Vendor Pain Index โ Q1 2026 vs Q2 2026
๐ฆ Vendor Pain Index โ Q1 2026 vs Q2 2026
A quarter-over-quarter comparison of vendor security performance across three lenses: Revenue, R&D Spend, and Employees.
Each Pain Index is calculated as (CRITICAL ร 3 + HIGH ร 1) รท normalizer. A higher index means more security pain per unit โ lower is better. Vendors with zero HIGH/CRITICAL CVEs in a given quarter are marked โ
.
๐ Editorial
Every quarter, vendors publish advisories, security bulletins and vulnerability disclosures. Security teams are expected to read them, understand them and somehow decide what deserves attention.
The problem is simple: there is too much information and too little time.
WSIC started as a personal project to deal with that reality.
After many years in infrastructure, networking and security, I found myself spending more time filtering information than acting on it. Hundreds of advisories, CVEs, vendor bulletins and release notes compete for attention every week. Most are worth knowing. Some are worth acting on. A few will ruin your weekend.
WSIC was created to help tell the difference. The daily briefings focus on a single question: Why Should I Care?
The Vendor Pain Index applies the same thinking to vendors.
Rather than counting vulnerabilities in isolation, the goal is to explore a broader question: which vendors generate disproportionately high amounts of operational security work relative to their size and resources?
The answer is not always obvious. A vendor may report hundreds of vulnerabilities and still perform reasonably well once revenue, R&D spending or workforce size are taken into account. Others may report relatively few vulnerabilities but rank poorly after normalization.
This report is therefore not a measure of vendor quality.
It is not a buyer's guide.
It is not investment advice.
It is not an attempt to name and shame.
It is simply an experiment in looking at security data from a different angle.
A known limitation worth naming
The formula counts CVEs at the point of public disclosure โ not at the point of patching. This creates a subtle distortion. A vendor that practises responsible coordinated disclosure โ fixing a vulnerability privately first, then disclosing after customers have had time to patch โ may appear to release many CVEs in a single quarter. That is not the same as a vendor that leaves known vulnerabilities unpatched for months before acting.
We are aware of this. Monitoring trends over multiple quarters will help distinguish between disclosure patterns and genuine security posture. A single bad quarter can have many explanations. A consistently high Pain Index across quarters is harder to explain away.
A note on humility
We did not arrive at this methodology with all the answers. The formulas are a starting point, not a conclusion. Some readers will disagree with the weighting. Others will suggest better normalizers. That is exactly the kind of conversation we want to start.
The methodology will evolve. We will get things wrong. We will correct them.
If this report starts discussions about how we measure software quality, engineering effectiveness and security outcomes, then it has already achieved its goal.
After all, the purpose of WSIC is not to provide answers. The purpose is to help ask better questions.
๐ฆ Built by an engineer who got tired of reading 200 security alerts a day and discovering breaking changes hidden in release notes.
๐ฆ Key Findings
- The biggest mover in Q2 was Progress Software, which jumped from a pain score of 1.0000 in Q1 to 21.0000, a staggering increase of +20.0000. This dramatic shift in the Vendor Pain Index (VPI) highlights the company's rapid growth and potential challenges in maintaining quality under increased pressure.
- Microsoft and Google stood out as raw volume outliers in Q2, with Microsoft reporting 40 CRIT and 100 HIGH CVEs, while Google had 26 CRIT and 37 HIGH vulnerabilities. These numbers underscore the ongoing struggle to secure complex software ecosystems.
- GitLab demonstrated cross-metric consistency by improving its pain scores across all three metrics (revenue, R&D spend, and employees) in Q2, with reductions of +5.0000, -18.5185, and -1.9231, respectively. This improvement suggests the company is making strides to address its weaknesses.
- Progress Software's deteriorated pain scores across all three metrics (revenue, R&D spend, and employees) in Q2 are concerning, with increases of +20.0000, +105.2631, and +7.1429, respectively. This trend may indicate a need for closer monitoring to prevent a decline in overall security posture.
- The Vendor Pain Index's findings highlight the importance of considering multiple metrics when evaluating vendor performance. By examining revenue, R&D spend, and employee pain scores together, IT decision-makers can gain a more comprehensive understanding of a vendor's strengths and weaknesses.
