“Patch everything” is not a strategy. It is a wish. Every environment has more vulnerabilities than any team can close in a week, which means the real question is never whether you have vulnerabilities. It is which ones actually matter, and where to point your limited time first.
The reassuring news is that risk is not random. It has a shape. A lot of what creates that shape is set by something as mundane as what industry your client is in, and what ordinary software everyone in that industry happens to run.
Every industry has a signature
Look across a large number of managed environments and a pattern emerges that is hard to unsee. Each industry tends to have a characteristic piece of software that shows up, again and again, as the most common carrier of active vulnerabilities. It is rarely exotic or particularly interesting. It is almost always something boring and everywhere.
In the environments Cork sees across its partner base, the patterns break down along a few clear lines.
Remote access and VPN clients dominate several sectors. Cisco Secure Client turns up as the most common vulnerable software in construction, in finance and insurance, and in retail, among others. SonicWall NetExtender leads in health care and in real estate. These are the tools everyone connects through to get work done, which is exactly why they are both everywhere and attractive to threat actors.
PDF readers own another large slice. Adobe Acrobat Reader and Foxit PDF Reader are the top vulnerable software in education, public administration, arts and entertainment, information, and transportation. Every desktop has one. Almost nobody thinks of it as security-critical. It opens files from outside the organization all day long.
Database servers show up in the industries built on data. Microsoft SQL Server is the most common vulnerable software in manufacturing and in professional, scientific, and technical services, sitting quietly behind the line-of-business applications those firms depend on.
Why the “boring” software is the risky software
There is a reason the pattern lands on ordinary tools rather than flashier ones.
First, they are everywhere. A vulnerability in software installed on one machine is a footnote. The same vulnerability in software installed on every machine is a campaign waiting to happen.
Second, they handle untrusted input or face the internet. A VPN client is a front door by design. A PDF reader opens documents from strangers all day. A database server is the thing worth stealing. These are not incidental targets. They are the point.
Third, they patch on their own schedule, not the operating system’s. Everyone has a process for OS updates. Far fewer have a reliable process for keeping the PDF reader, the VPN client, and the database engine current across a whole client base. That gap between “we patch” and “we patch everything” is where the exposure lives.
Not all vulnerabilities are equal: the KEV signal
This is where a single idea does more prioritization work than any scanner. Known Exploited Vulnerabilities.
The KEV catalog, maintained by the US Cybersecurity and Infrastructure Security Agency and VulnCheck , is a list of vulnerabilities confirmed to be under active exploitation in the real world. Not theoretical. Not “could be dangerous.” Being used, right now, by actual attackers.
That distinction changes how you triage. A vulnerability with a scary score that nobody is exploiting can wait. However, a vulnerability on the KEV list is a door someone is actively trying to walk through. When one of those lands in the everyday software your industry runs on, that is not a maintenance item. That is the thing to prioritize fixing today.
When you put the two ideas together, you get a genuinely short, genuinely useful list.
Which of my clients run the software my industry is most exposed on?
Which of those carry an actively exploited vulnerability that is still unpatched?
Answer those questions, and you have found the handful of things most likely to cause a real incident. This prioritization gets you ahead of everyone still trying to patch everything at once.
Turning the pattern into action
The obstacle has never been the concept. It has been the legwork. Answering that question the manual way means inventorying software across every client, cross-referencing it against exploited-vulnerability lists, and figuring out what is actually patched. For a small team across a large book, that is not realistic to do often, so it does not get done.
This is where surfacing vulnerabilities across the connected stack earns its keep. Cork finds the software vulnerabilities living across the tools you already run, ties them to specific endpoints and clients, and lets you act on them, including pushing patches through your RMM and package managers rather than touching each machine by hand. The prioritization stops being a research project and becomes a working list.
If you are on the client side of this, the takeaway is a question worth asking your provider. What are the common exposures for a business like mine, and are we carrying any that are actively being exploited right now? A provider who can answer that clearly is one who is triaging by real-world risk, not by whatever the scanner happened to sort to the top.
Risk has a shape, so use it
The point of all this is not to fear a specific product. Cisco, SonicWall, Adobe, Foxit, and Microsoft build software the entire economy runs on, and being common is not the same as being bad. It is that risk concentrates, predictably, in the tools an industry cannot operate without.
That predictability is a gift. It means you do not have to defend everything equally. You can look at what your industry actually runs, find the pieces carrying vulnerabilities the world is actively exploiting, and start prioritizing there.
Patch by priority, not by panic. The list is more reasonable to manage than it feels.



