How Long Can Your Company Afford to Leave a Critical Vulnerability Unpatched?
Posted in Uncategorized
Critical Vulnerability Patching
When a critical vulnerability shows up, your IT team needs to act fast to stay ahead of attackers.
Once a vulnerability becomes public, your company has a limited time to check if you are affected, understand the risk, fix the problem, and make sure your systems are secure.
So, how long can your company safely leave a critical vulnerability unpatched?
There isn’t one set number of days. The higher the risk and potential impact, the faster your company should respond.
A critical vulnerability on an isolated internal system does not necessarily require the same response as a known exploited vulnerability affecting an internet-facing server.
NIST recommends that companies set up a patch management process to find, prioritize, get, install, and check patches. The goal is more than just applying updates. Good patch management helps prevent compromise, data loss, downtime, and other issues.
For business leaders, the key question is therefore not:
“How many critical vulnerabilities do we have?”
It is:
“Which vulnerabilities create enough risk that we cannot afford to leave them exposed?”
There Is No One-Size-Fits-All Patching Deadline
Many companies ask whether they should patch every critical vulnerability within 24 hours, 48 hours, or seven days.
A better approach is to set your remediation goals based on risk.
Consider two critical vulnerabilities.
The first affects an internal application that requires authentication and sits behind multiple security controls.
The second affects an internet-facing remote-access system, and attackers are already exploiting the vulnerability.
Both may have a critical CVSS score, but the second represents a substantially more urgent business risk.
Your remediation timeline needs to account for factors such as:
- Whether attackers actively exploit the vulnerability
- Whether the affected system faces the internet
- Whether exploitation works remotely
- Whether authentication is required
- What access exploitation might provide
- Whether sensitive data is involved
- How important the affected system is to business operations
- Whether effective compensating controls exist
This approach helps your IT team clearly decide which issues to fix first.
Known Exploited Vulnerabilities Require Immediate Attention
One of the strongest indicators of urgency is evidence that attackers already exploit a vulnerability.
CISA manages the Known Exploited Vulnerabilities (KEV) Catalog to find vulnerabilities with evidence of exploitation in the wild. CISA encourages companies to use the catalog to focus remediation on vulnerabilities with demonstrated attack risk, not theoretical possibility.
Even if attackers aren’t exploiting a critical vulnerability yet, it still needs your attention.
If attackers are already exploiting a critical vulnerability, it needs attention.
The distinction becomes even more important when the vulnerable system is accessible from the internet.
Internet-Facing Systems Increase the Risk
Attackers can continuously scan the internet for vulnerable systems.
Attackers don’t need anyone to click a phishing email, enter your office, or already be inside your network.
If a vulnerable firewall, VPN, remote-access service, web application, or cloud system is exposed to the internet, attackers can potentially identify and target it directly.
This is why external exposure is one of the most important factors when deciding how quickly to fix a vulnerability.
Your vulnerability management program should therefore answer a basic question for every serious vulnerability:
Can an attacker reach the affected system right now?
If the answer is yes, the remediation timeline deserves particular scrutiny.
CVSS Scores Do Not Tell the Whole Story
CVSS provides a standard way to rate vulnerability severity, but it does not account for your company’s specific situation.
It does not know whether a vulnerable server contains sensitive information.
It does not know whether the server connects to your financial systems.
It does not know whether network segmentation prevents lateral movement.
It does not know whether attackers can reach the system from the internet.
These details are what truly shape your business risk.
A risk-based vulnerability management program combines technical severity with environmental and business context.
Think of the calculation as:
Severity + Exploitability + Exposure + Asset Importance + Business Impact
This way, leaders get a clearer picture than just sorting vulnerabilities by CVSS score.
How Long Is Too Long?
Your company should establish internal remediation targets before a critical vulnerability appears.
A practical framework could look like this:
| Vulnerability situation | Recommended response |
| Known exploited vulnerability affecting an internet-facing critical system | Emergency response and remediation as quickly as technically feasible |
| Critical vulnerability with a public exploit and internet exposure | Immediate prioritization and rapid remediation |
| Critical vulnerability affecting a high-value internal system | Rapid remediation measured in days rather than weeks |
| Critical vulnerability with effective compensating controls | Document the risk and establish a defined remediation deadline |
| Vulnerability that cannot be patched immediately | Apply compensating controls and establish a plan for permanent remediation |
These represent risk-management targets, not universal regulatory requirements.
Your company should establish its own standards based on its industry, technology environment, regulatory obligations, contractual requirements, and risk tolerance.
The most important thing is to set a deadline.
A critical vulnerability shouldn’t sit unresolved in a ticket queue for too long.
What If You Cannot Patch the Vulnerability?
Sometimes immediate patching is not practical.
The vendor may not have released a fix. The affected application may support a critical business process. The patch may require extensive testing or downtime.
But that doesn’t mean you should ignore the vulnerability.
Your company should document:
- The vulnerability — What weakness remains?
- The exposure — Which systems and assets are affected?
