Overview
Software vulnerability risk is shaped by rapidly increasing disclosure volumes, unreliable public data sources and a shrinking window between vulnerability disclosure and active exploitation. Understanding where your current approach leaves blind spots—and how to close them—is essential for reducing breach risk, maintainingcompliance and protecting business operations.
In this on-demand webinar, Flexera's Nathan Stevens and Jeroen Braak break down why traditional vulnerability management approaches are failing, how the National Vulnerability Database (NVD) has become unreliable, and what organizations need to do differently—with a live demo of Flexera's Software Vulnerability Research and Software Vulnerability Manager platforms.
You'll learn how to shrink your risk window and focus remediation on the threats that actually matter, including:
- Why over 250 vulnerabilities are now disclosed per business day—and why that number is accelerating due to AI
- Why the NVD is moving to a selective model that will cover less than 50% of validated vulnerabilities—and what that means for downstream tools
- How Secunia ;Research's verified, context-rich intelligence enables same-day alerting, accurate CVSS scoring and prioritized remediation across 74,000+ product versions
This session is designed for security teams, IT operations, ITAM practitioners and compliance officers who need a clear, practical approach to vulnerability management before the next disclosure, audit or regulatory deadline.
Speakers
Nathan Stevens
Senior Director, Solutions Engineering (APAC)
Flexera
Jeroen Braak
Security Sales Specialist
Flexera
Key takeaways for security, IT operations and ITAM teams
- Vulnerability volume has doubled—and traditional approaches can't keep up. Organizations now face over 250 new vulnerabilities per business day, up from 180 in 2025. AI and automation are accelerating both disclosure and exploitation, making manual tracking unsustainable.
- The NVD is no longer a reliable foundation for vulnerability management. Since February 2024, the NVD has been unable to maintain a verified, analyzed catalog of CVEs. It recently announced a shift to a selective, risk-based model that will focus only on US government priorities—resulting in less than 50% validated coverage. Organizations relying on NVD data downstream (through Tenable, Rapid7, Qualys, etc.) are inheriting those gaps.
- CVSS scores from vendors and public databases are frequently inaccurate. The webinar demonstrates a live example where a vendor scored a vulnerability at 3.3, Tenable scored it at 5.5, and Secunia Research's verified assessment confirmed it at 7.5—a critical difference that determines whether compliance teams act within days or deprioritize entirely.
- 99% of successful exploits target known vulnerabilities—and less than 10% of vulnerabilities are ever exploited. This means prioritization is the single most impactful capability. Patching everything is neither possible nor necessary—but patching the right 10% is critical.
- The risk window has collapsed from 30 days to less than one day—while average remediation still takes 192 days. Attackers are building exploits within hours of disclosure. Without same-day intelligence and automated remediation workflows, organizations are exposed for months before patches are deployed.
- The Jaguar Land Rover breach illustrates the real-world cost of an open risk window. The most costly cyberattack in UK history resulted in approximately £2 billion in economic losses, five months of limited production and logistics, 50% lost production in the final quarter, and an estimated £30 million in lost revenue in Q3 alone.
- Flexera delivers 70% reduction in time spent researching and validating security data—and can reduce patch deployment timelines from weeks or months to hours and days through automated, prioritized remediation.
Why most organizations are missing the software risks that matter most
Why vulnerability volume is overwhelming traditional security teams
Over 250 new vulnerabilities are disclosed every business day—and the number is accelerating faster than any team can manually track. The volume increase is driven by AI-powered discovery, broader software ecosystems and more active disclosure from researchers and vendors. Traditional processes that rely on manual research, spreadsheet tracking or periodic scanning can't keep pace. The webinar shows how Secunia Research monitors 74,000+ product versions and delivers same-day advisories for 95–97% of disclosures—providing the speed and coverage that manual processes cannot.
Outcome: Automated, curated intelligence replaces manual research—enabling teams to focus on action rather than tracking.
Why relying on public vulnerability databases creates dangerous blind spots
The NVD has been dysfunctional since February 2024 and is moving to a selective model that will cover less than 50% of validated vulnerabilities. ;Most traditional vulnerability scanners—Tenable, Rapid7, Qualys—rely on NVD data downstream. As the NVD reduces its scope to focus only on US government priorities, the gaps in enrichment, analysis and validation are passed directly to organizations using those tools.