๐ Quarterly Analysis
Overall, Q2 saw a mixed bag of performance from the vendors in our latest Vendor Pain Index report. GitLab, once again, emerged as the leader across all three metrics, but Progress Software's woes only intensified. The most improved vendor, GitLab, showed significant improvement in both revenue and R&D spend, while Progress Software's decline was stark โ a trend we hope they will address soon.
In terms of Revenue, GitLab has solidified its position as the leader, with a pain score of 5.0000 in Q2, down from 10.0000 in Q1. This significant improvement suggests that GitLab is making efforts to streamline their operations and reduce the risk of security breaches. Progress Software, on the other hand, saw its revenue-related pain increase by 16 times, indicating a major issue with their financial management and potentially exposing them to increased cybersecurity risks.
The R&D spend metric also showed GitLab's improvement, with a score of 18.5185 in Q2, down from 37.0370 in Q1. This reduction suggests that GitLab is investing more effectively in security research and development, allowing them to stay ahead of emerging threats. In contrast, Progress Software's R&D spend-related pain increased by over 100 times, indicating a lack of investment in cybersecurity capabilities.
Employees was the metric where GitLab continued its dominance, with a score of 1.9231 in Q2, down from 3.8462 in Q1. This improvement suggests that GitLab has made strides in hiring and training security talent, allowing them to better protect their customers' data. Progress Software's employees-related pain increased by over 20 times, indicating significant issues with employee vetting, onboarding, or training โ all critical components of a robust cybersecurity program.
As IT decision-makers review the Vendor Pain Index report, two key takeaways stand out: invest in vendors that demonstrate a commitment to security, and address vulnerabilities quickly. GitLab's continued leadership suggests they are doing something right, but Progress Software's decline is a stark warning โ don't wait until it's too late.
๐ Pain by Revenue
๐ New Leader: Progress Software โ takes the top spot in Q2 2026 with a Pain Index of 21.0000, displacing GitLab (10.0000 in Q1 2026).
๐ข Most Improved: GitLab โ Pain Index dropped from 10.0000 (Q1 2026) to 5.0000 (Q2 2026) โ a change of -5.0000.
๐ด Most Deteriorated: Progress Software โ Pain Index rose from 1.0000 (Q1 2026) to 21.0000 (Q2 2026) โ a change of +20.0000.
๐ Q2 2026 (current quarter)
| # | Vendor | Ticker | CRITICAL | HIGH | KEV ๐ฅ | Pain Index |
