← כל הכתבות דוח נתונים

The 1,100-Day Vulnerability Window: Why Small Business IT is a Global Security Time Bomb

New data from Israel reveals that 100% of small business endpoints harbor active security threats, with critical vulnerabilities remaining unpatched for over three years.

מאת אושרי פנחס · 16/08/2026

In the global cybersecurity landscape, small and medium-sized businesses (SMBs) are often described as the 'soft underbelly' of the digital economy. New data released on August 16, 2026, by the XIT monitoring system provides a stark, empirical look at just how soft that underbelly is. A study of small businesses in Israel—a nation often considered a global hub for cybersecurity innovation—reveals a troubling paradox: despite the country's high-tech reputation, its local small business infrastructure is riddled with basic, preventable vulnerabilities.

The findings are absolute. In a sample of 11 endpoints across various organizations, 100% of the computers were found to have at least one active security or system health alert. Not a single device in the sample could be classified as 'fully healthy.' While the sample size is focused, the density of the findings is alarming: 206 open vulnerability findings were identified across just 11 machines, encompassing 28 unique Common Vulnerabilities and Exposures (CVE) identifiers.

The Thousand-Day Exposure Gap

The most damning metric in the report is the age of the unpatched vulnerabilities. Security professionals typically aim to patch critical flaws within days or weeks; however, the XIT data found that CVE-2020-0878, a vulnerability related to the Microsoft Edge browser, is still active on business endpoints in 2025. This flaw was added to the CISA (Cybersecurity and Infrastructure Security Agency) Known Exploited Vulnerabilities (KEV) catalog on November 3, 2021.

The presence of a 2020 vulnerability in 2025 represents an exposure window of over 1,100 days. During this time, the systems remained open to a documented, 'in-the-wild' exploit. This matters far beyond the borders of Israel because attackers rarely target SMBs with expensive, custom-made 'Zero-day' exploits. Instead, they use automated tools to scan the globe for these exact types of 'legacy' flaws—vulnerabilities for which public exploit code and step-by-step tutorials are readily available on the dark web.

The risk is not just historical; it is immediate and evolving. The report also identified CVE-2025-0411 in the 7-Zip utility, which carries a CVSS severity score of 7.0 and a staggering 67.1% exploitation probability. This demonstrates that small businesses are failing to defend against both the ghosts of the past and the threats of the present.

Maintenance Neglect and Business Continuity

The data suggests that security failures are a symptom of broader IT neglect. According to the report, 55% of the computers had pending updates, and 45% suffered from driver errors. These are not merely administrative nuisances; they result in tangible operational downtime. In a 30-day window, the sample recorded 7 'Blue Screen of Death' (BSOD) events and 56 critical system errors within a single 24-hour period.

Furthermore, 3 out of the 11 computers were running end-of-life operating systems (Windows 10 versions or older that no longer receive security support). When 27% of machines experience unexpected shutdowns and 18% are under high memory stress, the risk of data loss from a system crash becomes as high as the risk of a cyberattack. The average uptime of 167 hours—nearly a full week without a reboot—indicates that employees are not restarting their machines, a simple but critical step for applying security patches and clearing system cache.

The Global Lesson: Automation Over Apathy

The Israeli context serves as a warning for small businesses worldwide. The lack of a dedicated IT department often leads to a reliance on 'set it and forget it' configurations that eventually fail. The presence of CVE-2025-15556 in common software like Notepad++ proves that every single application on a workstation is a potential entry point that requires monitoring.

For the modern business, leaving a vulnerability open for years is a financial gamble that most cannot afford to lose. As exploitation probabilities for new flaws reach 67% within weeks of discovery, the transition to automated Patch Management and the decommissioning of unsupported legacy systems is no longer an IT recommendation—it is a requirement for economic survival.