- The reason for the delay — Why cannot the company patch now?
- The compensating controls — What reduces the risk?
- The owner — Who accepts responsibility for the remaining risk?
- The deadline — When will the company reassess or permanently remediate the vulnerability?
Possible compensating controls include network segmentation, access restrictions, configuration changes, disabling unnecessary services, removing internet exposure, and increased security monitoring.
NIST recognizes that companies sometimes need different remediation methods when they cannot immediately apply patches.
The goal is to manage risk, not to let exceptions become routine.
Measure How Quickly Your Company Remediates Vulnerabilities
Many companies track how many vulnerabilities they have.
That number doesn’t mean much without context.
Leadership should also understand how quickly the IT team handles major vulnerabilities.
NIST specifically recommends useful mitigation metrics, including measures of remediation time, to help companies evaluate vulnerability management performance.
For executives, these metrics turn vulnerability management from just a technical task into a way to measure and manage risk.
Vulnerability Assessment vs. Penetration Testing
A vulnerability assessment and a penetration test answer different questions.
A vulnerability assessment helps identify security weaknesses across your technology environment.
A penetration test attempts to exploit vulnerabilities and determine what an attacker could accomplish.
Understanding the difference helps your company make better decisions about which vulnerabilities to fix and when.
For example, a vulnerability assessment might identify a weakness in an internet-facing application.
A penetration test could determine whether an attacker can use that weakness to obtain credentials, access sensitive information, move laterally, or gain privileged access.
Your company does not have to run a penetration test for every vulnerability.
But when the potential business impact is significant, validating exploitability can give valuable information for prioritizing remediation. Read more about the difference between an external penetration test vs vulnerability assessment.
A mature program follows a continuous cycle:
Discover → Prioritize → Validate → Remediate → Verify
Verify That the Vulnerability Is Actually Fixed
Just closing a remediation ticket doesn’t always mean the vulnerability is gone.
The patch may have failed.
A vulnerable version may remain on another system.
A configuration change may not have applied correctly.
You may have overlooked a second instance of the affected application.
For this reason, NIST includes verification as part of enterprise patch management.
After remediation, your company should verify that the vulnerable condition no longer exists.
For significant vulnerabilities, additional vulnerability scanning or penetration testing can provide that validation.
AI Is Making Remediation Speed More Important
Artificial intelligence is increasing how quickly researchers can analyze software and identify vulnerabilities.
Attackers can also use AI to accelerate reconnaissance, vulnerability research, social engineering, and other activities.
This means the time between finding a vulnerability and it being exploited may keep getting shorter.
NIST’s Cyber AI Profile work reflects this larger shift by examining both AI-enabled cyber attacks and AI-enabled cyber defense.
The implication for vulnerability management is clear:
Your company needs to know how quickly it can move from vulnerability discovery to meaningful risk reduction.
If fixing vulnerabilities takes weeks or months, attackers using automation can make those delays even riskier. Read more about why a company should perform monthly network vulnerability assessments.
What CIOs Should Ask About Critical Vulnerabilities
CIOs do not need to understand every technical detail behind a CVE.
They should, however, be able to ask:
- How many critical vulnerabilities currently affect our environment?
- How many are known to be exploited?
- How many affect internet-facing systems?
- How long have our oldest critical vulnerabilities remained unresolved?
- What percentage do we remediate within our established timeframe?
- Which vulnerabilities cannot be patched immediately?
- What compensating controls protect those systems?
- Who accepts the remaining risk?
- How do we verify that remediation worked?
These questions give you a much clearer view of your cybersecurity risk than simply asking if the latest vulnerability scan is finished.
The Business Cost of Waiting
The cost of patching usually feels immediate.
IT staff need to test an update. A maintenance window may be necessary. An application may require downtime.
The cost of waiting often isn’t obvious until an attacker exploits the vulnerability.
Then the company may face:
- Business interruption
- Incident response costs
- Forensic investigation
- Data recovery
- Lost productivity
- Customer notification
- Legal expenses
- Regulatory consequences
- Reputation damage
NIST describes enterprise patch management as preventive maintenance because effective patching helps reduce the likelihood and impact of security incidents and operational disruptions.
This shows that fixing vulnerabilities quickly is about more than just IT concerns.
Patching helps your business keep running smoothly.
How Tanner Security Can Help
Tanner Security helps companies identify, prioritize, and reduce cybersecurity risk.
Our Vulnerability Assessment services can identify weaknesses across networks, systems, applications, and infrastructure.
Our Penetration Testing services go further by attempting to exploit vulnerabilities and determine how an attacker could compromise your environment.
An IT Risk Assessment can put those technical findings into business context so leadership understands which risks deserve attention first.
Tanner Security can also help companies strengthen their vulnerability management processes, establish practical remediation priorities, and validate whether security improvements actually reduce exposure.
The goal isn’t to create another long vulnerability report.
The goal is to help your company see which vulnerabilities matter most and what steps to take next.
Critical Vulnerability Patching Frequently Asked Questions
How quickly should a critical vulnerability be patched?
The appropriate timeline depends on the risk and the affected environment. A known exploited vulnerability affecting an internet-facing critical system may require emergency remediation, potentially within 24 to 48 hours when technically feasible. Other vulnerabilities may justify different timelines based on exploitability, exposure, asset importance, and compensating controls.
Is 24 hours a reasonable goal for critical vulnerabilities?
It can be an appropriate target for the highest-risk vulnerabilities, particularly those actively exploited or exposed to the internet. Companies should establish their own risk-based remediation standards rather than applying the same deadline to every critical vulnerability.
What makes a vulnerability critical?
A critical vulnerability generally presents the potential for severe consequences if exploited. CVSS provides one way to communicate technical severity, but companies should also consider actual exploitability, exposure, affected assets, and potential business impact.
What is a known exploited vulnerability?
A known exploited vulnerability has evidence that attackers have used the vulnerability in real-world attacks. CISA tracks these vulnerabilities in its Known Exploited Vulnerabilities Catalog and recommends prioritizing them for remediation.
Should every critical vulnerability receive the same remediation deadline?
No. Companies should consider exploitation, internet exposure, asset criticality, potential business impact, available security controls, and other factors when setting remediation deadlines.
What should a company do if it cannot patch a critical vulnerability?
The company should document the risk, determine why immediate patching cannot occur, apply appropriate compensating controls, assign responsibility for the remaining risk, and establish a timeline for permanent remediation. Read more about the 10 cybersecurity myths small businesses need to know.
Can compensating controls replace a security patch?
Compensating controls can reduce risk when patching is not possible, but they should not automatically replace permanent remediation. Companies should keep working toward a supported, secure configuration.
Does CVSS determine how quickly a vulnerability should be patched?
No. CVSS provides useful technical severity information, but it does not account for every factor in your company’s environment. Exploitability, exposure, asset importance, known exploitation, and business impact should also influence remediation priorities. Read more about which cybersecurity investment a company should make first.
How should companies prioritize vulnerabilities?
Companies should combine technical severity with exploitability, known exploitation, internet exposure, asset importance, sensitive data, business impact, and existing security controls. Look at the CIS controls implementation checklist for more information about prioritizing vulnerabilities.
Are network security scans enough?
Network security scanning provides broad visibility into security weaknesses, but it does not always show whether an attacker can exploit a weakness or what they could accomplish. An AWS penetration testing can give a deeper assurance when the impact warrants it.
What is the difference between vulnerability assessment and penetration testing?
A vulnerability assessment identifies and evaluates security weaknesses. Penetration testing attempts to exploit weaknesses to determine whether they may result in meaningful compromise. Learn more about the difference in an external network pen test and a vulnerability assessment.
How often should companies perform vulnerability assessments?
The appropriate frequency depends on the company’s risk profile, technology environment, rate of change, and regulatory or contractual requirements. Companies should maintain ongoing vulnerability visibility and reassess systems after significant changes. Learn more about why we suggest performing vulnerability assessments on a monthly basis.
Can AI make vulnerability remediation more urgent?
Yes. AI is finding vulnerabilities faster than companies can patch them and can accelerate vulnerability discovery and cybersecurity research, while attackers can use AI to improve reconnaissance and other attack activities. As the time between discovery and exploitation potentially shrinks, companies need efficient processes to identify, prioritize, and remediate vulnerabilities.
Can Tanner Security help rank critical vulnerabilities?
Yes. Tanner Security can perform vulnerability assessments, penetration testing, and IT risk assessments to help companies understand their vulnerabilities, evaluate practical risk, prioritize remediation, and validate security improvements.
Related Cybersecurity Services
Vulnerability Assessment: Identify and evaluate vulnerabilities across your company’s technology environment.
Penetration Testing: Determine whether attackers can exploit vulnerabilities and what they could accomplish.
IT Risk Assessment: Put cybersecurity vulnerabilities into the context of business operations and risk.
NIST IT Audit: Strengthen network architecture, segmentation, access controls, and other security measures.
NIST CSF Consulting: Develop a practical cybersecurity strategy based on your company’s specific risks and business priorities.
Critical Vulnerability Patching Bottom Line
A critical vulnerability does not automatically come with a universal 24-hour or 48-hour deadline.
But that doesn’t mean your company should wait.
The most important factors include known exploitation, internet exposure, exploitability, asset importance, business impact, and available security controls.
Your company should already have a process for answering five questions:
- What is vulnerable?
- How serious is the risk?
- Can an attacker reach it?
- How quickly can we reduce the risk?
- How do we verify the fix?
If your company can’t answer these questions quickly, it might be time to review your vulnerability management program.
Tanner Security can help you identify your most significant vulnerabilities, understand the risk they create, and determine what to address first.
Don’t wait for a critical vulnerability to turn into a security incident before deciding how quickly your company should respond.
Contact Form
Schedule a Call