Vendor Pain Index โ€” Q1 2026 vs Q2 2026

๐Ÿฆ… Vendor Pain Index โ€” Q1 2026 vs Q2 2026

A quarter-over-quarter comparison of vendor security performance across three lenses: Revenue, R&D Spend, and Employees.

Each Pain Index is calculated as (CRITICAL ร— 3 + HIGH ร— 1) รท normalizer. A higher index means more security pain per unit โ€” lower is better. Vendors with zero HIGH/CRITICAL CVEs in a given quarter are marked โœ….


๐Ÿ“ Editorial

Every quarter, vendors publish advisories, security bulletins and vulnerability disclosures. Security teams are expected to read them, understand them and somehow decide what deserves attention.

The problem is simple: there is too much information and too little time.

WSIC started as a personal project to deal with that reality.

After many years in infrastructure, networking and security, I found myself spending more time filtering information than acting on it. Hundreds of advisories, CVEs, vendor bulletins and release notes compete for attention every week. Most are worth knowing. Some are worth acting on. A few will ruin your weekend.

WSIC was created to help tell the difference. The daily briefings focus on a single question: Why Should I Care?

The Vendor Pain Index applies the same thinking to vendors.

Rather than counting vulnerabilities in isolation, the goal is to explore a broader question: which vendors generate disproportionately high amounts of operational security work relative to their size and resources?

The answer is not always obvious. A vendor may report hundreds of vulnerabilities and still perform reasonably well once revenue, R&D spending or workforce size are taken into account. Others may report relatively few vulnerabilities but rank poorly after normalization.

This report is therefore not a measure of vendor quality.
It is not a buyer's guide.
It is not investment advice.
It is not an attempt to name and shame.
It is simply an experiment in looking at security data from a different angle.

A known limitation worth naming

The formula counts CVEs at the point of public disclosure โ€” not at the point of patching. This creates a subtle distortion. A vendor that practises responsible coordinated disclosure โ€” fixing a vulnerability privately first, then disclosing after customers have had time to patch โ€” may appear to release many CVEs in a single quarter. That is not the same as a vendor that leaves known vulnerabilities unpatched for months before acting.

We are aware of this. Monitoring trends over multiple quarters will help distinguish between disclosure patterns and genuine security posture. A single bad quarter can have many explanations. A consistently high Pain Index across quarters is harder to explain away.

A note on humility

We did not arrive at this methodology with all the answers. The formulas are a starting point, not a conclusion. Some readers will disagree with the weighting. Others will suggest better normalizers. That is exactly the kind of conversation we want to start.

The methodology will evolve. We will get things wrong. We will correct them.

If this report starts discussions about how we measure software quality, engineering effectiveness and security outcomes, then it has already achieved its goal.

After all, the purpose of WSIC is not to provide answers. The purpose is to help ask better questions.

๐Ÿฆ… Built by an engineer who got tired of reading 200 security alerts a day and discovering breaking changes hidden in release notes.


๐Ÿฆ… Key Findings

  • The biggest mover in Q2 was Progress Software, which jumped from a pain score of 1.0000 in Q1 to 21.0000, a staggering increase of +20.0000. This dramatic shift in the Vendor Pain Index (VPI) highlights the company's rapid growth and potential challenges in maintaining quality under increased pressure.
  • Microsoft and Google stood out as raw volume outliers in Q2, with Microsoft reporting 40 CRIT and 100 HIGH CVEs, while Google had 26 CRIT and 37 HIGH vulnerabilities. These numbers underscore the ongoing struggle to secure complex software ecosystems.
  • GitLab demonstrated cross-metric consistency by improving its pain scores across all three metrics (revenue, R&D spend, and employees) in Q2, with reductions of +5.0000, -18.5185, and -1.9231, respectively. This improvement suggests the company is making strides to address its weaknesses.
  • Progress Software's deteriorated pain scores across all three metrics (revenue, R&D spend, and employees) in Q2 are concerning, with increases of +20.0000, +105.2631, and +7.1429, respectively. This trend may indicate a need for closer monitoring to prevent a decline in overall security posture.
  • The Vendor Pain Index's findings highlight the importance of considering multiple metrics when evaluating vendor performance. By examining revenue, R&D spend, and employee pain scores together, IT decision-makers can gain a more comprehensive understanding of a vendor's strengths and weaknesses.

