The Open Door: 92% of Small Business PCs in Israel Harbor Active Security Exploits
New monitoring data reveals a critical maintenance gap as small businesses leave systems unpatched against vulnerabilities already being used by cybercriminals.
A new report based on anonymous monitoring data from the XIT system has revealed a stark reality for the small and medium enterprise (SME) sector in Israel. According to the sample of active endpoints, a staggering 92% of computers—12 out of 13 devices—have at least one active alert indicating a functional failure or a critical security risk. While the sample size is focused, it serves as a canary in the coal mine for a global problem: the dangerous lag between the discovery of a security flaw and the application of a patch.
The most alarming finding is the presence of 21 security vulnerabilities (CVEs) that appear on the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog. Unlike theoretical risks, these are flaws that cybercrime organizations have already weaponized. For an international audience, this highlights a systemic issue where small businesses, often lacking dedicated IT departments, become the weakest link in global supply chains by failing to address threats that are already being actively exploited in the wild.
From Theoretical Flaws to Active Weapons
In the world of cybersecurity, there is a critical distinction between a vulnerability and an exploit. While the National Vulnerability Database (NVD) contains thousands of entries, the KEV catalog focuses on those currently used as tools for intrusion. The XIT data identified 266 open vulnerability findings across just 13 computers, comprising 32 unique CVE codes. Of these, 21 are already being utilized by attackers.
Specific examples highlight the severity of the neglect. The sample found WinRAR (version 5.91) installations containing CVE-2025-8088, which carries a CVSS severity score of 8.8 and a massive 94.6% exploitation probability. Another flaw in the same software, CVE-2025-6218, shows a 90.5% probability of exploitation. Perhaps most telling is the persistence of CVE-2020-0878 in Microsoft Edge—a vulnerability dating back to 2021 that remains unpatched on these systems. This suggests that for many Israeli small businesses, patch management is not just delayed; it is non-existent.
System Instability and the Productivity Tax
Beyond the threat of a data breach, the data indicates that poor maintenance is actively strangling productivity. 69% of the computers (9 out of 13) are currently waiting for system updates, with 24 pending updates recorded in total. This lack of upkeep manifests in physical system failures: over a 30-day period, the fleet recorded 11 "Blue Screen of Death" (BSOD) events, and 70 system errors were documented in the last 24 hours alone.
The instability is compounded by hardware strain. 38% of the computers suffer from driver errors, and 31% have experienced unexpected shutdowns. With an average RAM consumption of 62% and 23% of machines under constant memory stress, these businesses are operating on the edge of failure. Furthermore, 15% of the computers have less than 15% free disk space. A full disk is more than a storage issue; it prevents the system from writing essential files and often blocks the installation of the very security patches needed to protect the business.
The End-of-Life Trap
The report also identifies a looming "ticking time bomb" for business continuity: the use of obsolete software. Two computers in the sample are running versions of Windows 10 or older that have reached End of Life (EOL) status. These systems no longer receive security updates from Microsoft, meaning any new vulnerability discovered will remain open forever.
With 8% of systems running with firewalls disabled and 23% facing active antivirus threats, the situation in the Israeli SME sector reflects a broader global challenge. Small businesses often prioritize immediate operational needs over digital hygiene, but as the XIT data shows, this creates a environment where a single unpatched PC can lead to ransomware, data theft, or total operational collapse. The recommendation is clear: businesses must move away from "firefighting" and prioritize the closure of KEV-listed vulnerabilities and the upgrading of legacy systems to ensure survival in an increasingly hostile digital landscape.