Number of 2020 vulnerability disclosures set to overtake 2019
Despite a sharp decrease of 19.2 percent observed earlier in the year, vulnerability disclosures in 2020 are expected to exceed 2019's level according to Risk Based Security.
The company's VulnDB team aggregated 23,269 vulnerabilities disclosed during 2020. Despite the initial disruption from COVID-19, the trend of total number of vulnerabilities suggests that business operations and routines have normalized as the gap has closed to 0.98 percent.
"2020 could be titled 'The Great Catch-up'. We saw an incredible drop of 19.2 percent in Q1, but with each subsequent quarter that massive gap steadily closed," says Brian Martin, vice president of vulnerability intelligence at Risk Based Security. "The question now is how COVID-19 will impact the 2021 vulnerability landscape. Have we fully shaken off the disruption from the pandemic, or will we still see some lingering side-effects?"
During the pandemic there were three Vulnerability Fujiwhara events -- the term adopted for the collision of patch releases from Oracle, Microsoft, and other major vendors on the same day. These result in challenging workloads for vulnerability management teams, and make timely patching and remediation a difficult task for many organizations.
To make matters more difficult the Common Vulnerabilities and Exposures (CVE) list continues to fall behind in its coverage. "In 2020, CVE failed to report 29 percent of known disclosed vulnerabilities and organizations looking for those details can find those missing vulnerabilities in VulnDB," says Martin. "Our VulnDB team hit a major milestone of 80,000 aggregated vulnerabilities without a CVE ID. Now that it appears operations have mostly normalized, those who are wary or are struggling with current workloads may want to consider strengthening their vulnerability management programs with proper vulnerability intelligence."
You can get the full 2020 Year End Vulnerability QuickView Report from the Risk Based Security site.