|---|---|---|---|---|---|---|
| 1 | Progress Software | PRGS | 3 | 12 | True | 21.0000 |
| 2 | Rapid7 | RPD | 0 | 12 | โ | 13.9535 |
| 3 | GitLab | GTLB | 0 | 5 | โ | 5.0000 |
| 4 | Palo Alto Networks | PANW | 8 | 26 | True | 4.7125 |
| 5 | Tenable | TENB | 0 | 3 | โ | 2.8846 |
| 6 | Fortinet | FTNT | 4 | 8 | โ | 2.6560 |
| 7 | Elastic | ESTC | 0 | 4 | โ | 2.2989 |
| 8 | N-able | NABL | 0 | 1 | โ | 1.8868 |
| 9 | MongoDB | MDB | 0 | 4 | โ | 1.5385 |
| 10 | IBM | IBM | 4 | 78 | True | 1.3026 |
| 11 | Adobe | ADBE | 7 | 8 | โ | 1.1508 |
| 12 | HPE | HPE | 6 | 16 | โ | 0.8765 |
| 13 | Microsoft | MSFT | 40 | 100 | True | 0.6630 |
| 14 | F5 | FFIV | 0 | 2 | โ | 0.6042 |
| 15 | GOOGL | 26 | 37 | โ | 0.2579 | |
| 16 | Dell | DELL | 1 | 29 | โ | 0.2388 |
| 17 | Broadcom/VMware | AVGO | 0 | 16 | โ | 0.2120 |
| 18 | Zoom | ZM | 0 | 1 | โ | 0.2028 |
| 19 | Apple | AAPL | 15 | 38 | โ | 0.1778 |
| 20 | Juniper/HPE | HPQ | 1 | 4 | โ | 0.1219 |
| 21 | Cisco | CSCO | 1 | 2 | โ | 0.0823 |
| 22 | Oracle | ORCL | 0 | 2 | โ | 0.0297 |
| 23 | Amazon/AWS | AMZN | 0 | 1 | โ | 0.0013 |
๐ Q1 2026 (previous quarter, for reference)
| # | Vendor | Ticker | CRITICAL | HIGH | KEV ๐ฅ | Pain Index |
|---|---|---|---|---|---|---|
| 1 | GitLab | GTLB | 0 | 10 | โ | 10.0000 |
| 2 | Elastic | ESTC | 0 | 6 | โ | 3.4483 |
| 3 | MongoDB | MDB | 0 | 4 | โ | 1.5385 |
| 4 | Progress Software | PRGS | 0 | 1 | โ | 1.0000 |
| 5 | Tenable | TENB | 0 | 1 | โ | 0.9615 |
| 6 | Zscaler | ZS | 1 | 0 | โ | 0.9464 |
| 7 | IBM | IBM | 2 | 58 | โ | 0.9263 |
| 8 | Zoom | ZM | 1 | 1 | โ | 0.8114 |
| 9 | Fortinet | FTNT | 0 | 6 | โ | 0.7968 |
| 10 | HPE | HPE | 2 | 23 | โ | 0.7476 |
| 11 | Atlassian | TEAM | 1 | 0 | โ | 0.4566 |
| 12 | SAP | SAP | 4 | 4 | โ | 0.4190 |
| 13 | Microsoft | MSFT | 14 | 65 | True | 0.3224 |
| 14 | Broadcom/VMware | AVGO | 2 | 15 | โ | 0.2783 |
| 15 | ServiceNow | NOW | 1 | 0 | โ | 0.2037 |
| 16 | Dell | DELL | 1 | 16 | True | 0.1418 |
| 17 | GOOGL | 8 | 38 | True | 0.1391 | |
| 18 | Apple | AAPL | 6 | 36 | True | 0.1157 |
| 19 | Cisco | CSCO | 1 | 4 | True | 0.1152 |
| 20 | Palo Alto Networks | PANW | 0 | 1 | โ | 0.0943 |
| 21 | Salesforce | CRM | 1 | 0 | โ | 0.0700 |
| 22 | Oracle | ORCL | 0 | 1 | โ | 0.0148 |
๐ Pain by R&D Spend
๐ New Leader: Progress Software โ takes the top spot in Q2 2026 with a Pain Index of 110.5263, displacing GitLab (37.0370 in Q1 2026).
๐ข Most Improved: GitLab โ Pain Index dropped from 37.0370 (Q1 2026) to 18.5185 (Q2 2026) โ a change of -18.5185.
๐ด Most Deteriorated: Progress Software โ Pain Index rose from 5.2632 (Q1 2026) to 110.5263 (Q2 2026) โ a change of +105.2631.
