By J. Mesa
In 2021, researchers recorded more software vulnerabilities than in any year before it. The record has been broken several times since. For a business, the lesson is practical: you can’t fix everything, so you need to know what to fix first.
This post explains what a vulnerability is, how the industry tracks them, and how to set priorities.
What is a software vulnerability?
A vulnerability is a flaw in software or hardware that an attacker can use to do something the designer never intended, such as running their own code, reading private data, or crashing a system. Vendors fix vulnerabilities with updates, also called patches.
What is a CVE?
CVE stands for Common Vulnerabilities and Exposures. It is a public catalog that gives each known vulnerability a unique ID, such as CVE-2021-44228. The nonprofit MITRE runs the program with funding from the US government.
A CVE ID gives everyone the same name for the same flaw. Vendors, researchers, and security tools all use it.
What is the National Vulnerability Database?
The National Vulnerability Database (NVD) is run by the National Institute of Standards and Technology. It takes each CVE and adds detail: a severity score, the affected products, and links to fixes.
How many vulnerabilities were disclosed in 2021?
A report by Risk Based Security and Flashpoint counted 28,695 vulnerabilities disclosed in 2021, the highest number on record at the time. Three findings stood out:
- 28,695 vulnerabilities were disclosed during the year.
- 29 percent had no CVE ID. Another 4 percent had an ID in “reserved” status, which meant the NVD held no usable information about them yet.
- 4,108 were remotely exploitable and had both a documented public exploit and an available fix.
That last group matters most. The report found that an organization could cut its risk and its immediate workload by nearly 86 percent by putting those vulnerabilities first.
Why does the number keep rising?
- More software exists, and more of it connects to the internet
- More researchers look for flaws, and more vendors run reward programs
- Software is built from shared components, so one flaw affects many products
- Reporting has improved
A rising count partly reflects better discovery. It still means more work for whoever maintains your systems.
What does a severity score mean?
Most vulnerabilities receive a score from the Common Vulnerability Scoring System (CVSS), on a scale of 0 to 10.
- 9.0 to 10.0: critical
- 7.0 to 8.9: high
- 4.0 to 6.9: medium
- 0.1 to 3.9: low
The score measures how bad a flaw could be. It does not tell you whether attackers are using it, or whether your business is exposed.
Do I need to patch every vulnerability?
Over time, yes. Right away, no. Nobody can install every fix at once. What matters is the order.
Which vulnerabilities should I patch first?
- Flaws attackers are using right now. CISA publishes the Known Exploited Vulnerabilities catalog, a list of flaws with confirmed attacks. Start there.
- Flaws in systems that face the internet. Firewalls, VPNs, email servers, and websites are reachable by anyone.
- Flaws that can be exploited remotely and have public exploit code.
- Critical and high scores on systems that hold sensitive data.
- Everything else, on a regular schedule.
This is the same lesson the 2021 report drew. A small share of vulnerabilities carries most of the real risk.
What is a zero-day?
A zero-day is a vulnerability that attackers use before the vendor has released a fix. You can’t patch it, so other layers have to protect you: limited access, network controls, monitoring, and backups. When the fix arrives, install it at once.
What is patch management?
Patch management is the routine of finding, testing, and installing updates. A simple version for a small business:
- Keep a list of your devices and software.
- Turn on automatic updates wherever you can.
- Check once a month for updates that need manual installation, such as firewalls and business applications.
- Install urgent fixes for internet-facing systems within days.
- Replace products the vendor no longer supports.
- Record what you did.
How fast should I patch?
Many organizations aim to fix critical flaws on internet-facing systems within days and everything else within 30 days. Attackers often begin using a new flaw within days of its disclosure, so speed on the most exposed systems matters more than perfect coverage.
How do I find out which vulnerabilities affect my business?
- Turn on update notifications from your vendors
- Subscribe to CISA alerts
- Run a vulnerability scan, which checks your systems against the list of known flaws
- Ask your IT provider for a report on what is out of date
A scan gives you a list. A risk assessment tells you which items on the list matter.
What if a system can’t be patched?
Some older systems have no fix available. Reduce the risk another way:
- Take the system off the internet
- Put it on a separate network segment
- Limit who and what can connect to it
- Plan and budget for its replacement
Why do so many vulnerabilities lack a CVE ID?
The CVE program depends on vendors and researchers to request IDs, and the process takes time. Some flaws are published on a vendor’s site or a researcher’s blog and never enter the catalog. Tools that rely only on CVE data miss those. It is one more reason to follow your vendors’ own security notices.
Does this apply to a small business?
Yes. You use the same operating systems, browsers, routers, and business applications as large companies, and attackers scan for the same flaws. The good news is that you have fewer systems to keep track of.
What should I do this month?
- List your devices and software.
- Turn on automatic updates.
- Check your firewall and router for updates.
- Look up CISA’s Known Exploited Vulnerabilities catalog and compare it with the products you use.
- Schedule a vulnerability scan.
Your next step
As the world changes, so does the threat landscape. Diligence and awareness build resistance, and a community that shares what it learns protects everyone in it. Get in touch with our team to learn how Cerberus Cybersecurity can find and rank your vulnerabilities with a risk and compliance assessment. Contact us today. At Cerberus Cybersecurity, our stance on cybersecurity is and will remain people first.

Leave a Reply