flaws Unpatched

Project Glasswing's analysis reveals that the sheer volume of newly discovered vulnerabilities is overwhelming the human processes responsible for disclosure and remediation, creating a dangerous backlog. When vulnerabilities are identified but not disclosed or patched in a timely manner, threat actors have an extended window of opportunity to discover and exploit them independently. This 'firehose' problem demonstrates that technical vulnerability discovery has outpaced organizational capacity to respond, making prioritization and automation essential. The consequences are severe: unpatched vulnerabilities in production systems can lead to data breaches, ransomware incidents, and prolonged attacker dwell time. Organizations cannot rely solely on manual processes when the volume and velocity of vulnerability disclosures continues to grow year over year.

Tactical Insight

Immediate actions

  • Implement a risk-based vulnerability prioritization framework (e.g., CVSS + exploitability in the wild) to triage the backlog effectively.
  • Subscribe to automated vulnerability intelligence feeds (e.g., NVD, CISA KEV) to receive real-time alerts on critical disclosures.
  • Audit your asset inventory to identify which systems are exposed to currently unpatched, high-severity vulnerabilities.

Long-term improvements

  • Deploy automated patch management tooling to reduce dependence on manual remediation workflows at scale.
  • Establish formal SLAs for patch application based on severity (e.g., critical: 24–72 hours, high: 7 days, medium: 30 days).
  • Build or join a coordinated vulnerability disclosure program to streamline researcher-to-vendor communication pipelines.

Detection & monitoring measures

  • Continuously scan internet-facing and internal assets with authenticated vulnerability scanners to detect unpatched systems.
  • Integrate vulnerability management data into your SIEM to correlate open vulnerabilities with active threat indicators.
  • Track mean time to remediate (MTTR) as a key security metric and report it to executive leadership regularly.