Vicarius’ “Exposed and Unfixed: The 2026 State of Vulnerability Remediation” Finds Siloed Workflows and Manual Processes Leave 79% of Organizations Vulnerable to Known Exploits
58% of all vulnerability remediation activities still require direct human intervention
75% of critical vulnerability responses simply initiate an administrative workflow rather than resolving the threat
NEW YORK, July 15, 2026 (GLOBE NEWSWIRE) -- Vicarius, a vulnerability remediation company, today released its Exposed and Unfixed: The 2026 State of Vulnerability Remediation report, a comprehensive study analyzing operational metrics from IT and security leaders across the U.S. and U.K. to reveal how organizations manage and struggle to resolve security flaws after they are detected.
Despite industry emphasis on automated scanning, the actual process of fixing vulnerabilities remains trapped behind manual workflows and fragmented toolsets. Drawing from real-world insights from enterprise IT and security executives, the report breaks down why critical flaws sit exposed for months, where organizational handoffs break down, and why traditional ticketing systems are creating a false sense of security.
Key findings:
"Treating a ticket creation as a security victory is a fundamental operational flaw," said Roi Cohen, CEO of Vicarius. "Our latest report shows that while finding flaws has become automated, fixing them is still held back by human intervention, organizational silos, and tool sprawl. When three out of four critical vulnerability responses result in an administrative handoff rather than immediate mitigation, we shouldn't be surprised that attackers operating at machine speed win the race."
How to Protect Your Organization
The gaps uncovered in this report show that traditional vulnerability management is broken. To stop the endless cycle of manual handoffs and unaddressed risks, organizations must shift from passive scanning to active, automated resolution.
Redefine "remediated" before you report another metric.
Name an owner before you add another approval step.
Count your tools before buying another one.
Methodology
The 2026 State of Vulnerability Remediation report was conducted in April 2026 in partnership with Global Surveyz, an independent market research firm. The study gathered insights from 300 IT and cybersecurity professionals across the United States and the United Kingdom. The respondent pool was evenly distributed among managers, directors, and vice presidents. All participants represent organizations with between 500 and 2,000 employees spanning key industry sectors, including financial services, manufacturing, healthcare, automotive, government, and technology services.
Download Vicarius’ Exposed and Unfixed: The 2026 State of Vulnerability Remediation report, or learn more about vRx for native remediation at scale and vIntelligence for continuous orchestration.
About Vicarius
Vicarius’ mission is to revolutionize vulnerability management by closing the loop between problem detection and proactive resolution. The company’s portfolio is built on two flagship pillars: vRx for advanced, native remediation at scale, and vIntelligence, an agentic validation engine that delivers continuous AI-driven security insight and orchestration.
Now with vRx and vIntelligence, Vicarius offers a full remediation cycle. With 1,000+ customers in 80 countries, vRx by Vicarius streamlines and automates risk mitigation for security teams, SMBs, and Fortune 500 enterprises.
Media contact
Deb Montner
dmontner@montner.com