The Patchwork Fortress: Why 92% of Small Business Workstations in Israel are Sitting Ducks for Cyberattacks
New data from XIT reveals a dangerous backlog of unpatched vulnerabilities and hardware neglect, leaving small businesses exposed to exploits that have been public for years.
A new report from the XIT monitoring system, released September 15, 2026, paints a grim picture of the digital resilience of small and medium-sized businesses (SMBs) in Israel. Based on an anonymous sample of 13 endpoints representing daily business operations, the study found that 12 out of 13 (approximately 92%) had at least one active alert indicating a failure in maintenance, performance, or security.
The findings highlight a critical "exposure window": 69% of the sampled computers are currently waiting for uninstalled system updates, with a total of 15 pending updates across the small fleet. While large enterprises typically employ automated Patch Management systems, the data suggests that for Israeli small businesses, IT maintenance is frequently pushed to the bottom of the priority list. This neglect is not just a local issue; as global supply chains become more integrated, a single unpatched workstation in a small Israeli firm can serve as a weak link for international partners.
The Vulnerability Gap: Three-Year-Old Exploits Still Active
The XIT data identified 266 open vulnerability findings across the 13 computers, comprising 32 unique CVE identifiers. Alarmingly, 21 of these vulnerabilities are already classified by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as Known Exploited Vulnerabilities (KEV)—meaning they are actively being used by hackers "in the wild."
Perhaps the most disturbing finding is the age of these gaps. The oldest unpatched exploit identified was CVE-2020-0878 in the Microsoft Edge browser, which was added to the CISA catalog in November 2021. This means business workstations in Israel are currently exposed to malicious code that has been known to the security community for over three years. By failing to update, these businesses are essentially leaving their digital doors unlocked for automated scanning tools used by global threat actors.
The risk is not limited to legacy software. The sample also detected fresh threats, such as outdated versions of WinRAR (version 5.91) vulnerable to CVE-2025-8088 and CVE-2025-6218. These vulnerabilities carry a high severity rating (CVSS 8.8) and an extremely high exploitation probability of 94.6%. An attacker leveraging these can achieve remote code execution simply by sending a compromised archive file, bypassing traditional perimeter defenses.
Hardware Fatigue and System Instability
IT maintenance in the SMB sector is as much about operational stability as it is about security. XIT's monitoring shows that 31% of the computers experienced a "Blue Screen of Death" (BSOD) within the last 30 days, totaling 10 system crashes. Furthermore, 49 critical system errors were recorded in the Event Viewer within a single 24-hour window.
These failures, combined with the fact that 38% of the computers suffer from driver errors, point to aging hardware and a lack of preventative maintenance. The operational risk is further compounded by the use of end-of-life software: 23% of the workstations are running unsupported operating systems (certain older versions of Windows 10 or below). These machines will never receive another security patch, making them "ticking time bombs" that can be used for lateral movement within a corporate network to infect more modern servers.
The Resource Crunch: Why SMBs are Failing
The findings suggest a direct correlation between resource strain and system instability. Average memory consumption in the sample stood at 59%, but several machines crossed the 85% threshold, leading to significant performance degradation. Low disk space, found in 8% of cases, creates a secondary security risk: operating systems require free space to download and install updates. When a disk is full, the auto-update process fails silently, leaving the machine vulnerable.
Finally, the average uptime between reboots was 200 hours. While no computer had gone more than a month without a restart, an eight-day uptime can prevent the final installation of critical kernel updates. For small businesses, the professional recommendation remains clear: adopt forced update policies and mandate at least one weekly reboot. Without centralized management, the window between a vulnerability's release and its remediation remains dangerously wide.