Follow the chain. A research organisation discovers vulnerabilities and discloses them responsibly. A maintainer receives a report and fixes what capacity allows. A database enriches what it can, per the triage model at 26-0412. A security team patches what its scanner surfaces.
Each party is behaving correctly within its remit. The aggregate outcome — thousands of publicly known, unfixed defects in universally deployed software — is produced by all of them and owned by none.
This Is A Coordination Failure, Not Negligence
It is worth being precise, because the temptation is to assign blame. The researcher who withheld findings would be criticised for it. The maintainer working without pay cannot be asked for more. The database triaging by exposure made a defensible call.
The failure is that no participant has either the mandate or the information to assess the total, and the total is the thing that determines actual risk.
Where An Equivalent Function Exists Elsewhere
Other domains have built exactly this role. Financial regulators assess systemic risk that no individual bank is positioned to see. The systemic-event classification filed at 26-0415 is an early attempt at the same thing for cyber incidents.
None of those emerged voluntarily from the participants. They were imposed after an aggregate failure that individual prudence had not prevented.
What Could Be Measured Now
Somebody could publish, monthly, the count of disclosed-and-unpatched vulnerabilities in the twenty most widely deployed open-source components, weighted by deployment.
That is a tractable measurement with existing data. It does not exist, and until it does, every discussion of whether the current arrangement is working is being conducted without the number that would settle it.
This is an analysis file built on published research, listed below, read against files previously published by this desk. The argument and the proposal are ours and labelled as such. Corrections: corrections@forensicpost.com.