CVEs With a CVSS Score Greater Than or Equal to 9 Lena Sinterhauf 1,2 , Andreas Aßmuth 2 , and Roland Kaltefleiter 1 1
arXiv:2604.20765v1 [cs.CR] 22 Apr 2026
NetUse AG, Kiel, Germany e-mail: {lsi | rk}@netuse.de 2 Kiel University of Applied Sciences, Kiel, Germany e-mail: [email protected] The present study investigates the speed and efficiency of identifying and remediating critical vulnerabilities, focusing on those with CVSS scores of 9.0 or above. It synthesises quantitative analyses of vulnerability data from global databases spanning 2009 to 2024 with qualitative case studies of major security incidents. The objective of this study is to identify the factors that contribute to delays in vulnerability response and to provide actionable recommendations for improving the resilience of IT infrastructures against critical security threats. This study provides a long-term analysis of critical vulnerabilities (CVSS ≥ 9.0) across 245,456 CVE records over a period of 16 years (2009 to 2024). Contrary to previous studies, this research combines large-scale quantitative analysis with qualitative case studies of major incidents (Heartbleed, EternalBlue, and Log4Shell) to identify systemic delays in vulnerability remediation and examines sector-specific patch patterns across more than 20 industries, thus providing practical insights for the prioritisation of vulnerability remediation in the context of limited security resources. The structure of this paper is as follows: Section II provides a comprehensive review of the extant literature on vulnerability I. I NTRODUCTION management and scoring systems. Section III delineates the The increasing digitisation and interconnectivity of organ- research methodology. The fourth section of this text presents isations and critical infrastructures has led to a growing threat the results of the data analyses and case studies. The subsequent landscape dominated by cyberattacks. Information security section, Section V, discusses the implications of these findings. constitutes a central component within contemporary corporate Finally, Section VI concludes with a summary and suggestions strategies, with the objective of preserving the integrity, for future research. availability, and confidentiality of data. The standardised II. R ELATED WORK identification and documentation of security vulnerabilities is facilitated by the Common Vulnerabilities and Exposures (CVE) Research on software vulnerabilities has addressed the system [1]. The assessment of vulnerabilities is conducted subjects of detection, severity assessment, and remediation. through the utilisation of the Common Vulnerability Scoring CVSS a widely utilised numerical classification system for System (CVSS), a method that employs a scale ranging from vulnerability criticality, which serves to guide the prioritisation 0 (lowest) to 10 (highest) to evaluate the severity of the of remediation efforts [2][8]. Service Level Agreements (SLAs) vulnerabilities identified [2]. Vulnerabilities that receive a score have been proposed as a means of defining remediation of 9.0 or higher are designated as critical, given the substantial timelines. It is recommended that critical vulnerabilities be risks they pose to the affected systems. addressed within days to weeks [9][10]. Empirical studies have analysed vulnerability lifecycles, Despite the implementation of established security processes, the timely detection and remediation of critical vulnerabilities management frameworks, open-source processes, and metrics, remain challenging. The failure to disclose vulnerabilities or such as mean time to remediate and disclosure-to-patch the failure to deploy patches in a timely manner can expose delays [11][12]. The extant literature consistently highlights organisations to significant risks of exploitation, resulting challenges in the timely remediation of issues, which are in financial losses, operational disruptions and reputational influenced by system complexity, organisational readiness, and damage [3][4]. Notable incidents, such as the Log4Shell resource constraints. vulnerability, have underscored the pressing need for effective Research focusing explicitly on critical vulnerabilities reand efficient vulnerability management [5]–[7]. ports that, despite improvements in disclosure speed, patch Abstract—Critical vulnerabilities with Common Vulnerability Scoring System scores of 9.0 or higher pose severe risks to organisations’ information systems. Timely detection and remediation are essential to minimise economic and reputational damage from cyberattacks. This paper provides a thorough analysis of the identification and resolution timelines of such critical vulnerabilities. A mixed-methods approach is employed, integrating quantitative data from global vulnerability databases analysing 245,456 Common Vulnerabilities and Exposures records spanning from 2009 to 2024, of which 12.8 % were critical, with qualitative case studies of notable incidents. This methodical combination of quantitative and qualitative data sources enables the identification of patterns and delay factors in vulnerability management. The findings indicate significant delays in public disclosure and patch deployment, influenced by industry-specific factors, resource availability and organisational processes. The paper concludes with a series of actionable recommendations to improve the efficiency of vulnerability responses. Despite faster disclosure, the remediation gap for critical vulnerabilities remains a systemic risk, driven by organisational inertia and system complexity. Keywords-critical vulnerabilities; vulnerability detection time; vulnerability management; patch management.
