Desk live·
ForensicPost
Cloud/Method/File 26-0307

Thousands of Unfixed Findings Publish With No Party Accountable for the Aggregate

Every party in the disclosure chain manages its own piece competently. The aggregate exposure created when thousands of findings publish unfixed is nobody’s assigned responsibility.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetDisclosure ecosystem
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

Follow the chain. A research organisation discovers vulnerabilities and discloses them responsibly. A maintainer receives a report and fixes what capacity allows. A database enriches what it can, per the triage model at 26-0412. A security team patches what its scanner surfaces.

Each party is behaving correctly within its remit. The aggregate outcome — thousands of publicly known, unfixed defects in universally deployed software — is produced by all of them and owned by none.

This Is A Coordination Failure, Not Negligence

It is worth being precise, because the temptation is to assign blame. The researcher who withheld findings would be criticised for it. The maintainer working without pay cannot be asked for more. The database triaging by exposure made a defensible call.

The failure is that no participant has either the mandate or the information to assess the total, and the total is the thing that determines actual risk.

Where An Equivalent Function Exists Elsewhere

Other domains have built exactly this role. Financial regulators assess systemic risk that no individual bank is positioned to see. The systemic-event classification filed at 26-0415 is an early attempt at the same thing for cyber incidents.

None of those emerged voluntarily from the participants. They were imposed after an aggregate failure that individual prudence had not prevented.

What Could Be Measured Now

Somebody could publish, monthly, the count of disclosed-and-unpatched vulnerabilities in the twenty most widely deployed open-source components, weighted by deployment.

That is a tractable measurement with existing data. It does not exist, and until it does, every discussion of whether the current arrangement is working is being conducted without the number that would settle it.

How we reported this

This is an analysis file built on published research, listed below, read against files previously published by this desk. The argument and the proposal are ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. Project Glasswing and the AI vulnerability disclosure velocity crisisCloud Security Alliance
  2. The NVD backlog is a symptom: vulnerability management has a scaling problemNowSecure
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary