Cybersecurity · Third-Party Risk

AI Can Now Find Vulnerabilities Faster. Your Vendors May Not Fix Them Faster.

Gartner's Q2 2026 Emerging Risk Report — a survey of 316 senior executives and risk managers — ranked AI-driven vulnerability discovery the single most critical emerging risk worldwide, ahead of geopolitical shocks and agentic AI itself. Detection has industrialized. The question every TPRM and cyber-risk leader now has to answer is whether vendor remediation has kept pace.

Crest.Digital Editorial September 2, 2026 10 min read Cybersecurity & Vendor Risk

For most of the last decade, the cybersecurity conversation around vulnerabilities has centered on discovery — finding the flaw before an attacker does. That framing made sense when discovery was the bottleneck: skilled researchers, limited tooling, and a slow, manual process meant most vulnerabilities sat undiscovered for months or years. AI has broken that bottleneck. What it hasn't broken, and what a fresh piece of Gartner research says enterprises are now underestimating, is the bottleneck sitting immediately downstream — whether the organization actually responsible for fixing a newly discovered flaw can do so before it's exploited.

That downstream bottleneck is rarely inside the enterprise's own four walls. Most of a typical organization's technology surface area runs through vendors, SaaS platforms, managed service providers, and the subcontractors behind them — which means a faster vulnerability-discovery cycle only lowers enterprise risk if the vendor on the other end of that discovery can remediate at a matching pace. Gartner's newest data suggests that assumption deserves far more scrutiny than most third-party risk programs currently give it.

The Gartner Signal — A First-Time, Number-One Ranking

In its Q2 2026 Emerging Risk Report, Gartner surveyed 316 senior executives and risk managers across a range of industries and regions during April and May 2026, asking them to identify and rank the risks they believe pose the greatest threat to their organizations over the coming months. AI-enabled discovery of cyber vulnerabilities came back first — the single highest-ranked emerging risk in the entire survey, and notably, the first time the issue had appeared in the report at all. Three months earlier, the same quarterly survey had information integrity risk at the top, with AI vulnerability discovery not even registering in the top five.

Kevin Mercado, senior principal analyst in Gartner's Risk & Audit Practice, framed the shift plainly in Gartner's own reporting on the survey: "The ability of AI to increase the efficiency and accessibility of vulnerability discovery is making it increasingly difficult for traditional risk management approaches to keep pace." His warning goes directly to the point this article is built around — "without corresponding improvements in governance, security operations, and remediation capabilities, AI-driven vulnerability discovery may outpace organizational defenses, increasing the likelihood of significant cyber incidents and operational disruption."

The rest of Gartner's top five reinforces how central AI has become to the enterprise risk conversation generally — geopolitical energy and supply shocks ranked second, agentic AI itself ranked third, information integrity risk fourth, and an AI workforce preparedness gap rounded out fifth. But it's the number-one ranking that matters most for a third-party risk program specifically: AI is compressing the interval between a flaw existing and a flaw being found, and in many documented cases, between a flaw being found and a working exploit being available. That compression happens on both sides of every vendor relationship — attackers scanning for flaws in vendor software, and increasingly, vendors and their customers scanning for flaws using the same class of tooling.

Do you know how fast your critical vendors actually close a disclosed vulnerability?

Most vendor cyber questionnaires capture a point-in-time posture. See how AI-powered vendor intelligence tracks vulnerability signals against actual remediation evidence, continuously.

Explore Crest Intelligence

The Vendor Remediation Gap

Call it the vendor remediation gap: the widening interval between when a vulnerability affecting a vendor's product, platform, or infrastructure is discovered, and when that vendor can demonstrate — with evidence, not just a status update — that the flaw is actually closed. Three structural forces are widening that gap even as detection technology improves.

Detection has scaled faster than remediation capacity. AI-assisted scanning tools can enumerate previously unknown flaws across an organization's codebase, configuration, and dependencies at a volume no human review team can absorb manually. Fixing a flaw, by contrast, still generally requires a human engineer to understand the change, test it against production dependencies, schedule a deployment window, and confirm nothing broke — work that has not compressed at anything like the same rate. The result is a growing backlog of known-but-unpatched vulnerabilities sitting inside vendor environments at any given moment.

Vendor resourcing is uneven across a typical portfolio. A large, well-capitalized software vendor with a mature security engineering function can often triage and patch a high-severity disclosure within days. A smaller vendor, a niche point-solution provider, or a subcontractor several tiers removed from the primary relationship frequently cannot — not from negligence, but because dedicated security remediation capacity is exactly the kind of overhead a resource-constrained vendor deprioritizes until an incident forces the issue. A vendor portfolio is only ever as fast as its slowest critical vendor.

Most TPRM programs still measure posture, not remediation speed. Annual cyber questionnaires and point-in-time security ratings tell a risk team what a vendor's security posture looked like on the day it was assessed — they say very little about how quickly that same vendor closes a newly disclosed, high-severity flaw six months later. Without a mechanism built specifically to track vulnerability signal through to verified closure, a program can hold a green rating on a vendor sitting on an unpatched, actively exploited flaw for months.

