← כל הכתבות דוח נתונים

Critical Security Flaws Leave Israeli Small Businesses Exposed for Years

A new report reveals widespread, long-standing cybersecurity vulnerabilities and neglected IT maintenance across small businesses in Israel, leaving them open to known and actively exploited threats.

מאת אושרי פנחס · 22/07/2026

Alarming findings from a sample of the XIT monitoring system reveal a troubling state of computer maintenance and security among small businesses in Israel. The data indicates that every single endpoint in the sample suffers from at least one active alert, pointing to a severe lack of routine care and a high potential for significant operational and security risks. This widespread neglect exposes these businesses to well-known and documented cyber threats.

One of the most disturbing findings is the extended duration for which critical security vulnerabilities, already actively exploited by attackers, remain unpatched in small business systems. For instance, the CVE-2020-0878 vulnerability in Microsoft Edge, which was added to CISA's Known Exploited Vulnerabilities (KEV) catalog as early as November 3, 2021, is still open in some systems. This means that over 950 days (as of mid-June 2024) have passed since the security community warned about the active exploitation of this flaw, yet it remains unaddressed. This prolonged window, where a known and proven vulnerability goes uncorrected, offers a prime opportunity for attackers to breach systems, steal information, disrupt operations, or deploy malware. This issue is not unique to Israel; small businesses globally often lack the dedicated IT resources to promptly address such threats, making them attractive targets for cybercriminals.

Basic Maintenance Neglected, Common Vulnerabilities Ignored

The XIT sample, comprising 10 endpoints, uncovered a long list of fundamental maintenance issues. A significant 60% of computers exhibited driver errors (drivers_error), 40% experienced blue screens of death (BSOD) and unexpected shutdowns, and another 40% were awaiting system updates (updates_pending). These figures, combined with 20% of computers having their firewall turned off (firewall_off) and 10% with nearly full disks, paint a picture of ongoing neglect. Driver errors and unexpected shutdowns can lead to data loss, productivity hits, and critical system outages. A nearly full disk degrades performance, prevents the installation of crucial updates, and hinders the creation of essential log files for troubleshooting.

The data also showed an average memory consumption of 60%, with one out of ten computers operating under high memory load (above 85%), significantly impacting performance. Additionally, 4 out of 10 computers were awaiting updates, with a total of 6 updates pending across the sample. The absence of updates, particularly security updates, leaves known attack vectors open. The fact that one out of ten computers is running an unsupported operating system (Windows 10 and below), and therefore no longer receives security updates, poses an especially severe security risk. This highlights a common challenge for small businesses worldwide, where budget constraints often delay necessary hardware and software upgrades.

The Danger of Old, Documented Vulnerabilities

Vulnerability intelligence gathered by XIT reveals 173 open vulnerability findings across 9 computers, representing 27 unique CVEs. Of these, 16 vulnerabilities have already been actively exploited in the wild and are included in CISA's Known Exploited Vulnerabilities (KEV) list. Although the matching was performed by product name only and not verified against the installed version number, and the findings are defined as 'potential matches for review,' the mere presence of these vulnerabilities in systems is critical.

Notable examples include CVE-2025-15556 in Notepad++ with a CVSS score of 7.5 and an exploitation probability of 1.3%, and CVE-2010-0840 in Java 8 Update 491 with a severe CVSS score of 9.8. Both are actively exploited. The reason old and well-documented vulnerabilities are most frequently exploited is that they are widely known to attackers. Exploitation tools for them are broadly available, often open-source, and require little effort from the attacker. Small businesses, which typically lack the resources and expertise of larger organizations, tend to neglect updating their software and systems, thereby leaving these openings exposed for extended periods. The window between a vulnerability's publication, its entry into CISA's KEV list, and its actual remediation is critical. Every day an exploited vulnerability remains open increases the risk of a successful breach. Attackers constantly scan networks for systems with known vulnerabilities, and a lack of prompt action makes these businesses easy targets.

Professional Context and Recommendations

The business implications of these findings are severe. Failure to address basic maintenance issues can lead to system downtime, data loss, decreased productivity, and reputational damage. Beyond that, actively exploited security vulnerabilities expose businesses to the dangers of ransomware attacks, theft of sensitive information (customer data, employee records, or trade secrets), industrial espionage, and more. A successful breach can result in heavy regulatory fines (especially in the context of privacy protection), high recovery costs, and even business collapse.

To mitigate these risks, small businesses need to adopt a proactive approach to computer maintenance and security. Professional recommendations include:

The data from the XIT system underscores the urgent need for increased awareness and significant improvement in information security among small businesses in Israel, to protect them from evolving cyber threats. These recommendations are universally applicable, as small businesses globally face similar challenges and risks.