Cybersecurity at SMBtech

Check Point Research Finds Critical Vulnerabilities Have Doubled But Fewer Than One In 12 Demand Urgent Action

Surprisingly Useful AI Article Enhancements

Check Point Software Technologies has released its 2026 Exposure Gap Report, drawing on data from real customer environments across four industries to reveal that the proportion of critical vulnerability exposures more than doubled over the past year – even as fewer than one in 12 proved urgent enough to require immediate remediation.

The report, titled “Under Pressure: The 2026 Exposure Gap Report,” paints a picture of security teams struggling to keep pace with an expanding attack surface being probed at increasing speed by automation and AI-assisted tools. The central finding is that while the volume of vulnerability alerts has surged, the real challenge for organisations is no longer detection but determining which exposures can actually be exploited.

Vulnerabilities Surge As A Share Of Critical Exposures

According to the report, 42.6 per cent of all critical exposures identified in 2026 were vulnerabilities, more than double the 18.7 per cent recorded a year earlier. That makes vulnerabilities the single largest category of critical exposure across the customer environments analysed.

Yet after exploitability validation, only 7.8 per cent of vulnerability alerts warranted Critical or High attention. More than 90 per cent did not require the same immediate remediation focus, suggesting that the raw volume of alerts is creating noise that can obscure genuinely exploitable risks.

The report describes this mismatch as the “exposure gap” – the distance between visibility, prioritisation and safe remediation. As AI-assisted attack tools enable threat actors to test exposed systems, credentials, phishing infrastructure and known weaknesses across more organisations and at greater speed, traditional patch cycles and manual triage are struggling to match the pace.

Yochai Corem, VP and General Manager of Exposure Management at Check Point Software Technologies, pointed to the challenge facing security teams.

“The volume of alerts is no longer the problem – the signal is,” Corem commented. “When critical vulnerabilities double but fewer than one in twelve turn out to be urgent, the organisations that win are the ones that can find the genuinely exploitable risks fast and act on them before attackers do.”

Risk Concentrated Around Two Categories

The report found that 76 per cent of all critical exposures traced back to just two categories: vulnerabilities and internal information disclosure. This concentration of risk around exploitable weaknesses and exposed information assets was a recurring theme across the data.

Phishing websites also grew as a proportion of critical exposures, rising from 1.0 per cent in 2025 to 10.5 per cent in 2026, making it one of the fastest-growing exposure types in the dataset. Meanwhile, internal information disclosure declined from 56.8 per cent to 33.3 per cent as a share of critical exposures but remained the second-largest category overall.

Malicious file exposure fell from 18.3 per cent to 4.6 per cent, and compromised access tokens accounted for 1.8 per cent. The remaining categories collectively made up less than 10 per cent of critical exposures.

The overall picture, according to Check Point, is a shift from disclosure and malware-dominated exposure toward vulnerability and phishing-related risk.

Exposure Profiles Diverge Sharply By Sector

One of the report’s more notable findings is the degree to which exposure profiles vary by industry, with real implications for how different sectors should approach prioritisation.

Utilities recorded the highest concentration of vulnerability exposure, with vulnerabilities accounting for 78.2 per cent of critical exposures – nearly four out of every five. Government also showed a vulnerability-led profile at 56.4 per cent, a shift from 2025 when malicious files had been the dominant category at 39.9 per cent.

Healthcare presented a different picture entirely. Internal information disclosure accounted for 63.6 per cent of critical exposures in healthcare environments, followed by vulnerabilities at 17.6 per cent and malicious files at 10.5 per cent. The report attributes this to the prevalence of legacy medical devices, internet-connected clinical systems, sensitive patient data and numerous third-party providers in healthcare settings.

Financial services showed one of the more balanced exposure profiles, with internal information disclosure at 42.7 per cent, malicious files at 27.8 per cent, and compromised employee credentials and vulnerabilities each at approximately 9 per cent. The sector’s reliance on customer-facing applications, digital banking platforms and identity-based workflows helps explain the spread of risk across multiple attack paths.