๐Ÿ“Š Quarterly Analysis

Overall, Q2 saw a mixed bag of performance from the vendors in our latest Vendor Pain Index report. GitLab, once again, emerged as the leader across all three metrics, but Progress Software's woes only intensified. The most improved vendor, GitLab, showed significant improvement in both revenue and R&D spend, while Progress Software's decline was stark โ€“ a trend we hope they will address soon.

In terms of Revenue, GitLab has solidified its position as the leader, with a pain score of 5.0000 in Q2, down from 10.0000 in Q1. This significant improvement suggests that GitLab is making efforts to streamline their operations and reduce the risk of security breaches. Progress Software, on the other hand, saw its revenue-related pain increase by 16 times, indicating a major issue with their financial management and potentially exposing them to increased cybersecurity risks.

The R&D spend metric also showed GitLab's improvement, with a score of 18.5185 in Q2, down from 37.0370 in Q1. This reduction suggests that GitLab is investing more effectively in security research and development, allowing them to stay ahead of emerging threats. In contrast, Progress Software's R&D spend-related pain increased by over 100 times, indicating a lack of investment in cybersecurity capabilities.

Employees was the metric where GitLab continued its dominance, with a score of 1.9231 in Q2, down from 3.8462 in Q1. This improvement suggests that GitLab has made strides in hiring and training security talent, allowing them to better protect their customers' data. Progress Software's employees-related pain increased by over 20 times, indicating significant issues with employee vetting, onboarding, or training โ€“ all critical components of a robust cybersecurity program.

As IT decision-makers review the Vendor Pain Index report, two key takeaways stand out: invest in vendors that demonstrate a commitment to security, and address vulnerabilities quickly. GitLab's continued leadership suggests they are doing something right, but Progress Software's decline is a stark warning โ€“ don't wait until it's too late.


๐Ÿ“Š Pain by Revenue

๐Ÿ”„ New Leader: Progress Software โ€” takes the top spot in Q2 2026 with a Pain Index of 21.0000, displacing GitLab (10.0000 in Q1 2026).

๐ŸŸข Most Improved: GitLab โ€” Pain Index dropped from 10.0000 (Q1 2026) to 5.0000 (Q2 2026) โ€” a change of -5.0000.

๐Ÿ”ด Most Deteriorated: Progress Software โ€” Pain Index rose from 1.0000 (Q1 2026) to 21.0000 (Q2 2026) โ€” a change of +20.0000.

๐ŸŸ  Q2 2026 (current quarter)

#VendorTickerCRITICALHIGHKEV ๐Ÿ”ฅPain Index
1Progress SoftwarePRGS312True21.0000
2Rapid7RPD012โ€”13.9535
3GitLabGTLB05โ€”5.0000
4Palo Alto NetworksPANW826True4.7125
5TenableTENB03โ€”2.8846
6FortinetFTNT48โ€”2.6560
7ElasticESTC04โ€”2.2989
8N-ableNABL01โ€”1.8868
9MongoDBMDB04โ€”1.5385
10IBMIBM478True1.3026
11AdobeADBE78โ€”1.1508
12HPEHPE616โ€”0.8765
13MicrosoftMSFT40100True0.6630
14F5FFIV02โ€”0.6042
15GoogleGOOGL2637โ€”0.2579
16DellDELL129โ€”0.2388
17Broadcom/VMwareAVGO016โ€”0.2120
18ZoomZM01โ€”0.2028
19AppleAAPL1538โ€”0.1778
20Juniper/HPEHPQ14โ€”0.1219
21CiscoCSCO12โ€”0.0823
22OracleORCL02โ€”0.0297
23Amazon/AWSAMZN01โ€”0.0013

๐Ÿ“ Q1 2026 (previous quarter, for reference)