๐ Q2 2026 (current quarter)
| # | Vendor | Ticker | CRITICAL | HIGH | KEV ๐ฅ | Pain Index |
|---|---|---|---|---|---|---|
| 1 | Progress Software | PRGS | 3 | 12 | True | 110.5263 |
| 2 | Rapid7 | RPD | 0 | 12 | โ | 63.1579 |
| 3 | Palo Alto Networks | PANW | 8 | 26 | True | 25.2525 |
| 4 | Fortinet | FTNT | 4 | 8 | โ | 24.3902 |
| 5 | GitLab | GTLB | 0 | 5 | โ | 18.5185 |
| 6 | Tenable | TENB | 0 | 3 | โ | 13.6364 |
| 7 | HPE | HPE | 6 | 16 | โ | 13.4921 |
| 8 | IBM | IBM | 4 | 78 | True | 10.8173 |
| 9 | Dell | DELL | 1 | 29 | โ | 10.1911 |
| 10 | N-able | NABL | 0 | 1 | โ | 10.0000 |
| 11 | Elastic | ESTC | 0 | 4 | โ | 8.8889 |
| 12 | Adobe | ADBE | 7 | 8 | โ | 6.7599 |
| 13 | Microsoft | MSFT | 40 | 100 | True | 6.1867 |
| 14 | MongoDB | MDB | 0 | 4 | โ | 5.5556 |
| 15 | Juniper/HPE | HPQ | 1 | 4 | โ | 4.3750 |
| 16 | F5 | FFIV | 0 | 2 | โ | 3.7037 |
| 17 | Apple | AAPL | 15 | 38 | โ | 2.4023 |
| 18 | GOOGL | 26 | 37 | โ | 1.8825 | |
| 19 | Broadcom/VMware | AVGO | 0 | 16 | โ | 1.4572 |
| 20 | Zoom | ZM | 0 | 1 | โ | 1.1905 |
| 21 | Cisco | CSCO | 1 | 2 | โ | 0.5376 |
| 22 | Oracle | ORCL | 0 | 2 | โ | 0.1947 |
๐ Q1 2026 (previous quarter, for reference)
| # | Vendor | Ticker | CRITICAL | HIGH | KEV ๐ฅ | Pain Index |
|---|---|---|---|---|---|---|
| 1 | GitLab | GTLB | 0 | 10 | โ | 37.0370 |
| 2 | Elastic | ESTC | 0 | 6 | โ | 13.3333 |
| 3 | HPE | HPE | 2 | 23 | โ | 11.5079 |
| 4 | IBM | IBM | 2 | 58 | โ | 7.6923 |
| 5 | Fortinet | FTNT | 0 | 6 | โ | 7.3171 |
| 6 | Dell | DELL | 1 | 16 | True | 6.0510 |
| 7 | MongoDB | MDB | 0 | 4 | โ | 5.5556 |
| 8 | Progress Software | PRGS | 0 | 1 | โ | 5.2632 |
| 9 | Zoom | ZM | 1 | 1 | โ | 4.7619 |
| 10 | Tenable | TENB | 0 | 1 | โ | 4.5455 |
| 11 | Zscaler | ZS | 1 | 0 | โ | 4.4776 |
| 12 | Microsoft | MSFT | 14 | 65 | True | 3.0090 |
| 13 | SAP | SAP | 4 | 4 | โ | 2.4133 |
| 14 | Broadcom/VMware | AVGO | 2 | 15 | โ | 1.9126 |
| 15 | Apple | AAPL | 6 | 36 | True | 1.5630 |
| 16 | GOOGL | 8 | 38 | True | 1.0149 | |
| 17 | ServiceNow | NOW | 1 | 0 | โ | 1.0135 |
| 18 | Cisco | CSCO | 1 | 4 | True | 0.7527 |
| 19 | Palo Alto Networks | PANW | 0 | 1 | โ | 0.5051 |
| 20 | Salesforce | CRM | 1 | 0 | โ | 0.5008 |
| 21 | Oracle | ORCL | 0 | 1 | โ | 0.0974 |
๐ Pain by Employees
๐ New Leader: Progress Software โ takes the top spot in Q2 2026 with a Pain Index of 7.5000, displacing GitLab (3.8462 in Q1 2026).
๐ข Most Improved: GitLab โ Pain Index dropped from 3.8462 (Q1 2026) to 1.9231 (Q2 2026) โ a change of -1.9231.
๐ด Most Deteriorated: Progress Software โ Pain Index rose from 0.3571 (Q1 2026) to 7.5000 (Q2 2026) โ a change of +7.1429.
