Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 4IT NewsFOSS

Multi-Patch Vulnerability Fixes Can Leave Open Source Exposed

Help Net Security, Thursday, July 23rd, 2026

University of Texas researchers found multi-patch CVE fixes create exploitable gaps between the first and final patch.

A study of 1,646 open source CVEs with multiple patches found roughly 31.7% take more than a day to complete, leaving systems vulnerable during the interval.

The research identified three fix patterns: vulnerabilities spanning multiple locations, bundled security changes, and defective patches requiring follow-up.

Automated detection tools failed to distinguish incomplete fixes from complete ones, with accuracy below 50%. Attackers can exploit the timing gap by spotting equivalent weaknesses in unpatched branches once the initial fix becomes public.

more →  ·  More from FOSS →