#VendorTickerCRITICALHIGHKEV ๐Ÿ”ฅPain Index
1GitLabGTLB010โ€”10.0000
2ElasticESTC06โ€”3.4483
3MongoDBMDB04โ€”1.5385
4Progress SoftwarePRGS01โ€”1.0000
5TenableTENB01โ€”0.9615
6ZscalerZS10โ€”0.9464
7IBMIBM258โ€”0.9263
8ZoomZM11โ€”0.8114
9FortinetFTNT06โ€”0.7968
10HPEHPE223โ€”0.7476
11AtlassianTEAM10โ€”0.4566
12SAPSAP44โ€”0.4190
13MicrosoftMSFT1465True0.3224
14Broadcom/VMwareAVGO215โ€”0.2783
15ServiceNowNOW10โ€”0.2037
16DellDELL116True0.1418
17GoogleGOOGL838True0.1391
18AppleAAPL636True0.1157
19CiscoCSCO14True0.1152
20Palo Alto NetworksPANW01โ€”0.0943
21SalesforceCRM10โ€”0.0700
22OracleORCL01โ€”0.0148

๐Ÿ“Š Pain by R&D Spend

๐Ÿ”„ New Leader: Progress Software โ€” takes the top spot in Q2 2026 with a Pain Index of 110.5263, displacing GitLab (37.0370 in Q1 2026).

๐ŸŸข Most Improved: GitLab โ€” Pain Index dropped from 37.0370 (Q1 2026) to 18.5185 (Q2 2026) โ€” a change of -18.5185.

๐Ÿ”ด Most Deteriorated: Progress Software โ€” Pain Index rose from 5.2632 (Q1 2026) to 110.5263 (Q2 2026) โ€” a change of +105.2631.

๐ŸŸ  Q2 2026 (current quarter)

#VendorTickerCRITICALHIGHKEV ๐Ÿ”ฅPain Index
1Progress SoftwarePRGS312True110.5263
2Rapid7RPD012โ€”63.1579
3Palo Alto NetworksPANW826True25.2525
4FortinetFTNT48โ€”24.3902
5GitLabGTLB05โ€”18.5185
6TenableTENB03โ€”13.6364
7HPEHPE616โ€”13.4921
8IBMIBM478True10.8173
9DellDELL129โ€”10.1911
10N-ableNABL01โ€”10.0000
11ElasticESTC04โ€”8.8889
12AdobeADBE78โ€”6.7599
13MicrosoftMSFT40100True6.1867
14MongoDBMDB04โ€”5.5556
15Juniper/HPEHPQ14โ€”4.3750
16F5FFIV02โ€”3.7037
17AppleAAPL1538โ€”2.4023
18GoogleGOOGL2637โ€”1.8825
19Broadcom/VMwareAVGO016โ€”1.4572
20ZoomZM01โ€”1.1905
21CiscoCSCO12โ€”0.5376
22OracleORCL02โ€”0.1947

๐Ÿ“ Q1 2026 (previous quarter, for reference)

#VendorTickerCRITICALHIGHKEV ๐Ÿ”ฅPain Index
1GitLabGTLB010โ€”37.0370
2ElasticESTC06โ€”13.3333
3HPEHPE223โ€”11.5079
4IBMIBM258โ€”7.6923
5FortinetFTNT06โ€”7.3171
6DellDELL116True6.0510
7MongoDBMDB04โ€”5.5556
8Progress SoftwarePRGS01โ€”5.2632
9ZoomZM11โ€”4.7619
10TenableTENB01โ€”4.5455
11ZscalerZS10โ€”4.4776
12MicrosoftMSFT1465True3.0090
13SAPSAP44โ€”2.4133
14Broadcom/VMwareAVGO215โ€”1.9126
15AppleAAPL636True1.5630
16GoogleGOOGL838True1.0149
17ServiceNowNOW10โ€”1.0135
18CiscoCSCO14True0.7527
19Palo Alto NetworksPANW01โ€”0.5051
20SalesforceCRM10โ€”0.5008
21OracleORCL01โ€”0.0974

๐Ÿ“Š Pain by Employees

๐Ÿ”„ New Leader: Progress Software โ€” takes the top spot in Q2 2026 with a Pain Index of 7.5000, displacing GitLab (3.8462 in Q1 2026).