Please cite as: Lena Sinterhauf, Andreas Aßmuth, and Roland Kaltefleiter, “CVEs With a CVSS Score Greater Than or Equal to 9,” in Proc of the First International Conference on Cross-Domain Security in Distributed, Intelligent and Critical Systems (CROSS-SEC 2026), Lisbon, Portugal, pp. 17–23, April 2026.
TABLE I. R ELATED W ORK ON CVE/CVSS A NALYSIS (2009 TO 2025)
Year
Title
Author(s)
Topics
2019
S. Alexiou
2025
Practical patch management and mitigation Guide to enterprise patch management planning To patch or not to patch
2025 2025
The secret life of CVEs Out of sight, still at risk
P. Przymus et al. P. Przymus et al.
Patch SLAs, remediation timelines [10] MTTR metrics, enterprise patching [11] Patching motivations, organisational challenges [12] CVE lifecycle analysis [13] Transitive vulnerabilities, Maven ecosystem [14]
2022
M. Souppaya, K. Scarfone J.R.C. Nurse
deployment often lags behind, thereby extending exposure identify trends and patterns over time, and reveal discrepancies windows and exploitation risk [13][14]. Despite the existence across industry sectors and software categories. of regulatory and sector-specific guidelines that advocate for The qualitative element of the study comprises in-depth case faster responses, the efficacy of patching varies across sectors studies of notable security incidents, including the Heartbleed, and vendors. EternalBlue, and Log4Shell vulnerabilities [6][17][18]. The Key studies on vulnerability management and CVE lifecycles case studies presented offer insights into the challenges have been summarised in Table I. Whilst the extant literature encountered by organisations in the field of vulnerability provides insights into patching processes and vulnerability management, including issues, such as delays, organisational lifecycles, none offer a long-term (2009 to 2024) analysis factors, and best practices in mitigation. The integration of quantitative and qualitative data facilitates focused on critical vulnerabilities (CVSS ≥ 9.0) across sectors, combined with qualitative case studies of high-impact incidents. cross-validation and more profound interpretation of results. The present study addresses this gap by integrating large-scale Quantitative findings reveal statistical trends and potential delay quantitative data with detailed case analyses to uncover patterns, factors, while qualitative analysis contextualises these findings delays, and factors unique to the highest severity vulnerabilities. within actual incident scenarios and management practices. The process of data validation entailed several key steps. Firstly, database entries were subjected to rigorous crossIII. M ETHODS checking. Secondly, the results were meticulously compared The present study employs a mixed-methods approach with existing literature to ensure the reliability of the findings. in order to comprehensively analyse the identification and Finally, consistency was maintained throughout all analysis remediation processes of critical security vulnerabilities. The phases. This integrated approach facilitates the development methodology integrates quantitative analysis of vulnerability of pragmatic recommendations that are designed to enhance data with qualitative case studies to gain both breadth and the efficiency and effectiveness of critical vulnerability management. depth of understanding. The quantitative component employs data from recognised IV. R ESULTS vulnerability databases, namely the National Vulnerability The analysis encompasses vulnerability data from 2009 to Database (NVD) and the MITRE CVE database [15][16]. The 2024, with a particular emphasis on critical vulnerabilities data were obtained from the official NVD JSON 2.0 feeds (as that have a severity score of 9.0 or higher. The results of 28 May 2025) and MITRE CVE list downloads (as of 20 of the study reveal three primary dimensions of interest: May 2025). The datasets were processed using Python scripts (e.g., pandas, json) to filter vulnerabilities with CVSS base detection and publication timelines, patch availability delays, scores of ≥ 9.0, to calculate temporal metrics (e.g., days from and organisational or sectoral variation in response times. reservation_date to published and to lastModifiedDate as patch proxy), and to aggregate results by year, assignee (assigners), A. Detection and Publication Timelines and sector. The total number of registered vulnerabilities increased The analysis encompasses 245,456 CVE records registered substantially over the study period, particularly after 2016 between January 2009 and December 2024, of which 31,430 when the CVE assignment process was expanded through the (approx. 12.8 %) were classified as critical with CVSS base introduction of CVE Numbering Authorities (CNAs) [19][20], scores of 9.0 or higher. Two primary temporal dimensions as illustrated in Figure 1. were examined: the duration from CVE reservation to public In this context, “registrations” denote the initial allocation disclosure, and the duration from disclosure to patch availab- of a CVE ID by MITRE or designated CNAs upon internal ility (approximated using database modification timestamps). vulnerability reporting, prior to public disclosure [21][22]. Statistical analysis was conducted to examine these timelines, “Publications” refer to the subsequent public release of detailed
