← כל הכתבות דוח נתונים

Critical Flaws: 100% of Small Businesses Face Urgent Security and Maintenance Alerts

A new analysis reveals that every endpoint in a sample of small businesses is plagued by active security and maintenance issues, including long-standing, exploited vulnerabilities.

מאת אושרי פנחס · 07/08/2026

An alarming new data analysis from XIT’s monitoring system, based on an anonymous sample of 11 endpoints across small businesses in Israel, paints a grim picture of cybersecurity and IT maintenance. The findings indicate that every single computer examined (11 out of 11) suffers from at least one active alert, pointing to a severe lack of routine maintenance and significant gaps in protection against cyber threats.

One of the most disturbing revelations is the presence of known security vulnerabilities, some of which have been actively exploited in the wild, remaining unpatched on systems for extended periods—in some cases, for years. This persistent neglect leaves these businesses highly exposed to attack.

Pervasive Maintenance and Security Gaps

The data highlights a wide array of common issues affecting system integrity and security levels. The most frequent problem identified is 'updates_pending,' with 7 out of 11 computers (64%) awaiting critical updates. Failure to apply these updates promptly exposes systems to documented vulnerabilities, as security patches are specifically designed to fix these weaknesses.

Equally concerning is the high rate of critical system failures: 6 out of 11 computers (55%) experienced 'blue screen of death' (BSOD) events, and another 6 out of 11 (55%) suffered unexpected shutdowns. Such failures disrupt workflow, lead to data loss, and can signal severe, unaddressed hardware or software problems.

Additionally, 5 out of 11 computers (45%) are plagued by 'drivers_error,' and 2 out of 11 (18%) show 'missing security updates.' While the latter percentage may seem relatively low, it is critically important, as security updates are the first line of defense against cyberattacks. The findings also reveal that one computer (9%) operates with its firewall off ('firewall_off'), and another (9%) has an active antivirus threat ('av_threat'). These figures underscore a lack of awareness or neglect of basic security controls, leaving businesses vulnerable.

Further performance metrics reinforce this bleak outlook. While average CPU utilization stands at 14.0% and average memory usage at 60.0% (excluding high-load machines), and average free disk space is 57.0% (excluding nearly full disks), the real issues lie elsewhere. Seven out of 11 computers are awaiting updates, totaling 10 pending updates. In the last 30 days, 14 blue screen events were recorded across the fleet, and 57 system errors appeared in event logs within the last 24 hours. These statistics point to ongoing operational instability.

The Danger of Neglected, Exploited Vulnerabilities

A particularly critical aspect emerging from the data is the issue of actively exploited vulnerabilities. The XIT system identified 206 open vulnerability findings across the 11 computers, representing 28 unique CVEs (Common Vulnerabilities and Exposures). Of these, 17 are vulnerabilities that have been actively exploited in the wild and are listed in CISA's (U.S. Cybersecurity and Infrastructure Security Agency) Known Exploited Vulnerabilities (KEV) catalog.

A particularly alarming statistic is that the oldest exploited vulnerability still open is CVE-2020-0878, a Microsoft Edge flaw that entered CISA’s exploitation catalog on November 3, 2021. This means the vulnerability has remained unpatched on small business systems for over 1,000 days (nearly three years) since it was publicly identified as an active, proven threat. The fact that older, well-documented vulnerabilities are the most exploited is no coincidence. Attackers often focus on known vulnerabilities because readily available and easy-to-use exploits exist for them. Small businesses, which often lack dedicated cybersecurity resources and expertise, become easy targets.

The window during which a known vulnerability remains open on a system, from its publication to its remediation, is an opportunity for attackers. In the case of CVE-2020-0878, this window has stretched for years, during which the business was continuously exposed to exploitation. Other examples include CVE-2025-0411 in 7-Zip (with a 67.1% exploitation probability) and CVE-2025-15556 in Notepad++ (with a 1.3% exploitation probability), both of which are actively exploited.

The data also reveals that 3 out of 11 computers are running an operating system that has reached end-of-life (Windows 10 and older). These machines will no longer receive security updates, making them exceptionally vulnerable to any new or old threats. This represents a ticking time bomb from a security perspective.

Professional Recommendations and Business Implications

The business implications of these findings are severe. Full hard drives, unpatched software, blue screens, and unexpected shutdowns are not just technical nuisances. They impair work efficiency, lead to the loss of valuable data, disrupt business continuity, and can result in significant financial losses. Furthermore, unaddressed security vulnerabilities provide an open door for attackers to steal sensitive information, encrypt files (ransomware attacks), or use business computers as platforms for further attacks. The business risk includes reputational damage, regulatory fines (in the event of a data breach), and even complete operational shutdown.

A critical professional recommendation is to adopt a proactive approach to maintenance and information security. This includes regularly performing software and operating system updates, actively monitoring systems for anomalies and faults, and immediately addressing security vulnerabilities. It is essential to use only supported operating systems and to upgrade computers running end-of-life systems. Additionally, it is vital to ensure all computers are protected by an updated firewall and antivirus software. Investing in ongoing maintenance and information security is not an expense but a necessary investment in protecting business assets and ensuring operational continuity, a lesson applicable to small businesses worldwide, not just in Israel.