Patching Once a Month Is No Longer Enough, Rapid7 Warns

Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A calendar showing traditional monthly patch days with a rapidly growing pile of unpatched vulnerabilities cascading across subsequent weeks, visualized as an o
Share

Key points

  • Rapid7 warned in 2025 that the volume of newly discovered software vulnerabilities is outpacing the speed at which organisations can fix them.
  • AI tools are helping criminals find and exploit flaws more quickly, shortening the window between a flaw being discovered and it being attacked.
  • Rapid7 says defenders must shift focus from severity scores, which rank how dangerous a flaw looks on paper, to actual exposure, meaning whether the flaw is reachable in their specific environment.
  • Traditional patch cycles, where IT teams fix vulnerabilities on a monthly or quarterly schedule, can no longer keep organisations safe on their own.

What is going wrong with patching?

For years, the standard playbook was simple: wait for the monthly list of software flaws, rank them by how dangerous they looked, and fix the worst ones first. Rapid7 says that playbook is collapsing.

The number of CVEs, which stands for Common Vulnerabilities and Exposures, the official tracking IDs assigned to known software flaws, hit record levels in recent years. Fixing them all isn't realistic. Nobody has the staff or the time.

AI is making things worse on the attackers' side. Criminals now use AI tools to scan for weaknesses and write working attack code far faster than before. As we reported on 10 August, AI can surface thousands of flaws in days that years of human review had missed, and the gap between disclosure and active exploitation has shrunk to days, sometimes hours.

A monthly patch meeting can't close a gap that wide.

How should organisations respond?

Rapid7's answer is a shift in thinking. Instead of asking how dangerous a flaw looks, security teams should ask whether that flaw can actually be reached in their network right now.

A critical-sounding vulnerability on a server locked away from the internet is less urgent than a moderate-looking flaw sitting on a public-facing login page. Context beats the score.

This approach, called exposure management, requires teams to map what's actually connected and accessible before deciding what to fix first. It's harder than consulting a ranked list, and more honest about where the real risk sits.

What does this mean for ordinary people?

Most of us won't patch enterprise software ourselves. But hospitals, banks, online retailers and government agencies all rely on exactly the kind of IT teams this report is aimed at.

When those teams fall behind, criminals break in. Stolen customer records and fraudulent charges are the downstream result of patching failures at scale.

If an organisation you deal with sends a breach notification, change your password for that service, check your bank statements, and consider whether you've reused that password elsewhere. Reusing passwords remains one of the most reliable ways a single breach turns into five.

MFA, short for multi-factor authentication, meaning a second confirmation step beyond your password such as a code sent to your phone, won't fix a server patching delay. It will, however, limit how much damage criminals can do with any credentials they steal as a result.

Common questions

Does this mean my accounts are in immediate danger?

Not necessarily. This is a warning about organisational risk management, not evidence of a specific breach. The sensible response is to check that important accounts use a unique password and have multi-factor authentication turned on.

Can AI help defenders as well as attackers?

Yes. Security teams also use AI to scan their own systems for weaknesses, though Rapid7's point, first covered by SecurityWeek, is that the balance currently favours the attacking side.

© 2026 Threat Vectr