15, 000
All CVEs Critical CVEs
10, 000 5, 000
All CVEs Critical CVEs
400
200
0 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
20, 000
Average Days to Publication
Number of CVEs
vulnerability information in databases, such as MITRE and the NVD, making it visible to the global security community [21]– [23].
Year of Reservation 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
0
Year of Reservation Figure 1. Annual distribution of CVE registrations (2009–2024). Orange bars represent total no. of CVEs, while blue bars show no. of critical vulnerabilities.
Figure 3. Average time from CVE reservation to public disclosure (2009–2024). Orange bars represent all CVEs, while blue bars show critical vulnerabilities.
2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
Number of CVEs
numbers of vulnerabilities simultaneously, making it advisable to address critical issues first. Our investigations also revealed that the time between regisThis phenomenon resulted in a marked increase in the publication of vulnerabilities in 2017 and again during the tration and publication of a vulnerability varies considerably. period of the pandemic caused by the virus known as SARS- While in some cases, assigners published registered CVEs CoV-2 (2020–2021), when working remotely and accelerated on the same day (duration 0 days), in other cases it took up digitisation led to a greater number of exposed systems (cf. to several years. Of course, the reasons for these enormous differences in time are not apparent from the data available Figure 2). to us. In cases where the time span is very short, immediate publication is usually due to already known or simultaneously All CVEs published vulnerabilities that were subsequently assigned a Critical CVEs 15, 000 CVE ID. However, short time spans also indicate that some organisations appear to have particularly efficient processes 10, 000 in place, possibly automated disclosure procedures or internal Standard Operating Procedures (SOPs) that prioritise rapid 5, 000 publication. Long durations do not automatically mean that 0 poor work was done in these cases. Reasons for this can also include complex coordination processes, late discovery of the actual impact, or subsequent publication of confidential Year of Publication vulnerabilities [23][24]. Notably, none of the assigners have an average publication Figure 2. Annual distribution of CVE publications (2009–2024). Orange bars represent total no. of CVEs, while blue bars show no. of critical time of 0 days for critical CVEs. This indicates that critical vulnerabilities. vulnerabilities are always subjected to at least a brief review before they are made public. Furthermore, it can be observed The proportion of critical vulnerabilities remained relatively that the longest average delay for critical CVEs (approx. stable throughout the observation period at approximately 850 days) is significantly shorter than for all CVEs (over 12.8 % of all registered CVEs, with a peak of 2,589 cases 2,300 days). This suggests that critical vulnerabilities are recorded in 2020. As illustrated in Figure 3, the average generally processed and published more quickly, even when time from CVE reservation to public disclosure has decreased delays occur. At the same time, the data shows that the variance dramatically, from over 400 days in 2013 to approximately in duration for critical CVEs is lower, suggesting increased 33 days in 2024. process standardisation or prioritisation. Notably, while critical vulnerabilities were published significantly faster than the overall average in earlier years (e.g., 57 vs. B. Time to Patch Availability 105 days in 2009), this gap has virtually disappeared in recent years, indicating that systematic improvements in disclosure Patch deployment analysis demonstrates that turnaround processes now benefit all vulnerability severity levels equally. times are both longer and more variable than those observed This convergence represents a positive development in the in the publication phase. The mean time to release a patch for CVE ecosystem. Nevertheless, the CVSS remains essential general vulnerabilities was approximately 1,732 days (median: for severity classification and prioritisation, particularly when 1,335 days), whereas for critical vulnerabilities it was around organisations face resource constraints or must process large 2,024 days (median: 1,668 days).
6, 000
60 40 20 0
All CVEs Critical CVEs
0
1000 2000 3000 4000 5000 6000 Days to Patch Availability
Figure 4. Cumulative distribution of time to patch availability (2009–2024). The curves show the percentage of CVEs patched within a given timeframe. Mean values: approximately 1,732 days (all CVEs) and 2,024 days (critical CVEs).
All CVEs Critical CVEs
4, 000
2, 000
0
2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
80
Days to Patch Availability
Cumulative Percentage (%)
100
Year Figure 5. Patch availability for all CVEs and critical CVEs (2009–2024). The average, minimum and maximum durations are specified for each year. In the trend lines, the orange line indicates all CVEs, while the blue line indicates critical CVEs.
Figure 4 illustrates the cumulative distribution of time to patch availability across the entire observation period. Notably, were often commercial software vendors — exhibited median 50 % of all CVEs received patches within 1,335 days of delays of between 2,000 and 4,000 days (cf. Figure 6). disclosure, while 90 % were patched within 4,054 days. For Sectors were assigned by mapping CVE assigners to critical vulnerabilities, the corresponding values were 1,668 primary industry classifications using a reproducible, ruleand 4,689 days. The distribution demonstrates that despite based keyword matching on assigner names, with overlaps prioritisation efforts, critical vulnerabilities exhibit longer between sectors (e.g., Open Source, Commercial Software, remediation times on average than the general population, likely Web & Content Management) resolved through a predefined reflecting the increased complexity and coordination require- prioritisation order. While this heuristic facilitates large-scale ments associated with high-severity issues. The highly skewed mapping, multi-sector entities and evolving business models distribution, with substantial differences between median and may introduce classification uncertainties. mean values, indicates that while the majority of vulnerabilities are addressed within reasonable timeframes, a significant tail TABLE II. N UMBER OF ALL AND CRITICAL CVE S BY SECTOR . of delayed patches persists across both categories. Sector All CVEs Critical CVEs Despite the improvements that have been made, no consistent or significant difference has been demonstrated between critical Cloud & Hosting 3700 263 and non-critical issues with regard to patch completion times, Commercial Software 41583 4658 as can be seen in Figure 5. The apparent improvement in recent Consulting & Research 82386 15744 years should be interpreted with caution due to right-censoring: Consumer Electronics 55 9 vulnerabilities from 2022 onwards have had less opportunity Education & Non-Profit 33 4 to exhibit extended patch delays, and currently unpatched Finance & Insurance 66 2 vulnerabilities are not represented in these measurements. Hardware 13474 1276 Many organisations implement release cycles that are similar Healthcare 22 10 across all severity levels. The phenomenon of extended Industrial & IoT 2493 308 exposure periods can be attributed to various factors, including Open Source 28699 2751 the increasing complexity of systems, the presence of legacy Other 51873 4055 dependencies, constraints in resources, and the incomplete Platforms & DevOps 108 1 automation of processes. However, between 2020 and 2024, an Security Vendors 7249 848 observable acceleration occurred, suggesting stronger regulatory Telecommunication & Net13620 1476 and procedural pressure on vendors. working Web & Content Manage95 25 C. Organizational and Sectoral Variations ment There are notable disparities between different assignees (assigners). It is evident that certain entities, including specialised security platforms and prominent open-source providers, attained a median patch time of less than five days. This is indicative of sophisticated automation and continuous integration processes. In contrast, slower assigners – which
While sample sizes vary considerably across sectors (Table II), the median-based analysis remains robust for identifying general remediation patterns, with smaller sectors (e.g., Healthcare, n = 22) providing indicative trends rather than definitive benchmarks.
Median Days to Patch
4,000 All CVEs Critical CVEs
3,000
2,000
1,000
t H ar dw Se cu ar Te e rit le y co Ve m nd m or un O s ic pe at n io So ns ur & ce N et w or Cl ki ou ng d Co & ns H ul os tin tin g g & Co Re m se m ar er ch ci al So ftw ar e
-P ro fi
ic s &
N on
tro n
Ed u
ca
tio n
su m
er E
le c
l&
Io
T
ps str ia Co n
In du
fo rm s
&
D ev O
O th e
m
r
t Pl at
Co
W eb
&
ag e an
tM en nt
an Fi n
en
ce ra n In su
ce
&
H ea
lth ca
re
0
Sector Figure 6. Median time to patch availability by sector (2009 to 2024). Sectors are sorted by overall patch performance (all CVEs). Orange bars represent all CVEs, while blue bars show critical vulnerabilities, revealing significant performance disparities across industries.
A further indication of this is provided by a comparison of EternalBlue (CVE-2017-0144), which was exploited in the performance across different sectors, which shows that open- WannaCry ransomware of May 2017, targeted Windows SMBv1 source communities and cloud providers generally remediate protocol flaws, affecting unpatched Windows systems globally faster than traditional industries, such as commercial software and causing damages in excess of $4 billion [18]. Microsoft or hardware manufacturing. It is particularly evident in the released a patch in March 2017 (pre-disclosure), yet six months healthcare, energy, and telecommunications sectors that there is post-disclosure, 20 % of organisations remained vulnerable, a tendency for shorter patch cycles, which is likely attributable thereby amplifying the subsequent ransomware outbreak. The to the presence of more stringent legal and compliance incident demonstrates the protracted nature of remediation requirements [25][26]. processes in commercial software sectors, extending beyond the established quantitative averages. This emphasises the necessity for regulatory mandates to enforce patch SLAs in critical D. Case Study Insights infrastructures, such as healthcare and telecommunications. The quantitative findings are reinforced by qualitative case studies of three landmark critical vulnerabilities (CVSS ≥ 9.0), illustrating real-world manifestation of detection, disclosure, and remediation patterns observed across the 2009-2024 dataset. The Heartbleed vulnerability (CVE-2014-0160), which was discovered in OpenSSL in April 2014, enabled attackers to read up to 64 KB of server memory, with the potential to expose private keys, passwords and session data for millions of systems worldwide [17]. Despite the rapid provision of patches within two days, the delays between disclosure and remediation in the affected companies averaged more than six months. This was due to widespread dependency on the open-source library and lack of automated detection tools. This case study highlights the challenges associated with the “last mile” of patch deployment, emphasising the necessity for dependency scanning and automated updating within opensource ecosystems to mitigate prolonged exposure windows, which align with the quantitative medians (1,668 days for critical CVEs).
The Log4Shell vulnerability (CVE-2021-44228), which was disclosed in December 2021 in Apache Log4j, enabled remote code execution via malicious logging inputs. This had a significant impact on more than 3 billion devices and triggered immediate zero-day exploits [5]–[7]. Patches were issued within days; however, full remediation took weeks due to supply-chain propagation and configuration complexity, with global adoption lagging as documented in BSI warnings [6]. This finding underscores the existence of persistent organisational delays, thereby signifying the necessity for continuous vulnerability management as opposed to periodic scans, as evidenced by the study’s comprehensive patterns. The collective analysis of these cases serves to reinforce the quantitative patterns identified, thereby illustrating how technical complexity, organisational inertia, and sectoral variations collectively drive the remediation gaps.
V. D ISCUSSION A ND E VALUATION The results of this study highlight both significant progress and persistent structural challenges in the management of critical software vulnerabilities. Over the period under scrutiny, the time lag between CVE reservation and public disclosure decreased significantly, reaching an average of approximately 33 days in 2024. This phenomenon points to an enhancement in the coordination and responsiveness of the global vulnerability management ecosystem. The expansion of the CNA programme and enhanced collaboration between security researchers, vendors, and vulnerability databases have likely contributed to this acceleration [19][27].The acceleration of disclosure processes has been demonstrated to increase transparency and enable organisations to initiate defensive measures earlier. Despite these improvements, the findings demonstrate that faster disclosure does not necessarily lead to faster remediation. The analysis indicates that remediation timelines persistently exceed expectations and demonstrate considerable variability, with a median duration of 1,668 days for critical vulnerabilities. This discrepancy underscores a systemic "last-mile" problem in vulnerability management, where the primary bottleneck shifts from vulnerability discovery to the development and deployment of patches [10]. The existence of this discrepancy can be attributed to a number of factors. In the contemporary context, software systems frequently employ complex dependency chains and interconnected components, a factor that has been shown to complicate the processes of patch development and testing. Moreover, organisational constraints, such as limited resources, operational risks associated with updates, and fragmented asset inventories, have the potential to delay patch deployment, particularly in large or legacy environments. Sectoral comparisons provide further support for these observations. It is evident that open-source ecosystems and cloud-based platforms frequently demonstrate a higher level of responsiveness, largely attributable to the utilisation of automated development pipelines and continuous integration practices. Conversely, traditional commercial vendors characteristically implement more extended release cycles. It has been demonstrated that regulated sectors, including but not limited to healthcare and telecommunications, exhibit accelerated remediation, a phenomenon that is presumably precipitated by regulatory incentives. Case studies, including those of Heartbleed, EternalBlue and Log4Shell, illustrate that even when patches are released promptly, organisations frequently require a considerable amount of time to identify affected systems and deploy updates across complex infrastructures. The findings emphasise that effective vulnerability mitigation is contingent not only on vendor response, but also on organisational preparedness and the implementation of mature patch management processes. The findings indicate an enhancement in vulnerability management with regard to transparency and disclosure efficiency. Nevertheless, the extended remediation timelines underscore
a persistent "last-mile" issue in the implementation of patch deployment. In order to address this challenge, it is necessary to implement not only faster vulnerability reporting but also improved automation, better asset visibility, and more mature patch management processes within organisations. VI. C ONCLUSION AND F UTURE W ORK The present study examined the processes of detection, disclosure, and remediation of critical vulnerabilities that had severity scores of nine or higher. Integration of data-driven analysis and qualitative case evaluations enabled identification of both structural improvements and persistent challenges in contemporary vulnerability management. The findings indicate that global disclosure timelines have become considerably reduced, signifying a maturation of the ecosystem of coordinated vulnerability reporting and enhanced cross-organisational communication [24][27]. Nevertheless, the remediation phase continues to demonstrate deficiencies, with notable heterogeneity in patch release times across software vendors and sectors. These delays, frequently attributable to resource constraints, legacy dependencies, and fragmented responsibilities, result in organisations remaining vulnerable for extended periods following the disclosure of vulnerabilities [10]. This work contributes to extant research by quantifying the systemic inefficiencies that persist despite procedural advances. It is also important to note that effective vulnerability management is not just a technical problem, but also a governance challenge [25]. In order to address this challenge, there is a need for synchronised policy, automation and human expertise. Organisations that actively integrate regulatory frameworks, establish prioritised workflows and mandate security accountability are better positioned to reduce the window between discovery and mitigation. From an applied perspective, this study underscores the necessity for organisations to accord priority to critical vulnerabilities (CVSS ≥ 9.0) through the implementation of established SLAs (cf. Section II) and sector-specific strategies (Subsection IV-C), while concomitantly addressing systemic remediation delays that have been identified across the period 2009 to 2024 (see Figures 4, 5, 6), particularly in commercial software sectors that require a longer timeframe to remediate (cf. Figure 6). In future research, the exploration of machine learning–driven models, such as exploit prediction scoring systems, in the refinement of prioritisation in dynamic threat environments is recommended. Further investigation into the following areas would be of use in attempting to bridge the gap between awareness and action: automated remediation pipelines; CI/CD-integrated patching; and multi-source vulnerability aggregation [28]. Furthermore, emerging paradigms, such as exposure management and zero-trust architectures offer promising frameworks for the unification of vulnerability management across hybrid infrastructures. The study indicates that, while the speed of identifying and publishing critical vulnerabilities is improving, sustainable cybersecurity resilience depends on transitioning from reactive
vulnerability management to proactive, continuous exposure governance. ACKNOWLEDGEMENT The present paper is founded upon Lena’s Master Thesis, which was conducted at the Faculty of Computer Science and Electrical Engineering, Kiel University of Applied Sciences.
[12]
[13] [14]
R EFERENCES [1] [2] [3]
[4]
[5] [6]
[7]
[8]
[9]
[10]
[11]
MITRE Corporation, “Frequently asked questions (faqs) - what is cve?”, Accessed: 2026-03-14. [Online]. Available: https : //www.cve.org/ResourcesSupport/FAQs National Institute of Standards and Technology (NIST), “Vulnerability metrics”, Accessed: 2026-03-14. [Online]. Available: https://nvd.nist.gov/vuln-metrics/cvss# Ponemon Institute, “Cost of a data breach report 2024”, 2024, Accessed: 2026-03-14. [Online]. Available: https://table.media/ wp - content / uploads / 2024 / 07 / 30132828 / Cost - of - a - Data Breach-Report-2024.pdf Bundesamt für Sicherheit in der Informationstechnik, “The state of it security in germany in 2023 (original title in german: Die Lage der IT-Sicherheit in Deutschland 2023)”, 2023, Accessed: 2026-03-14. [Online]. Available: https://www.bsi.bund.de/ SharedDocs/Downloads/DE/BSI/Publikationen/Lageberichte/ Lagebericht2023.pdf National Institute of Standards and Technology (NIST), “CVE2021-44228 detail”, Accessed: 2026-03-14. [Online]. Available: https://nvd.nist.gov/vuln/detail/CVE-2021-44228 Bundesamt für Sicherheit in der Informationstechnik, “Critical vulnerability published in log4j (cve-2021-44228) (original title in german: Kritische Schwachstelle in log4j veröffentlicht (CVE-2021-44228))”, Accessed: 2026-03-14. [Online]. Available: https : / / www . bsi . bund . de / SharedDocs / Cybersicherheitswarnungen / DE / 2021 / 2021 - 549032 - 10F2 . pdf?__blob=publicationFile&v=5 CrowdStrike Intelligence Team, “Log4j2 vulnerability "log4shell" (CVE-2021-44228)”, 2021, Accessed: 2026-03-14. [Online]. Available: https : / / www . crowdstrike . com / en us / blog / log4j2 - vulnerability - analysis - and - mitigation recommendations/ Forum of Incident Response and Security Teams (FIRST), “Common vulnerability scoring system v4.0 – user guide”, Accessed: 2026-03-14. [Online]. Available: https://www.first. org/cvss/v4.0/user-guide Bundesamt für Sicherheit in der Informationstechnik (BSI), “OPS.1.1.3: Patch and change management (original title in german: OPS.1.1.3: Patch- und Änderungsmanagement)”, 2021, Accessed: 2026-03-14. [Online]. Available: https://www.bsi. bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/IT-GSKompendium_Einzel_PDFs_2021/04_OPS_Betrieb/OPS_1_ 1_3_Patch_und_Aenderungsmanagement_Edition_2021.pdf? __blob=publicationFile&v=2 S. Alexiou, “Practical patch management and mitigation”, ISACA Journal, vol. 2019, no. 3, pp. 1–6, 2019. Accessed: 2026-03-14. [Online]. Available: https : / / www . isaca . org / resources / isaca - journal / issues / 2019 / volume - 3 / practical patch-management-and-mitigation M. Souppaya and K. Scarfone, “Guide to enterprise patch management planning: Preventive maintenance for technology”, National Institute of Standards and Technology (NIST), Tech. Rep. NIST SP 800-40 Rev. 4, 2022. Accessed: 2026-0314. [Online]. Available: https : / / nvlpubs . nist . gov / nistpubs / SpecialPublications/NIST.SP.800-40r4.pdf4
[15] [16] [17] [18] [19] [20] [21] [22] [23] [24]
[25]
[26]
[27]
[28]
