Outdated Systems Leave 92% of Small Businesses Vulnerable to Cyberattacks
A new report reveals a alarming security gap in small businesses, with critical vulnerabilities remaining unpatched for years, exposing them to significant cyber risks.
A new monitoring report, based on anonymized data from the XIT system and released on 2026-09-28, paints a concerning picture of the digital resilience among small businesses in Israel. The findings, drawn from a sample of 12 endpoints across various organizations, indicate that 11 out of 12 computers (approximately 92%) exhibited at least one active alert related to security, performance, or maintenance issues. Most troublingly, critical security vulnerabilities, known to the intelligence community for years, remain unaddressed within these business systems, creating an open invitation for cyber attackers.
Years of Neglect: Vulnerabilities from 2020 Still Active
One of the most striking revelations in the data is the prolonged exposure to known vulnerabilities. The sample identified 231 open vulnerability findings across just 12 computers, encompassing 28 unique CVE identifiers. Of these, 17 vulnerabilities are listed in the CISA KEV (Known Exploited Vulnerabilities) catalog, a critical list maintained by the U.S. Cybersecurity and Infrastructure Security Agency that compiles security flaws proven to be actively exploited by hackers in the wild.
The oldest vulnerability still open in the sample is CVE-2020-0878 in Microsoft Edge. This vulnerability entered CISA’s exploited catalog in November 2021, over three years ago. This means a small business endpoint has remained vulnerable for over 1,200 days, despite a readily available security update. This timeframe is critical; as more time passes, automated attack tools become more accessible, making older vulnerabilities the easiest entry point for attackers to breach an organizational network without requiring advanced technical capabilities.
Alongside these long-standing vulnerabilities, the sample also highlights modern risks. CVE-2025-0411 in the popular 7-Zip software, with a CVSS severity score of 7.0 and a high exploitability probability of 67.1%, was found to be open on systems. Furthermore, 17% of the computers are running operating systems that are no longer supported (specific versions of Windows 10 and older), meaning they will never receive further security updates, effectively becoming a digital 'time bomb' at the heart of the business.
Poor Maintenance: A Broader Risk Factor
The data suggests a direct correlation between general maintenance levels and security posture. A significant 42% of computers were in an 'Updates Pending' state, and a similar proportion suffered from driver errors. A failure to perform reboots exacerbates the situation: the average uptime between reboots was 430 hours, with some computers not having been shut down or rebooted for over 720 hours (a full month). Failing to reboot prevents critical security updates from taking effect, even if they have been downloaded to the computer.
In terms of performance, the average RAM consumption stood at 65%, with 33% of computers experiencing high load and 17% exceeding the 85% threshold. High memory usage isn't just a performance issue; it causes system instability, evidenced by 17 system errors in the event log over the last 24 hours and two 'Blue Screen of Death' (BSOD) incidents recorded across the fleet in the past 30 days. An unstable computer is prone to crashing precisely when defense systems, such as antivirus or firewalls, need resources to block an attack.
Additionally, 25% of computers had specifically missing security updates, and 17% had antivirus software in a 'Stale' (outdated) state. In one instance, the firewall was found to be completely disabled, leaving the computer entirely exposed to external network scans.
The Business Impact: Why Old Vulnerabilities are the Most Dangerous
For a small business, the notion of 'I'm not a target' is a common misconception. Attackers use automated scanners that specifically look for documented vulnerabilities (like those listed in NVD and CISA KEV). When a vulnerability remains open for years, it becomes part of the standard 'toolkit' of every novice hacker. The business risk extends beyond data loss to complete operational disruption due to system crashes or ransomware attacks exploiting an unpatched flaw.
Professional context also highlights disk space management as another layer of security. In the sample, 8% of computers had nearly full disks (below 15% free space). Beyond causing sluggishness, a full disk prevents the operating system from downloading and installing new security updates, creating a vicious cycle of outdatedness.
Expert recommendations derived from this data emphasize adopting a strict 'Patch Management' policy, including weekly reboots of all endpoints and ensuring all third-party software (such as 7-Zip or Notepad++) is updated to its latest version. In a reality where only 8% of computers were found to be completely healthy without alerts, it appears the distance between a small business in Israel and a significant cyber incident is shorter than ever before. This situation is not unique to Israel; small businesses globally often lack dedicated IT security staff and resources, making them prime targets for opportunistic cyberattacks that leverage well-known, unpatched vulnerabilities.