๐ Q2 2026 (current quarter)
| # | Vendor | Ticker | CRITICAL | HIGH | KEV ๐ฅ | Pain Index |
|---|---|---|---|---|---|---|
| 1 | Progress Software | PRGS | 3 | 12 | True | 7.5000 |
| 2 | Rapid7 | RPD | 0 | 12 | โ | 4.6154 |
| 3 | Palo Alto Networks | PANW | 8 | 26 | True | 2.3256 |
| 4 | GitLab | GTLB | 0 | 5 | โ | 1.9231 |
| 5 | Tenable | TENB | 0 | 3 | โ | 1.5000 |
| 6 | Fortinet | FTNT | 4 | 8 | โ | 1.2903 |
| 7 | Elastic | ESTC | 0 | 4 | โ | 1.0000 |
| 8 | Microsoft | MSFT | 40 | 100 | True | 0.9865 |
| 9 | Adobe | ADBE | 7 | 8 | โ | 0.9236 |
| 10 | MongoDB | MDB | 0 | 4 | โ | 0.7143 |
| 11 | GOOGL | 26 | 37 | โ | 0.5782 | |
| 12 | Apple | AAPL | 15 | 38 | โ | 0.5533 |
| 13 | N-able | NABL | 0 | 1 | โ | 0.5263 |
| 14 | HPE | HPE | 6 | 16 | โ | 0.5075 |
| 15 | Broadcom/VMware | AVGO | 0 | 16 | โ | 0.4848 |
| 16 | IBM | IBM | 4 | 78 | True | 0.3405 |
| 17 | Dell | DELL | 1 | 29 | โ | 0.3299 |
| 18 | F5 | FFIV | 0 | 2 | โ | 0.3077 |
| 19 | Zoom | ZM | 0 | 1 | โ | 0.1351 |
| 20 | Juniper/HPE | HPQ | 1 | 4 | โ | 0.1273 |
| 21 | Cisco | CSCO | 1 | 2 | โ | 0.0580 |
| 22 | Oracle | ORCL | 0 | 2 | โ | 0.0142 |
| 23 | Amazon/AWS | AMZN | 0 | 1 | โ | 0.0006 |
๐ Q1 2026 (previous quarter, for reference)
| # | Vendor | Ticker | CRITICAL | HIGH | KEV ๐ฅ | Pain Index |
|---|---|---|---|---|---|---|
| 1 | GitLab | GTLB | 0 | 10 | โ | 3.8462 |
| 2 | Elastic | ESTC | 0 | 6 | โ | 1.5000 |
| 3 | MongoDB | MDB | 0 | 4 | โ | 0.7143 |
| 4 | Broadcom/VMware | AVGO | 2 | 15 | โ | 0.6364 |
| 5 | Zoom | ZM | 1 | 1 | โ | 0.5405 |
| 6 | Tenable | TENB | 0 | 1 | โ | 0.5000 |
| 7 | Microsoft | MSFT | 14 | 65 | True | 0.4798 |
| 8 | HPE | HPE | 2 | 23 | โ | 0.4328 |
| 9 | Fortinet | FTNT | 0 | 6 | โ | 0.3871 |
| 10 | Zscaler | ZS | 1 | 0 | โ | 0.3797 |
| 11 | Apple | AAPL | 6 | 36 | True | 0.3600 |
| 12 | Progress Software | PRGS | 0 | 1 | โ | 0.3571 |
| 13 | GOOGL | 8 | 38 | True | 0.3117 | |
| 14 | IBM | IBM | 2 | 58 | โ | 0.2421 |
| 15 | Dell | DELL | 1 | 16 | True | 0.1959 |
| 16 | SAP | SAP | 4 | 4 | โ | 0.1429 |
| 17 | ServiceNow | NOW | 1 | 0 | โ | 0.1027 |
| 18 | Cisco | CSCO | 1 | 4 | True | 0.0812 |
| 19 | Palo Alto Networks | PANW | 0 | 1 | โ | 0.0465 |
| 20 | Salesforce | CRM | 1 | 0 | โ | 0.0360 |
| 21 | Oracle | ORCL | 0 | 1 | โ | 0.0071 |
๐ฆ
Vendor Pain Index by Donna AI | Data: NVD ยท CISA KEV ยท Yahoo Finance
Pain Index = (CRITICAL ร 3 + HIGH ร 1) รท normalizer. CRITICAL = CVSSv3 โฅ 9.0 ยท HIGH = CVSSv3 7.0โ8.9
๐ Complete Monitoring Scope โ Q2 2026
The following vendors and projects are tracked every quarter. Inclusion in the ranked tables requires a public stock listing with available financial data. Everything else is listed here for transparency.
