Enterprise attack surfaces continue to expand rapidly, with more than 20,000 new vulnerabilities disclosed in the first half of 2025, putting a strain on already-strained security teams in managing vulnerabilities. Nearly 35% of these vulnerabilities have publicly available exploit code, according to the Global Threat Intelligence Index study by threat intelligence firm Flashpoint.
See also: Security Testing: Why BAS is a proof of defense

The volume of disclosed vulnerabilities has more than tripled, while the amount of exploit code has more than doubled since the end of February 2025 alone. These increases now make it unfeasible for most organizations to assess, patch, or mitigate every vulnerability, Flashpoint argues, suggesting that businesses should implement a risk-based remediation framework.
But some experts argue that a full-fledged functional overhaul of vulnerability management practices is needed to manage vulnerabilities. Josh Lefkowitz, CEO of Flashpoint, says that the increases in disclosed vulnerabilities and publicly available exploit code reflect a shift in the threat landscape. The widening gap between exposure and response makes it impractical for security teams to rely on traditional approaches. The countermeasure is not “fix everything faster,” but “fix smarter” by leveraging security intelligence, according to Lefkowitz.
See also: Cyberattack disrupts flights at European airports

Businesses must evolve beyond reactive patch cycles and embrace risk-based, intelligence-driven vulnerability remediation. External security experts agree that businesses must implement a risk-based remediation framework.
Hüseyin Can Yüceel, head of security research at security validation firm Picus Security, says that while the increasing volume of disclosed vulnerabilities may be discouraging, only a few will impact any particular business.
Security teams that rely heavily on public vulnerability intelligence sources, such as Common Vulnerabilities and Exposures (CVE) and the National Vulnerability Database (NVD), are at a serious disadvantage, Flashpoint warns. The average delay between the publication of a CVE and the enrichment of the NVD now stretches into weeks and months — creating critical intelligence gaps. The instability in CVE program funding earlier this year creates additional doubts.
See also: Cyberattacks on Critical Infrastructure: A Threat to National Security

Frameworks like Gartner's CTEM provide security operations center teams with a roadmap for how to mature their processes to prioritize reports based on exploitability and business impact — not just raw severity scores.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
