CyberISolve

Security Testing & Risk

What a Real Vulnerability Assessment Found: Patterns From Recent Engagements

August 26, 2026 · 6 min read

Quick answer: the vulnerabilities that actually show up most often in small and mid-sized business assessments are rarely exotic, unpatched software, weak or reused credentials, overly broad access permissions, and exposed remote-access services account for the large majority of what we find. Here’s a look at the patterns, generalized across recent engagements rather than describing any one client.

Unpatched software, further behind than expected

The single most common finding is software that’s behind on patches, not by weeks, usually, but by months or longer on at least one system. This isn’t a judgment on the businesses we assess; patching consistently across every server, workstation, and piece of network equipment is genuinely hard without a dedicated process, and it’s exactly why a scheduled patch management process matters more than any single update cycle.

Weak or reused administrative credentials

Close behind patching gaps: administrative accounts with weak passwords, passwords reused across multiple systems, or, more often than you’d expect, default credentials that were never changed after initial setup on network equipment or management interfaces. A single reused admin password across systems means one compromised credential grants access far beyond where it was originally exposed.

Overly broad access and permissions

Access that was granted for a specific past need and never revoked is extremely common, a former employee’s account still active, a contractor’s access that was never scoped down after the project ended, or file-share permissions that grant far more read/write access than any given role actually requires. None of this looks alarming day to day, which is exactly why it accumulates unnoticed.

Exposed remote-access services

A meaningful share of engagements turn up a remote-access service, usually RDP, sometimes a NAS admin panel or an old VPN appliance, directly reachable from the public internet without the protections it should have. This is consistently one of the highest-severity findings we issue, precisely because it’s one of the most actively scanned-for configurations on the internet; see our Remote Access Security service and write-up on secure remote access for what the fix actually looks like.

Missing or unenforced multi-factor authentication

MFA gaps show up less as “no MFA at all” and more as “MFA on email, but not on the VPN, the admin panel, or the accounting software”, partial coverage that leaves exactly the systems an attacker would target next unprotected. Our write-up on MFA covers why the type of MFA matters too, not just whether it’s enabled.

What this means for prioritization

None of these findings require sophisticated tooling to fix, which is the point worth taking away: the highest-impact fixes in most assessments are unglamorous and largely a matter of process, patch on a schedule, enforce MFA everywhere, review access on a recurring basis, and don’t expose remote access directly to the internet. A vulnerability monitoring engagement is built specifically to catch these before they sit unnoticed for months.

← All Blogs

Frequently asked questions

Are these findings specific to one industry?

No, these patterns show up across almost every industry we assess, they reflect common IT and process gaps, not sector-specific weaknesses.

How long does a vulnerability assessment take?

Typically one to two weeks depending on environment size, from initial scanning through a prioritized report.

Related CyberISolve Services

Related Cybersecurity Resources

Dealing with something similar?

Tell us what's going on, active incidents get a same-day response, 24/7.