โ Zero HIGH/CRITICAL CVEs this quarter โ Public vendors
These vendors had no HIGH or CRITICAL CVEs published in NVD during this quarter. A clean quarter does not guarantee a clean posture โ but it is worth acknowledging.
Atlassian ยท Check Point ยท CrowdStrike ยท Okta ยท Qualys ยท SAP ยท Salesforce ยท SentinelOne ยท ServiceNow ยท Zscaler
โ ๏ธ Private vendors โ monitored, no financial data
These vendors are tracked but cannot be included in normalized rankings because financial data is not publicly available. CVE counts are monitored.
Cloud Software Grp ยท ConnectWise ยท Ivanti ยท SolarWinds ยท WatchGuard
๐ Open source projects โ monitored, no financial data
Open source projects are widely deployed in enterprise infrastructure. They are tracked because their vulnerabilities matter โ but without revenue, R&D spend or headcount to normalize against, they cannot be ranked alongside commercial vendors. A separate analysis may be warranted in a future edition.
๐ก A note on open source and enterprise responsibility.
These CVEs represent real work: real researchers finding real bugs, real developers fixing them, often without pay. If your organization runs on open source and has never contributed back, this is a good moment to reconsider. Better-funded open source is more secure open source. Consider donating or sponsoring the projects your infrastructure depends on.
โ ๏ธ Private & Commercial Vendors โ Q1 2026 vs Q2 2026
No public financial data โ Pain Index cannot be calculated. Absolute CVE counts only. Score = CRITICAL ร 3 + HIGH.
| Vendor | Q1 CRIT | Q1 HIGH | Q1 Score | Q2 CRIT | Q2 HIGH | Q2 Score | Trend |
|---|---|---|---|---|---|---|---|
| Cloud Software Grp | 1 | 0 | 3 | 2 | 4 | 10 | ๐ด Worse |
| ConnectWise | 3 | 0 | 9 | 0 | 0 | 0 | ๐ข Better |
| Ivanti | 0 | 1 | 1 | 1 | 4 | 7 | ๐ด Worse |
| SolarWinds | 4 | 3 | 15 | 0 | 1 | 1 | ๐ข Better |
| WatchGuard | 0 | 1 | 1 | 0 | 3 | 3 | ๐ด Worse |
๐ Open Source Projects โ Q1 2026 vs Q2 2026
No financial normalization possible. Score = CRITICAL ร 3 + HIGH.
| Vendor | Q1 CRIT | Q1 HIGH | Q1 Score | Q2 CRIT | Q2 HIGH | Q2 Score | Trend |
|---|---|---|---|---|---|---|---|
| Apache (OSS) | 4 | 8 | 20 | 13 | 20 | 59 | ๐ด Worse |
| Canonical | 0 | 1 | 1 | 1 | 7 | 10 | ๐ด Worse |
| Linux (kernel) | 26 | 152 | 230 | 15 | 253 | 298 | ๐ด Worse |
| Mozilla | 62 | 25 | 211 | 4 | 0 | 12 | ๐ข Better |
| Redis | 0 | 0 | 0 | 0 | 5 | 5 | ๐ด Worse |
๐ Sources & Methodology
- CVE Data: NIST NVD API v2.0 โ official U.S. government repository. Every CVE is counted once. Severity based on CVSSv3 base score (HIGH: 7.0โ8.9 ยท CRITICAL: โฅ9.0).
- Actively Exploited (๐ฅ): CISA KEV Catalog โ confirmed active exploitation in the wild.
- Company Metrics: Yahoo Finance via yfinance โ point-in-time snapshot. Revenue and R&D are TTM from the most recent annual filing. Employee count as reported in the latest annual filing.
- Pain Index Formula:
(CRITICAL ร 3 + HIGH ร 1) รท Normalizer. CRITICAL weighted 3ร to reflect higher exploitability and impact. - Three Lenses: Revenue, R&D Spend, Employees โ each normalizer tells a different story. Vendors that rank poorly across all three have a harder case to make.
- Private vendors (no stock ticker) are excluded from ranked tables โ financial data not publicly available. Listed separately for completeness.