๐ŸŸข Most Improved: GitLab โ€” Pain Index dropped from 3.8462 (Q1 2026) to 1.9231 (Q2 2026) โ€” a change of -1.9231.

๐Ÿ”ด Most Deteriorated: Progress Software โ€” Pain Index rose from 0.3571 (Q1 2026) to 7.5000 (Q2 2026) โ€” a change of +7.1429.

๐ŸŸ  Q2 2026 (current quarter)

#VendorTickerCRITICALHIGHKEV ๐Ÿ”ฅPain Index
1Progress SoftwarePRGS312True7.5000
2Rapid7RPD012โ€”4.6154
3Palo Alto NetworksPANW826True2.3256
4GitLabGTLB05โ€”1.9231
5TenableTENB03โ€”1.5000
6FortinetFTNT48โ€”1.2903
7ElasticESTC04โ€”1.0000
8MicrosoftMSFT40100True0.9865
9AdobeADBE78โ€”0.9236
10MongoDBMDB04โ€”0.7143
11GoogleGOOGL2637โ€”0.5782
12AppleAAPL1538โ€”0.5533
13N-ableNABL01โ€”0.5263
14HPEHPE616โ€”0.5075
15Broadcom/VMwareAVGO016โ€”0.4848
16IBMIBM478True0.3405
17DellDELL129โ€”0.3299
18F5FFIV02โ€”0.3077
19ZoomZM01โ€”0.1351
20Juniper/HPEHPQ14โ€”0.1273
21CiscoCSCO12โ€”0.0580
22OracleORCL02โ€”0.0142
23Amazon/AWSAMZN01โ€”0.0006

๐Ÿ“ Q1 2026 (previous quarter, for reference)

#VendorTickerCRITICALHIGHKEV ๐Ÿ”ฅPain Index
1GitLabGTLB010โ€”3.8462
2ElasticESTC06โ€”1.5000
3MongoDBMDB04โ€”0.7143
4Broadcom/VMwareAVGO215โ€”0.6364
5ZoomZM11โ€”0.5405
6TenableTENB01โ€”0.5000
7MicrosoftMSFT1465True0.4798
8HPEHPE223โ€”0.4328
9FortinetFTNT06โ€”0.3871
10ZscalerZS10โ€”0.3797
11AppleAAPL636True0.3600
12Progress SoftwarePRGS01โ€”0.3571
13GoogleGOOGL838True0.3117
14IBMIBM258โ€”0.2421
15DellDELL116True0.1959
16SAPSAP44โ€”0.1429
17ServiceNowNOW10โ€”0.1027
18CiscoCSCO14True0.0812
19Palo Alto NetworksPANW01โ€”0.0465
20SalesforceCRM10โ€”0.0360
21OracleORCL01โ€”0.0071

๐Ÿฆ… Vendor Pain Index by Donna AI  |  Data: NVD ยท CISA KEV ยท Yahoo Finance
Pain Index = (CRITICAL ร— 3 + HIGH ร— 1) รท normalizer. CRITICAL = CVSSv3 โ‰ฅ 9.0 ยท HIGH = CVSSv3 7.0โ€“8.9


๐Ÿ“‹ Complete Monitoring Scope โ€” Q2 2026

The following vendors and projects are tracked every quarter. Inclusion in the ranked tables requires a public stock listing with available financial data. Everything else is listed here for transparency.

โœ… Zero HIGH/CRITICAL CVEs this quarter โ€” Public vendors

These vendors had no HIGH or CRITICAL CVEs published in NVD during this quarter. A clean quarter does not guarantee a clean posture โ€” but it is worth acknowledging.

Atlassian ยท Check Point ยท CrowdStrike ยท Okta ยท Qualys ยท SAP ยท Salesforce ยท SentinelOne ยท ServiceNow ยท Zscaler

โš ๏ธ Private vendors โ€” monitored, no financial data

These vendors are tracked but cannot be included in normalized rankings because financial data is not publicly available. CVE counts are monitored.

