← כל הכתבות דוח נתונים

The Patch Gap: 92% of Small Business Computers Exposed to Known Cyber Vulnerabilities

New monitoring data reveals a dangerous backlog of uninstalled security updates and system instability among small enterprises, leaving them vulnerable to years-old exploits.

מאת אושרי פנחס · 10/09/2026

In the global fight against cybercrime, small and medium-sized enterprises (SMEs) are often described as the 'soft underbelly' of the digital economy. New data released on September 10, 2026, by the XIT monitoring system provides a stark illustration of this reality. A study focused on small businesses in Israel—a nation often considered a high-tech hub—reveals that even in technologically advanced environments, basic digital hygiene is frequently neglected.

The findings are alarming: out of a sample of 13 endpoints, 12 (approximately 92%) had at least one active alert indicating a failure in maintenance or information security. This isn't just a local concern; as supply chains become more integrated, a single unpatched computer in a small Israeli firm can serve as a gateway for attackers to reach international partners.

A Wide-Open Window for Cyberattacks

The primary threat identified is a massive backlog of 24 pending software and operating system updates. According to the report, 69% of the monitored computers (9 out of 13) have pending updates, with 23% of those being classified as critical security patches that have yet to be implemented.

By cross-referencing this data with global databases such as CISA’s Known Exploited Vulnerabilities (KEV) catalog, the EPSS, and the NVD, the study identified 266 open vulnerability findings consisting of 32 unique CVE identifiers. Most concerning is the presence of vulnerabilities already being exploited in the wild. For instance, outdated versions of WinRAR (version 5.91) were found to be exposed to CVE-2025-8088, which carries a severe CVSS score of 8.8 and an incredibly high exploitation probability of 94.6%.

This flaw, alongside CVE-2025-6218, allows attackers to execute code remotely. Perhaps most shocking is the discovery of an unpatched Microsoft Edge vulnerability (CVE-2020-0878) that was documented back in 2021. This suggests that some businesses have allowed critical security gaps to persist for over five years without remediation.

System Instability and the Cost of Neglect

Beyond the immediate risk of a data breach, the XIT data points to a significant impact on business continuity due to poor maintenance. In the last 30 days alone, the monitored fleet recorded 11 "Blue Screen of Death" (BSOD) events. Furthermore, 38% of the computers suffer from driver errors, and 31% have experienced unexpected shutdowns. In a single 24-hour window, the systems logged 70 separate errors in their Event Logs.

Hardware performance is also reaching a breaking point. While average CPU usage sits at a healthy 20%, average RAM consumption is a staggering 62%. In 23% of the machines, memory load was critically high, with one computer exceeding 85%—a state that leads to severe slowdowns and application crashes. Additionally, 15% of the computers are running with less than 15% free disk space, a threshold that prevents operating systems from performing essential write operations and automatic updates.

The 'End of Life' Trap

The study also highlights the danger of 'End of Life' (EOL) software. Two of the 13 computers are running versions of Windows 10 that are no longer supported, or even older operating systems. For a small business, these machines are a permanent liability; they will never receive another security patch, even if a major ransomware exploit is discovered. They act as a permanent "weak link" in the corporate network.

While the average uptime between reboots was 175 hours—and no computer went more than a month (720 hours) without a restart—the delay in rebooting often prevents the finalization of critical security patches. This failure to patch is no longer just a technical oversight; it is a legal and insurance risk. In the event of a cyber incident, insurance providers increasingly scrutinize whether a business maintained reasonable standards, such as proactive patch management.

For small businesses, where every hour of downtime is costly, the transition from "break-fix" maintenance to proactive monitoring is no longer optional. As this data shows, the gap between a functioning system and a total security collapse is narrower than many business owners realize.