⏱️
Detection Speed ≠ Enterprise Safety A faster vulnerability-discovery cycle only reduces enterprise risk if the party responsible for the fix closes it at a matching pace. Gartner's own framing is explicit: AI-driven discovery "may outpace organizational defenses" without a corresponding improvement in remediation capability — and for most enterprises, most of that remediation capability sits inside a vendor's organization, not their own.

From Vulnerability Signal to Closed Remediation — Six Stages

Closing the vendor remediation gap doesn't require slowing down vulnerability discovery — it requires building the operational machinery to act on a disclosed flaw as fast as it's found. Six stages carry a vulnerability signal from discovery to a defensible, evidenced close.

1

Vendor Criticality Baseline

Establish each vendor's cyber-criticality tier ahead of time — system access, data sensitivity, operational dependency, substitutability — so severity is judged against real exposure, not spend or reputation.

2

Vulnerability Signal Ingestion

Continuously ingest vulnerability intelligence — CVE and NVD feeds, exploit-prediction scoring, vendor security advisories, dark-web exploit chatter — rather than waiting for vendors to self-report.

3

Exposure Mapping

Match each disclosed vulnerability against the specific software, versions, and infrastructure actually in use by each vendor, filtering out industry-wide noise that never touches the real portfolio.

4

Remediation SLA Assignment

Assign a risk-based remediation deadline combining vendor criticality tier and vulnerability severity — materially shorter windows for high-criticality vendors facing high-severity flaws.

5

Evidence of Closure

Require and independently verify remediation evidence — patch confirmation, compensating-control documentation, or a formal risk-acceptance record — rather than an unverified closure claim.

6

Escalation & Audit Trail

Escalate overdue or critical remediations to a named risk owner automatically, and preserve a full audit trail from signal to closure for every vulnerability tracked against every vendor.

The sequence matters as much as any individual stage. Skip the criticality baseline and every disclosed vulnerability looks equally urgent — a state that either burns out a risk team chasing low-impact flaws or, more dangerously, causes genuinely critical ones to get lost in the noise. Skip the evidence-of-closure stage and a program is left trusting a vendor's word that a fix shipped, which is precisely the point-in-time, self-reported assurance model that a portfolio-wide AI-driven vulnerability landscape has already outgrown.

Ready to see vulnerability-to-remediation tracking running against your actual vendor portfolio?

Crest.Digital applies agentic AI to continuous vendor cyber monitoring — mapping disclosed vulnerabilities to real exposure and tracking every remediation to verified closure, with a named reviewer on every determination.

Building a Remediation-Speed Program, Not Just a Detection Program

Most enterprises already have some form of vulnerability intelligence feeding into their own security operations. Far fewer have built the equivalent discipline for their third-party portfolio — treating vendor vulnerability remediation as a tracked, escalated, evidenced control rather than a line item inside an annual questionnaire. Eight practices distinguish programs that have made that shift.

The Eight-Point Vendor Remediation Framework

  • Tier vendors by cyber criticality before a vulnerability ever surfaces. Access, data sensitivity, operational dependency, and substitutability — not contract value — should determine how urgently a disclosed flaw gets chased.
  • Ingest vulnerability intelligence continuously, not on a review cycle. CVE/NVD feeds, exploit-prediction scoring, and vendor advisories should flow into the program in near real time, not at the next scheduled reassessment.
  • Map every signal to actual exposure. Filter disclosed vulnerabilities against the specific software and versions genuinely in use by each vendor — generic industry alerts create noise a risk team can't sustainably chase.
  • Set risk-based remediation SLAs, not a single blanket deadline. A critical vendor facing a high-severity flaw needs a materially shorter clock than a low-access vendor facing a low-severity one.
  • Require verifiable evidence of closure. Patch confirmation, compensating-control documentation, or a formally approved risk-acceptance record — not a vendor's unverified "resolved" status update.
  • Escalate overdue and critical items automatically. A named risk owner should be alerted the moment a high-criticality remediation passes its SLA, not discover it at the next quarterly review.
  • Track repeat and systemic patterns across the portfolio. A vendor that consistently misses remediation SLAs, or a vulnerability class recurring across multiple vendors, is a program-level signal worth escalating beyond the individual case.
  • Maintain an audit-ready evidence trail end to end. Every stage — signal, exposure match, SLA assignment, evidence, escalation — should be documented well enough to support a board, regulator, or cyber-insurance underwriter's review after the fact.

Two of these eight practices tend to separate mature programs from the rest. Risk-based SLA assignment matters because a single fixed remediation window — "30 days for every vendor, every flaw" — either sets the bar too low for genuinely critical exposure or too high for low-risk vendors, and most programs default to the former simply because it's operationally simpler to administer. Verified evidence of closure matters because the alternative — trusting a vendor's self-reported status — reintroduces exactly the self-attestation gap that continuous vendor monitoring exists to close in the first place; a "resolved" ticket status is not the same thing as a confirmed patch.