Cloud Software Grp ยท ConnectWise ยท Ivanti ยท SolarWinds ยท WatchGuard

๐Ÿ”“ Open source projects โ€” monitored, no financial data

Open source projects are widely deployed in enterprise infrastructure. They are tracked because their vulnerabilities matter โ€” but without revenue, R&D spend or headcount to normalize against, they cannot be ranked alongside commercial vendors. A separate analysis may be warranted in a future edition.

๐Ÿ’ก A note on open source and enterprise responsibility.
These CVEs represent real work: real researchers finding real bugs, real developers fixing them, often without pay. If your organization runs on open source and has never contributed back, this is a good moment to reconsider. Better-funded open source is more secure open source. Consider donating or sponsoring the projects your infrastructure depends on.

โš ๏ธ Private & Commercial Vendors โ€” Q1 2026 vs Q2 2026

No public financial data โ€” Pain Index cannot be calculated. Absolute CVE counts only. Score = CRITICAL ร— 3 + HIGH.

VendorQ1 CRITQ1 HIGHQ1 ScoreQ2 CRITQ2 HIGHQ2 ScoreTrend
Cloud Software Grp1032410๐Ÿ”ด Worse
ConnectWise309000๐ŸŸข Better
Ivanti011147๐Ÿ”ด Worse
SolarWinds4315011๐ŸŸข Better
WatchGuard011033๐Ÿ”ด Worse

๐Ÿ”“ Open Source Projects โ€” Q1 2026 vs Q2 2026

No financial normalization possible. Score = CRITICAL ร— 3 + HIGH.

VendorQ1 CRITQ1 HIGHQ1 ScoreQ2 CRITQ2 HIGHQ2 ScoreTrend
Apache (OSS)4820132059๐Ÿ”ด Worse
Canonical0111710๐Ÿ”ด Worse
Linux (kernel)2615223015253298๐Ÿ”ด Worse
Mozilla62252114012๐ŸŸข Better
Redis000055๐Ÿ”ด Worse

๐Ÿ“š Sources & Methodology

  • CVE Data: NIST NVD API v2.0 โ€” official U.S. government repository. Every CVE is counted once. Severity based on CVSSv3 base score (HIGH: 7.0โ€“8.9 ยท CRITICAL: โ‰ฅ9.0).
  • Actively Exploited (๐Ÿ”ฅ): CISA KEV Catalog โ€” confirmed active exploitation in the wild.
  • Company Metrics: Yahoo Finance via yfinance โ€” point-in-time snapshot. Revenue and R&D are TTM from the most recent annual filing. Employee count as reported in the latest annual filing.
  • Pain Index Formula: (CRITICAL ร— 3 + HIGH ร— 1) รท Normalizer. CRITICAL weighted 3ร— to reflect higher exploitability and impact.
  • Three Lenses: Revenue, R&D Spend, Employees โ€” each normalizer tells a different story. Vendors that rank poorly across all three have a harder case to make.
  • Private vendors (no stock ticker) are excluded from ranked tables โ€” financial data not publicly available. Listed separately for completeness.

Read more

Why Should I Care? โ€” 2026-09-24 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-24 27 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 15 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-23 | ๐Ÿ”ด 5 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-23 35 vendor intel items scanned ย |ย  ๐Ÿ”ด 5 HIGH ย |ย  ๐ŸŸก 3 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-22 | ๐Ÿ”ด 1 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 17 RADAR ยท โšช 66 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-22 18 vendor intel items scanned ย |ย  ๐Ÿ”ด 1 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 17 RADAR ย |ย  โšช 66 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-21 | ๐Ÿ”ด 23 HIGH ยท ๐ŸŸก 32 MEDIUM ยท ๐Ÿ”ต 209 RADAR ยท โšช 73 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-21 264 vendor intel items scanned ย |ย  ๐Ÿ”ด 23 HIGH ย |ย  ๐ŸŸก 32 MEDIUM ย |ย  ๐Ÿ”ต 209 RADAR ย |ย  โšช 73 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) โ€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic