Houston Area Patch Index
How Much Patching Work Software Vendors Are Creating for Your Business
Houston Area Patch Index: 38,446 vendor security advisories, 2022-01 through 2026-07. Published 2026-08-02. Updated 2026-08-02.
The Houston Area Patch Index measures how much patching work software vendors generate for the businesses that run their products. It tracks every published security advisory across the vendors in a typical business technology stack, how severe those flaws are, and how long it takes before attackers are confirmed to be exploiting them.
Advisory Volume Over Time
Monthly published advisories. Filter by vendor group to see where the surge is concentrated.
Vendor group
Chart view
Severity Mix by Year
Share of advisories by severity, excluding the Linux kernel. UNKNOWN means the record carried no vendor severity score.
| Severity | 2022 | 2023 | 2024 | 2025 | 2026 |
|---|---|---|---|---|---|
| Critical | 5.0% | 5.1% | 6.0% | 9.2% | 13.2% |
| High | 41.0% | 43.3% | 49.1% | 45.7% | 50.6% |
| Medium | 25.9% | 33.0% | 40.7% | 40.8% | 30.4% |
| Low | 2.3% | 2.9% | 4.2% | 4.3% | 3.6% |
| Unknown | 25.7% | 15.7% | 0.0% | 0.0% | 2.1% |
| Critical + high, of scored | 62.0% | 57.4% | 55.1% | 54.9% | 65.3% |
Advisory Count by Vendor, 2026
Advisories published so far in 2026, ranked. This is the volume each vendor is asking your team to absorb.
Build Your Stack
Select the vendors your business actually runs. The index calculates the patch load your team is absorbing.
Measurement period
Rated critical or high is a share of scored advisories only, so unscored records are excluded rather than counted as harmless. Confirmed exploited in the wild counts advisories listed in CISA's Known Exploited Vulnerabilities catalog.
Vendor Detail
Click any column heading to sort. KEV means confirmed exploited in the wild by CISA; the lag is the median number of days from publication to that confirmation.
Filter by group
| Vendor▲▼ | Group▲▼ | 2026▲▼ | 2025▲▼ | Change▲▼ | KEV▲▼ | Median Lag▲▼ |
|---|
Key Findings
The patch surge is real
and industry wide
Advisory volume in 2026 is running about 2.6 times the 2025 pace across every tracked vendor. This is not one vendor having a bad year.
Severity is climbing too
The critical-plus-high share sat flat for four years, then reached 65.3% in 2026, up from 54.9%. More patches, and more of them urgent.
AI-assisted discovery is the driver
Microsoft credits its own in-house AI scanner for its record volume. Google and an industry AI program report similar results. The tooling went operational in 2026 and the numbers moved with it.
Attacks arrive within weeks, not years
72% of flaws that get exploited are under confirmed attack within 30 days of the fix shipping. The window to apply a patch is far shorter than most maintenance cycles assume.
Silence is not safety
Some vendors publish no advisories at all. That usually means no public disclosure program rather than a flawless product. You cannot patch what a vendor never tells you about.
Patch What Gets Attacked First
You cannot patch everything the moment it ships. Nobody can. The question is which fixes go first, and how fast. The index answers both.
Severity tells you what could go wrong. Exploitation tells you what is going wrong.
Every advisory published in 2026, narrowed to the ones attackers are confirmed to be using.
The fixes that get attacked, get attacked fast
How long after a fix was published before CISA confirmed attackers were exploiting it. Based on 353 confirmed cases.
Time from fix published to confirmed attack
Whose flaws actually get attacked
Fastest growing volume, 2025 to 2026
What this means for a Houston business
- Shrink the patch window. The goal is not only patching everything faster. It is getting the exploited minority applied within days rather than months. Everything else can follow a normal maintenance rhythm.
- Rank by exploitation, then severity. The CISA Known Exploited Vulnerabilities catalog is free and public. Anything on it that touches your stack jumps the queue regardless of its severity score, because it is being used right now.
- Know what you run before the alert lands. You cannot prioritize what you have not inventoried. When a flaw lands on the exploited list, the question "do we run that?" has to be answerable in minutes, not days.
- Measure the delay, not the effort. The metric that predicts a breach is the average number of days between a fix being published and being installed. If nobody is tracking that number, nobody is managing the risk.
How CinchOps Can Help
Managed IT
Patch inventory, testing, deployment, and verification on a flat monthly rate per endpoint. No contracts, no hidden fees, no cancellation penalties.
Managed IT supportCybersecurity
Fixes prioritized against the CISA exploited-vulnerabilities catalog, so the flaws attackers are actually using jump the queue instead of waiting their turn.
Cybersecurity servicesBusiness Continuity
Geo-redundant backups outside the Gulf Coast flood zone, so a bad patch or a bad storm is a restore rather than a rebuild.
Business continuity and DRWhat This Index Does Not Measure
This index does not grade vendors. A high advisory count often reflects more transparency, not worse security. A vendor that publishes hundreds of fixes is telling you what it found, while a vendor publishing none may simply have no disclosure program at all. What the index measures is the workload landing on your IT team, not the quality of any vendor's engineering.
Methodology
- Purpose and intent
- To quantify the patching workload that software vendors generate for small and mid-sized businesses, and to track how that workload changes as AI-assisted vulnerability discovery becomes standard practice. Published as a service to the Houston business community.
- Coverage
- 18 vendors chosen for their presence in a typical business technology stack and for having enough published history to chart honestly. Vendors excluded for insufficient signal or scope: cloudflare, connectwise, crowdstrike, datto, okta, samsung mobile. Their exclusion is a data-quality decision, not a judgment about their security.
- Sources
- CVE records from the CVE.org cvelistV5 repository, Microsoft advisory counts from the MSRC security update API, and exploitation status from the CISA Known Exploited Vulnerabilities catalog. No surveys, no self-reporting, no vendor participation.
- What counts as an advisory
- One published CVE attributed to a vendor. Vendors are matched by CNA assigner. Microsoft is counted from MSRC monthly data rather than CVE records to reflect its Patch Tuesday releases accurately. One advisory does not always equal one patch: a single update can fix many CVEs, and one CVE can span several products.
- Severity
- Taken from the vendor's own CVSS score where published, with a fallback to enrichment data. Records with no score are reported as UNKNOWN rather than being imputed or dropped, because early records frequently lack scores. Any "critical or high" percentage on this page counts advisories scored 7.0 or above as a share of the advisories that carry a score at all; unscored records are left out of that denominator rather than assumed harmless.
- Confirmed exploitation
- An advisory is counted as exploited only if CISA has added it to the Known Exploited Vulnerabilities catalog, which requires evidence of real-world attacks. This is a deliberately conservative floor: it captures documented exploitation, not every flaw that has ever been attacked. The lag figures measure days from an advisory's publication to that CISA listing.
- Known limitations
- The Linux kernel became its own CVE authority in 2022, which sharply raised its counts for reasons unrelated to code quality; it is charted separately and excluded from cross-vendor severity totals. Industry-wide CVE volume also rose as more organizations began issuing CVEs. Advisory counts measure disclosure, not underlying security. The current month is partial.
- Refresh
- The index is rebuilt from source data monthly. Figures on this page were generated 2026-08-02.