Unpatched Flaws Now Outpace Stolen Credentials as the Leading Breach Entry Point
Verizon's 2025 DBIR puts vulnerability exploitation at 31% of breach root causes. Median patch time has climbed to 43 days, and only 26% of CISA KEVs were fully remediated — a gap attackers are sprinting through.

Vulnerability exploitation has decisively overtaken credential abuse as the most common way attackers break into enterprises, according to Verizon's 2025 Data Breach Investigations Report (DBIR), now in its 19th edition. Exploited flaws drove 31% of confirmed breaches across the study's dataset of 22,000 incidents spanning 145 countries; credential misuse accounted for 13%. The gap was not this wide a year ago.
The numbers have teeth. Median time-to-patch rose to 43 days in 2025, up from 32 days the prior year. Only 26% of CISA Known Exploited Vulnerabilities were fully remediated — down from 38% the year before — while the volume of critical-severity flaws organisations had to triage grew 50% year-on-year. Something had to give, and it did.
"Attackers follow the path of least effort at scale, and right now that path runs through unpatched perimeter and edge devices, where a working exploit needs no prior access, no phished user, and no breach data to buy," said Daniel Bechenea, security manager at Pentest-Tools.com. Chris Wysopal, co-founder and chief security evangelist at Veracode, agreed: "Organizations are still simply not fixing flaws fast enough."
Google Cloud Security's Cloud Threat Horizons Report arrived at a compatible figure independently: software vulnerabilities were the single largest initial access vector in that dataset at 44.5% of incidents, again ahead of credential abuse. Two methodologically separate studies landing in the same place is hard to dismiss.
But the story is not as clean as the headline number suggests. James John, incident response manager at Bridewell (which contributed case data to Verizon's report), said the picture changes once you look past initial access. "Exploitation may now win the race to the front door, but stolen credentials are still the thread running through most intrusions we respond to; they're just used later in the attack, to move laterally and reach the data that matters," John said. He also flagged a measurement problem: credential theft and pretexting (which the DBIR attributes to 6% of breaches, increasingly common in ransomware chains) blur together in post-incident classification, so some of the apparent credential decline is an artefact of how events get logged.
Phishing held steady at 16% of initial access vectors. Third-party and supply chain exposure jumped sharply: breaches involving an external vendor now account for 48% of all incidents in the DBIR dataset, a figure that reflects both attacker targeting and the expanding software dependency graph most enterprises carry.
And AI is beginning to compress the exploitation window in ways that make the 43-day median patch time look worse than it already is. Verizon's team warned that threat actors are using AI assistance to accelerate time-to-exploit for known vulnerabilities "from months to mere hours." Google's Threat Intelligence Group published evidence in May 2025 of a zero-day exploit chain developed with direct AI tooling assistance by a financially motivated criminal group. So a CVE that previously gave defenders a few weeks of quiet time now may not.
Muhammad Yahya Patel, vCISO for EMEA at Huntress, said the DBIR should push CISOs away from scheduled patch cycles toward continuous, risk-based vulnerability management tied to real-time exploitation intelligence. "The organizations best positioned are those that have built defense in depth across all of these vectors," Patel said. Raghu Nandakumara, VP of industry strategy at Illumio, pointed to a structural problem underneath the cycle: AI-assisted discovery, open-source dependency sprawl, and a more active disclosure ecosystem mean the backlog of unpatched flaws is growing faster than remediation capacity at most organisations.
Ransomware appeared in 48% of breaches (up from 44%), even as ransom payments fell — 69% of victims did not pay. Marks & Spencer's weeks of outages following a 2025 ransomware attack illustrated where the leverage is migrating: from data-theft extortion to sustained operational disruption, which lands harder on essential services than on organisations that can credibly demonstrate tested backups.
The patch-your-perimeter advice is as old as the field. What the 2025 DBIR adds is a precise measurement of how badly execution is slipping at exactly the moment attackers are getting faster — and the CVE database at NVD is not getting shorter.



