Patching Once a Month Is No Longer Enough, Rapid7 Warns

Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a rack-mounted network security appliance in a dimly lit server room, blue and amber status LEDs glowing, ethernet cable
Share

Key points

  • Rapid7 warned in 2025 that the volume of newly discovered software vulnerabilities is outpacing the speed at which organisations can fix them.
  • AI tools are helping criminals find and exploit flaws more quickly, shortening the window between a flaw being discovered and it being attacked.
  • Rapid7 says defenders must shift focus from severity scores, which rank how dangerous a flaw looks on paper, to actual exposure, meaning whether the flaw is reachable in their specific environment.
  • Traditional patch cycles, where IT teams fix vulnerabilities on a monthly or quarterly schedule, can no longer keep organisations safe on their own.

What is going wrong with patching?

For years, the standard playbook was simple: wait for the monthly list of software flaws, rank them by how dangerous they looked, and fix the worst ones first. Rapid7 says that playbook is collapsing.

The number of CVEs, which stands for Common Vulnerabilities and Exposures, the official tracking IDs assigned to known software flaws, hit record levels in recent years. Fixing them all is not realistic. Nobody has the staff or the time.

AI is making things worse on the attackers' side. Criminals now use AI tools to scan for weaknesses and write working attack code far faster than before. The gap between a flaw being publicly listed and criminals actively exploiting it has shrunk to days, sometimes hours.

A monthly patch meeting cannot close a gap that wide.

How should organisations respond?

Rapid7's answer is a shift in thinking. Instead of asking "how dangerous does this flaw look?", security teams should ask "can this flaw actually be reached in our network right now?"

A critical-sounding vulnerability on a server that is locked away from the internet is less urgent than a moderate-looking flaw sitting on a public-facing login page. Context beats the score.

This approach, called exposure management, requires teams to map out what is actually connected and accessible before deciding what to fix first. It is harder than consulting a ranked list. It is also more honest about where the real risk sits.

What does this mean for ordinary people?

Most of us will not patch enterprise software ourselves. But the organisations that hold our data, hospitals, banks, online retailers, government agencies, rely on exactly the kind of IT teams this report is aimed at.

When those teams fall behind, criminals break in. Breached customer records, fraudulent charges, and leaked personal details are the downstream result of patching failures at scale.

If an organisation you deal with sends a notification about a data breach, take it seriously. Change your password for that service, watch your bank statements, and consider whether you reused that password elsewhere. Reusing passwords remains one of the most reliable ways a single breach turns into five.

MFA, short for multi-factor authentication, meaning a second confirmation step beyond your password such as a code sent to your phone, would not fix a server patching delay. It would, however, limit how much damage criminals can do with any credentials they steal as a result of one.

Common questions

Does this mean my accounts are in immediate danger?

Not necessarily. This is a warning about organisational risk management, not evidence of a specific breach. The sensible response is to check that any important accounts use a unique password and have multi-factor authentication turned on.

Can AI help defenders as well as attackers?

Yes. Security teams also use AI to scan their own systems for weaknesses, though Rapid7's point, first covered by SecurityWeek, is that the balance currently favours the attacking side.

© 2026 Threat Vectr