Global research bodies are converging on the same conclusion from different angles. ISACA's guidance on continuous assurance increasingly frames vulnerability and control remediation as a tracked, time-bound process requiring documented evidence rather than a periodic checkbox, and the NIST Cybersecurity Framework's "Respond" and "Recover" functions explicitly call for organizations to track remediation timeliness as a measurable control, not an assumed outcome of having a patch-management policy on paper. Neither framework was written with AI-accelerated discovery specifically in mind, but both anticipate the same underlying failure mode this article describes — a gap between knowing about a risk and demonstrably closing it.

Where Agentic AI Fits

There's a certain irony in the fact that the technology creating the vulnerability-discovery surge is also the best available tool for closing the remediation gap it opens. Manually cross-referencing every newly disclosed CVE against the specific software and versions running across a portfolio of hundreds or thousands of vendors, then tracking each relevant one through to verified closure, is not a task that scales with headcount — it's exactly the kind of continuous, high-volume, pattern-matching work agentic AI is suited to.

An AI-led vendor risk workflow can continuously ingest vulnerability intelligence feeds, resolve which vendors and which specific systems a new disclosure actually touches, assign a risk-based remediation SLA by vendor tier automatically, and monitor for closure evidence — flagging the moment a critical item passes its deadline without a verified fix. That compresses what would otherwise require a dedicated analyst manually cross-checking spreadsheets against advisory feeds into a continuously running control that never falls behind the pace of disclosure, regardless of how many new vulnerabilities surface in a given week.

What doesn't change is who makes the call on residual risk. An AI-assisted system can tell a reviewer that a critical vendor's remediation for a high-severity flaw is now eleven days overdue, or that a vendor's "patched" claim doesn't match the version fingerprint the system observed in a follow-up scan — but whether to escalate to the vendor's leadership, invoke a contractual remediation clause, or formally accept the residual risk for a defined period is a judgment call that belongs to a named human risk owner, supported by the evidence trail the AI-led workflow assembled. That human-in-the-loop structure is what makes a remediation-speed program defensible to a board, an auditor, or a cyber-insurance underwriter — not that AI closed the loop, but that AI surfaced the complete, current picture a human then acted on, with the reasoning preserved.

This work sits naturally alongside capabilities most mature vendor risk programs are already building toward. A CISO-level view of vendor cyber risk and the broader shift toward continuous, real-time vendor risk scoring both depend on the same underlying discipline this article describes — treating a vendor's security posture as a living, continuously evidenced state rather than a once-a-year snapshot. The same logic that closed the gap in sanctions and watchlist screening — a clearance has a shelf life, not a permanent status — applies just as directly to vulnerability remediation, and cyber insurers are beginning to price that discipline directly, as supply-chain cyber exposure increasingly becomes underwritten risk rather than an unpriced externality.

Frequently Asked Questions

Gartner surveyed 316 senior executives and risk managers across industries and regions in April and May 2026 for its quarterly Emerging Risk Report. AI-enabled discovery of cyber vulnerabilities ranked as the single most critical emerging risk in that survey — the first time it had appeared in the report at all, having been outside the top five just one quarter earlier when information integrity risk held the top spot. Geopolitical energy and supply shocks, agentic AI, information integrity risk, and an AI workforce preparedness gap rounded out the remaining top five.

AI-assisted scanning tools can identify previously unknown flaws in software, APIs, and infrastructure at a volume and speed no manual review process can match, and the interval between a flaw being found and a working exploit existing has compressed sharply. Most of an enterprise's technology footprint runs through vendors, SaaS providers, and their subcontractors rather than systems built and patched in-house — so a faster vulnerability-discovery cycle only reduces enterprise risk if the third parties running that footprint can remediate at a matching pace. When they can't, the enterprise inherits the exposure regardless of how quickly its own security team found out about it.

The vendor remediation gap is the widening interval between when a vulnerability affecting a vendor's product or infrastructure is discovered — increasingly by AI-driven scanning, on either side of the relationship — and when that vendor actually confirms the flaw is fixed, with evidence. Detection has industrialized faster than remediation has, particularly among smaller or resource-constrained vendors, so the count of known-but-unpatched vulnerabilities sitting inside a typical vendor portfolio at any given time is growing even as detection technology improves.

Prioritization should combine vendor criticality with vulnerability severity rather than treating every disclosed flaw identically. A vendor with deep system access, sensitive data exposure, or limited substitutability should trigger a materially shorter remediation SLA for a high-severity vulnerability than a low-access, easily replaceable vendor with the same flaw. Programs that tier vendors by criticality up front — before a vulnerability signal ever arrives — can route and escalate exceptions immediately instead of re-litigating vendor importance every time a new flaw surfaces.

Agentic AI can continuously ingest vulnerability intelligence feeds, match disclosed flaws against the specific software, versions, and infrastructure actually in use across a vendor portfolio, assign a risk-based remediation SLA by vendor tier, and track evidence of closure against every open item — work that scales far beyond what a manual spreadsheet-driven tracking process can sustain across hundreds or thousands of vendors. The determination of what counts as acceptable remediation evidence, and whether to escalate, suspend, or accept a given vendor's residual risk, remains a human decision made by a named risk owner, with the AI-assembled evidence trail supporting that decision.

Vendor Cyber Risk Continuous Monitoring Vulnerability Management AI Risk Intelligence Third Party Risk Management