Multi-Patch Vulnerability Fixes Can Leave Open Source Exposed
Help Net Security, Thursday, July 23rd, 2026
University of Texas researchers found multi-patch CVE fixes create exploitable gaps between the first and final patch.
A study of 1,646 open source CVEs with multiple patches found roughly 31.7% take more than a day to complete, leaving systems vulnerable during the interval.
The research identified three fix patterns: vulnerabilities spanning multiple locations, bundled security changes, and defective patches requiring follow-up.
Automated detection tools failed to distinguish incomplete fixes from complete ones, with accuracy below 50%. Attackers can exploit the timing gap by spotting equivalent weaknesses in unpatched branches once the initial fix becomes public.