Remediation Speed Varies Widely

The report also examined how quickly organisations are closing critical exposures once they are identified, finding significant variation across sectors.

Utilities posted the fastest median time to remediation at 12.6 hours, despite handling the second-highest remediation volume. Government followed at 25.4 hours, while financial services managed the largest workload with a median time of 48.5 hours.

Healthcare recorded the slowest median remediation time at 158.8 hours, reflecting the constraints of legacy systems, clinical uptime requirements and change control processes – even though the sector maintained a strong fix implementation rate of 85.5 per cent. The report suggests healthcare organisations are acting on recommended fixes but face operational complexity that slows the process.

Across the four industries analysed, organisations acted on an average of 85.9 per cent of recommended fixes. Financial services recorded the highest implementation rate at 91.7 per cent.

Sub-Hour Remediation Is Achievable

A notable data point in the report is the proportion of organisations resolving critical exposures within one hour. Utilities led at 30 per cent, followed by financial services at 23.1 per cent, government at 14.3 per cent and healthcare at 7.7 per cent.

Check Point argues this demonstrates that rapid remediation is not simply a function of lower workload. Utilities and financial services both handled high remediation volumes while still achieving sub-hour resolution rates, suggesting that mature exposure management programs with established validation, ownership and response workflows can move quickly even under pressure.

Corem described the speed challenge in broader terms.

“Attackers are now testing more exposures, across more organisations, at greater speed than security professionals can manually keep pace with,” he noted. “The organisations that stay ahead are the ones that can quickly separate the small set of genuinely exploitable risks from the noise, then remediate them safely without disrupting operations.”

The Narrowing Window For Defenders

The report includes data on the gap between mean time to exploit and mean time to remediate, drawing on Mandiant and GTIG research alongside Check Point’s own findings.

According to the analysis, mean time to exploit has dropped into negative territory in recent years, meaning attackers are now exploiting vulnerabilities before a patch even exists. Meanwhile, mean time to remediate has held relatively flat at more than 60 days. The two lines are no longer simply diverging – they are crossing in opposite directions.

The report characterises this as a situation where remediation benchmarks that were considered acceptable in previous years no longer match the pace of modern attack activity. Organisations that measure remediation in weeks may remain exposed longer than the attack window allows.

Financial Services Leads On Volume And Implementation

Financial services recorded the highest average monthly remediation volume per organisation at 10,155, followed by utilities at 2,979, government at 2,012 and healthcare at 1,546.

When viewed alongside median time to remediation, the data indicates that volume alone does not determine performance. Utilities achieved the fastest remediation despite the second-highest volume, while financial services combined the largest workload with the highest fix implementation rate.

The report argues that effective exposure management programs are those that can remediate at scale while reducing the time critical exposures remain open.

Defensive Controls Fill The Gap

Beyond direct remediation, the report examined the role of defensive controls in reducing risk while exposures are being investigated and fixed.

Across a subset of organisations analysed, indicator of compromise (IoC) feed enforcement blocked an average of 4.52 million attacks per organisation. IPS and WAF rules blocked an average of 2,032 attacks per organisation.

Check Point’s takedown team reported a success rate exceeding 99 per cent in 2026, with an average takedown time of 12 hours and 78 per cent of requests completed within that timeframe. Takedown targets included phishing websites, executive and brand impersonation campaigns, rogue applications and leaked sensitive data.

Beyond Vulnerability Severity

The report also highlights that not all high-severity exposures are software vulnerabilities. Across the non-vulnerability alert population analysed, 38.3 per cent were rated Critical or High severity. Information disclosure, phishing websites, malicious files, compromised credentials and access token exposure can all create material risk.

Check Point argues that exposure management cannot rely on vulnerability severity alone. Mature prioritisation needs to combine exploitability validation, exposure context, threat intelligence, control coverage and business impact assessment to identify which issues require action first.

The full report is available for download from Check Point’s exposure management website.

Last Updated on July 3, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.