← כל הכתבות דוח נתונים

The 900-Day Vulnerability: Data Exposes Critical Security Decay in Small Business Networks

A deep dive into endpoint monitoring data reveals that 83% of small business workstations remain exposed to known exploits, some left unpatched for years.

מאת אושרי פנחס · 22/08/2026

In the global cybersecurity landscape, small and medium-sized enterprises (SMEs) are often described as the 'soft underbelly' of the digital economy. New data-driven monitoring of small businesses in Israel—a nation often considered a high-tech fortress—reveals a startling disconnect between perceived security and operational reality. Anonymous monitoring of 12 endpoints via the XIT system shows that 10 out of 12 computers (83%) suffer from at least one active security alert, signaling a high potential for operational and financial collapse.

The findings matter far beyond regional borders. As supply chains become increasingly integrated, a single unpatched workstation in a small firm can serve as a gateway for lateral movement into larger global networks. The data paints a picture of systemic neglect: 42% of monitored devices suffer from driver errors, while 33% have experienced critical Operating System failures, known as the 'Blue Screen of Death' (BSOD). With average memory consumption sitting at 63% and 25% of the fleet recording unexpected shutdowns, these businesses are not just insecure—they are functionally unstable.

The 900-Day Window: Why 'Known' Vulnerabilities Persist

The most alarming discovery lies in the vulnerability intelligence gathered. Across just 11 computers, 206 open vulnerability findings were identified, representing 28 unique CVE identifiers. Most significantly, 17 of these CVEs appear on the CISA 'Known Exploited Vulnerabilities' (KEV) catalog. These are not theoretical risks; they are flaws actively used by threat actors in the wild.

The data highlights a staggering failure in patch management. The oldest unpatched flaw found was CVE-2020-0878 in Microsoft Edge. Despite being added to the CISA catalog on November 3, 2021, this vulnerability has remained open on monitored systems for over 900 days as of August 2024. This 'open door' policy for hackers is a common symptom in small businesses that lack dedicated IT departments, yet it provides attackers with a low-effort path to total system compromise.

Recent threats are also being ignored. The report identified CVE-2025-0411 in 7-Zip (CVSS score 7.0) with a 67.1% exploit probability, and CVE-2025-15556 in Notepad++ (CVSS score 7.5). Despite the high probability of exploitation, only one out of the 206 verified vulnerabilities in the sample had been patched, illustrating a dangerous gap in reactive security measures.

Operational Decay and the 'End-of-Life' Trap

Beyond external attacks, the internal health of these systems is failing. The XIT monitoring found that 17% of the computers have active antivirus threats that have not been neutralized, and 8% are operating with their firewalls completely disabled. Furthermore, 25% of the fleet is running on obsolete operating systems, such as Windows 10 or older versions that have reached 'End-of-Life' status. For these machines, no future security patches will ever be released, making them permanent liabilities.

The business implications are severe. While only 8% of the monitored computers were found to be completely healthy and alert-free, the remaining 92% face a cocktail of risks: data loss from unexpected shutdowns, identity theft via expired security certificates, and ransomware facilitated by disabled firewalls. For the global reader, this serves as a case study in 'security debt'—the mounting cost of ignoring routine maintenance until it results in a catastrophic breach.

To mitigate these risks, experts suggest that small businesses must move toward proactive monitoring. Regular vulnerability scans, strict update policies, and the retirement of legacy hardware are no longer optional luxuries. In an era where a 900-day-old bug can still take down a business, maintenance is not an IT expense—it is a core requirement for survival.