J. R. C. Nurse, “To patch or not to patch: Motivations, challenges, and implications for cybersecurity”, 2025, Accessed: 2026-03-14. [Online]. Available: https://arxiv.org/pdf/2502. 17703 P. Przymus, M. Fejzer, J. Nar˛ebsk and K. Stencel, “The secret life of cves”, arXiv preprint, 2025. Accessed: 2026-03-14. [Online]. Available: https://arxiv.org/pdf/2504.03863 P. Przymus, M. Fejzer, J. Nar˛ebsk, K. Rykaczewski and K. Stencel, “Out of sight, still at risk: The lifecycle of transitive vulnerabilities in maven”, arXiv preprint, 2025. Accessed: 202603-14. [Online]. Available: https://arxiv.org/pdf/2504.04803 National Institute of Standards and Technology (NIST), “NVD data feeds - JSON 2.0 feeds”, 28th May 2025, Accessed: 202603-14. [Online]. Available: https://nvd.nist.gov/vuln/data-feeds MITRE Corporation, “CVE list downloads”, 20th May 2025, Accessed: 2026-03-14. [Online]. Available: https://www.cve. org/Downloads National Institute of Standards and Technology (NIST), “CVE2014-0160 detail”, 2014, Accessed: 2026-03-14. [Online]. Available: https://nvd.nist.gov/vuln/detail/CVE-2014-0160 National Institute of Standards and Technology (NIST), “CVE2017-0144 detail”, 2017, Accessed: 2026-03-14. [Online]. Available: https://nvd.nist.gov/vuln/detail/CVE-2017-0144 MITRE Corporation, “CVE numbering authority (cna) operational rules”, Accessed: 2026-03-14. [Online]. Available: https: //www.cve.org/ResourcesSupport/AllResources/CNARules MITRE Corporation, “List of partners”, https://www.cve.org/ PartnerInformation/ListofPartners, Accessed: 2026-03-14. MITRE Corporation, “Glossary - cve record”, https://www. cve.org/ResourcesSupport/Glossary#glossaryRecord, Accessed: 2026-03-14. MITRE Corporation, “Process”, https://www.cve.org/About/ Process, Accessed: 2026-03-14. National Institute of Standards and Technology (NIST), “CVEs and the NVD process”, 2024, Accessed: 2026-03-14. [Online]. Available: https://nvd.nist.gov/general/cve-process Bundesamt für Sicherheit in der Informationstechnik (BSI), “Bsi guideline on the coordinated vulnerability disclosure (cvd) process (original title in german: Leitlinie des BSI zum Coordinated Vulnerability Disclosure (CVD)-Prozess)”, 2022, Accessed: 2026-03-14. [Online]. Available: https://www.bsi. bund.de/SharedDocs/Downloads/DE/BSI/CVD/CVD-Leitlinie. pdf?__blob=publicationFile&v=4 Bundesamt für Sicherheit in der Informationstechnik (BSI), “Study on the effectiveness of it security laws among operators of critical infrastructures (original title in german: Untersuchung zur Wirksamkeit der IT-Sicherheitsgesetze unter Betreibern Kritischer Infrastrukturen)”, 2023, Accessed: 2026-03-14. [Online]. Available: https://www.bsi.bund.de/SharedDocs/Downloads/ DE/BSI/KRITIS/evaluierung- itsig2- ergebnisbericht.pdf?__ blob=publicationFile&v=3 World Economic Forum, “Global cybersecurity outlook 2022”, 2025, Accessed: 2026-03-14. [Online]. Available: https://reports. weforum . org / docs / WEF _ Global _ Cybersecurity _ Outlook _ 2025.pdf MITRE Corporation, “CVE® 25 years - 25th anniversary report october 2024”, https://www.cve.org/Resources/Media/ Cve25YearsAnniversaryReport.pdf, 2024, Accessed: 2026-0314. Forum of Incident Response and Security Teams (FIRST), “Exploit prediction scoring system (epss) - frequently asked questions”, Accessed: 2026-03-14. [Online]. Available: https: //www.first.org/epss/faq