The webinar demonstrates how Secunia Research provides independent, verified intelligence that doesn't depend on the NVD—including accurate CVSS scoring, exploit context and same-day remediation guidance.
Outcome: Organizations using verified, independent intelligence sources avoid inheriting the NVD's growing coverage gaps—and can trust their prioritization decisions.
Why accurate CVSS scoring is the difference between action and inaction
Vendor-provided and public CVSS scores are frequently inaccurate—and the difference can determine whether a vulnerability is treated as critical or ignored. The webinar includes a live demonstration: a vulnerability scored at 3.3 by the vendor, 5.5 by Tenable, and 7.5 by Secunia Research after independent verification. For organizations with compliance policies that require remediation within two weeks for vulnerabilities scoring 7.0 or above, this discrepancy is the difference between timely patching and months of undetected exposure.
Outcome: Verified CVSS scoring ensures compliance-driven remediation timelines are triggered by accurate data—not underreported vendor assessments.
Why shrinking the risk window is the most impactful security investment
The gap between vulnerability disclosure and remediation defines the opportunity for exploitation—and that gap is now measured in months while exploits appear in hours. The webinar introduces the "risk window" framework: disclosure-to-awareness time and awareness-to-remediation time. Average remediation still takes 192 days, while time to first exploit has dropped to less than one day. Flexera's Software Vulnerability Manager closes this gap through same-day alerting, automated patch publishing and integration with endpoint management tools (ConfigMgr, Intune, JAMF, WSUS, Tanium, Workspace ONE)—with the world's largest third-party patch catalog of over 14,000 patches.
Outcome: Patch deployment timelines are reduced from weeks and months to hours and days—directly shrinking the window of opportunity for attackers.
Why software vulnerability risk management matters
- Exploitation of known software vulnerabilities remains the greatest cause of security incidents—according to the UK National Cybersecurity Centre, the Australian government and multiple regulatory bodies including DORA, NIS2 and Cyber Essentials Plus.
- Only 6–8% of vulnerabilities lead to an exploit that could damage your organization—but without verified threat intelligence, teams can't identify which ones they are and waste resources patching blindly. (Flexera: Software Vulnerability Management)
- Secunia Research has provided market-leading vulnerability intelligence since 2002, covering 74,000+ product versions with same-day advisories, verified CVSS scoring and exploit-linked threat scores—independent of the NVD. (About Secunia Research)
- Flexera delivers the largest third-party patch catalog in the industry with over 14,000 patches, integrated with all major endpoint management tools for automated, prioritized remediation. (Flexera Patch Management)
👉 Watch our latest webinar on Stay ahead of cyber threats: Flexera's latest vulnerability insights
👉 Related: From alert to action: How intelligence, prioritization and patching drive security outcomes
If your team needs to identify, prioritize and remediate software vulnerabilities faster, Flexera's security solutions help:
- Software Vulnerability Research—verified, curated intelligence from Secunia Research with same-day advisories, threat scoring, exploit context and automated notifications across 74,000+ product versions
- Software Vulnerability Manager—scan, assess, prioritize and patch across Windows, Mac and Red Hat Linux with the industry's largest third-party patch catalog and integration with ConfigMgr, Intune, JAMF, WSUS and more
- Fully operational within an hour of deployment—reducing research time by 70% and patch deployment from weeks to hours
Frequently asked questions
The risk window is the time between when a vulnerability is disclosed and when it's remediated. It has two phases: disclosure-to-awareness (how quickly you learn about it) and awareness-to-remediation (how quickly you fix it). With exploits now appearing in less than a day and average remediation taking 192 days, shrinking this window is the most impactful action security teams can take.
Since February 2024, the NVD has been unable to maintain a fully validated catalog of CVEs. It recently announced a shift to a selective model focused on US government priorities, which will result in less than 50% validated coverage. Organizations relying on tools that use NVD data downstream—such as Tenable, Rapid7 and Qualys—are inheriting those gaps.
