A new report from California-based Skybox Security says that since there have been 9,799 unique vulnerabilities so far in the first half of 2020 alone, by the end of the year we will have reached the record of 20,000 vulnerabilities.
The first half of software security vulnerability reports saw a 34% increase from 7,318 last year. This is undoubtedly good news, reflecting the increased effort being put into vulnerability research.

Of the five new products on the list above, three are enterprise applications (IBM API Connect, Red Hat OpenShift, Oracle E-Business Suite). The other two – Edge Chromium and iPad OS – are typically deployed in workstations, home and commercial environments, emerging from “non-existent” to become what Skybox describes as “patch-seeking vulnerabilities” that require administrator attention .
Critical vulnerabilities make up 15% of all new reports, Skybox notes.
And while critical bugs – such as those that received the maximum score of 10.0 on the CVSS (a way of assessing the characteristics and severity of software vulnerabilities) – receive a lot of attention, they end up being dangerous as they are approached generically, the security firm notes.

“Although organizations tend to prioritize remediation of critical vulnerabilities … this general approach to prioritization could allow attackers to take advantage of any exposed medium-severity vulnerabilities.”
“Criminals know that medium severity flaws can remain unpatched in an organization’s systems for a long time , and depending on where these flaws, they could give an attacker access to a critical point in the system or allow them lateral movement.”
Security programs should have established processes to “update vulnerabilities based on exposure, exploitability, and other factors to keep remediation focused on critical risks,” Skybox says. It goes on to say, “If a security program bases vulnerability prioritization solely on CVSS, it could waste resources patching a vulnerable element protected by layers of defense and not update a medium severity vulnerability.”