Secunia Research independently tests, verifies and validates vulnerabilities across 74,000+ product versions. It delivers same-day advisories with verified CVSS scores, exploit intelligence and remediation guidance—regardless of whether the NVD has processed the vulnerability. The webinar shows a live example where Secunia's verified score was 7.5 versus the vendor's 3.3 and Tenable's 5.5.
Flexera Software Vulnerability Manager is designed to complement or replace traditional scanners by combining Secunia Research intelligence with lightweight scanning (700KB agent), prioritization based on threat scoring, and the industry's largest third-party patch catalog. It integrates with ConfigMgr, Intune, JAMF, WSUS, Tanium and Workspace ONE for automated remediation.
Software Vulnerability Manager can be fully operational within an hour of receiving the license. The lightweight scanner runs as a scheduled task, scanning executables, DLLs, OCX files and Log4j JAR files in under two minutes. Training and initial configuration support are included to ensure teams are scanning and prioritizing from day one.
Transcript
Nathan Stevens 00:04 - 02:39
Awesome. Welcome, everybody, to tonight's in today's session, depending on where you're viewing this, particular webinar from.
Give everyone a few seconds to join, today, get into the Goldcast, motion, and get ready for the next, thirty minutes or so of, how to see the risk others missed in your software estate. So today, we're going to take a bit more of a deeper dive into what an overview, really, just a teaser of some of the capabilities within the Flexera stack that you may not be aware of and particularly focus on the risk.
Today, we're joined by Jeroen who's going to take us through the security, component of the solution. So welcome, Jeroen.
Thanks for joining us. So just get stuck in.
So for those that haven't, and it's maybe your first webinar with us, we have gone through a whole series of these as well. So this is the last nine in the series.
These are available, online in some in some capacity as well, so, you know, some links will be shared in a second, if you wanna do catch up and watch any of these on demand. Continuing on with the webinar series.
So, really, today, we're focused on how to see the risk others missing. So depending on where you're joining this from, you'll get access to this content on nineteenth or the twentieth.
Looking ahead for the next two months, in June, we'll cover proving ITAM value, so a bit of a look into how do you sort of elevate the conversations around ITAM to the c level. And in July, we're gonna take a focus on metrics that matter.
So really looking into FinOps and the type of metrics that you can surface to really drive home the value and ROI around, the FinOps technology there. So today, like I always start with these sessions, I just put the platform front and center.
And today's a little bit different in terms of where we're going to focus is kind of adjacent to, you know, that the platform. So we have some fantastic capability around security vulnerability research and from the security team and also around how do we do that, vulnerability remediation through security vulnerability manager.
So I'm not gonna go through and, bore you to death, with any of my talk today, so I'll hand over to Jeroen who's going to take you through the details, in this space. So over to you.
Jeroen Braak 02:39 - 30:03
Yeah. Thanks, Nathan.
So hi, everyone. Yeah.
Let's talk about security. So first, you know, security has no less than 70 categories, and each category needs specialists, budgets, solutions, and they're all as equal as important to everyone involved.
So, what we do with Flexera's risk management solutions, we focus on the three Magenta ones. Obviously, with, the Regionspod Security acquisition, we are able to also add cloud security.
And with our ITV or IT visibility solution, we can deliver a higher confidence in more comprehensive risk and compliance management, of course, depending on the requirements and expectations of the customer. So let's dive, right in into the vulnerability and patch management and what that means.
So first, you know, what is a vulnerability? A vulnerability is a flaw. It's a bug.
It's a weakness in the system design, and it can be exploited at some point. You know? Software vulnerabilities are also referred as a CVE, a unique identifier to each vulnerability, and one CVE could potentially affect just one or, you know, in most of the time, multiple products, you know, even up to 200, products can't be affected by one CVE or one vulnerability.
They're all registered through a, platform called the cv. org.
It's a semi, government agency out of The US, and it's also, covered in the NVD, the National Vulnerability Database, and all since 1999, so over twenty seven years now. And what we see is a is a huge increase in the number of, vulnerabilities.
It's it's increasing rapidly, and that's not only because, you know, we are getting better in what we do, but, you know, also what happens with the AI, with MyFalls, you know, we see that a lot of lower bids are being disclosed right now. Where in 2025, we had about a 180 vulnerabilities per business day.
Currently, here today, we are over 250 CVs per business day. You know, let that sink in.
How do you track? How do you know? And how do you keep up with that? And, you know, we also see that with our own dedicated market leading research team, Secunia Research. We see a huge increase in, like, we never seen before.
As you can see here, you know, the past few years, it's pretty mild, I would say. But, you know, if we look at this year, you know, the numbers are doubling.
And that that is that is, you know, mainly due to the LMS or, to AI or automation. But, you know, it is a concerning, situation that we're in because how do you cope with that? And as I mentioned before, you know, CV information is maintained by, you know, this database, cv.
org, and the NVD, the National Vulnerability Database. And normally, the NVD pushes or publishes actually CVs with additional information.
They do, like, analysis and making sure that, you know, that all the information is correct in there. But, unfortunately, during the last two years since February 2024, we see that NVD is no longer up to the task to maintain a verified analyzed catalog of CVs and making it, therefore, dysfunctional and unreliable.
But many organizations still use that free data downstream. You know, we see that in the 10, you know, tenables or rapid sevens, the Qualysys and all those, major traditional vulnerability scammers out there.
And, actually, three weeks ago, the NVD announced that they are moving to a more selective risk based model. That means that they only will focus on subset of the of all the products that they normally would care about.
And that is gonna be a huge issue. You know, they're only gonna focus for internal customers.
They're a US government. And that will result in a in a less than 50% coverage in the validated and analyzed and enriched information that the organizations are looking for.
There's great news for malicious actors, you know, because they can you know, the vulnerabilities will still be disclosed, but, you know, there will be less information for people to actually remediate them. So the malicious actors can build exploits faster and be more successful.
So, you know, what is an exploit then? So, an exploit is our worst nightmare. When a vulnerability is disclosed by a vendor or before they even know, right, a zero day, malicious actors have already started building so called exploits or proof of concepts that could lead to ultimately a ransomware attack, a malware, data theft, or even other costly impactful events that can cripple companies, industries, people at home, hospitals, people even died in the past because of breaches.
And, you know, even governments could be affected by it. And, you know, exploitation of no soft software vulnerabilities remains the greatest cause of security incidents.
And that's not me saying it, but it's the National Cybersecurity Center saying it. It's the Australian government saying it, and there are so many other authorities and compliance or, regulators out there for the industry, like Cyber Essentials Plus, Dora, NIST two, you know, all these in the list.
And some in some of these compliance rules and regulations, even that the board level people are being personally responsible for, you know, for fines or even losing their job. So it's very important that we keep track of everything and we try to do our best.
And the best thing we can do, of course, is to patch. Right? The patch is the data for modifying existing software resource as you can read.
But it's also very important because, you know, there are some problems with patching. You know, it doesn't come out as fast as we would.
And if it comes out, the problem is that, you know, you need to find the patch first. You need to know if it's applicable to your environment and then, you know, deploy it.
That can take sometimes, you know, days, weeks, even sometimes even months in some cases. And that means that, you know, the malicious actors will have access to your environment if you if you either if you know it or not don't know it.
But that could, lead up to, like, huge, you know, massive, exploits or or other negative consequences.
Nathan Stevens 30:03 - 30:49
Yeah. Perfect.
So I think I've answered some of the questions. We've been answering them in the chat, as we've been talking as well.
So thanks again, Jeroen, for joining us today. As, as we said, please reach out to Jeroen or I, if you wanna get some more information.
We've just added these two QR codes to point to the product pages on the Flexera website, to get some more details, but please do reach out, to us if you wanna dive deep dive into the solution. It's just impossible to get through absolutely everything in in the time that we have today, but, hopefully, this was a fantastic, sneak peek of, both of these fantastic capabilities, and, please reach out if you wanna know any more.
So thanks again, and thanks everyone for joining today.
Jeroen Braak 30:49 - 30:49
Thank you.
Let’s get started
Our team is standing by to discuss your requirements and deliver a demo of our industry-leading platform.