Mind the Gap
With CVEs spiking year-over-year, running unmanaged open source in production creates a dangerous security gap. Here are 3 key questions to protect your stack.

With CVEs spiking year-over-year, running unmanaged open source in production creates a dangerous security gap. Here are 3 key questions to protect your stack.

The pace of vulnerability discovery and disclosure is increasing at an unprecedented rate. The velocity with which bugs are being found and common vulnerabilities and exposures (CVEs) are being produced is exponential in nature. The problem is worse than ever.
Bug bounty programs are the busiest they've ever been. And most security teams are drowning in vulnerability reports.
CVE disclosures have skyrocketed in 2026 versus the same period in 2025, 2024, and earlier.

Sources: Serious cyber vulnerability disclosures kept climbing in July
A step function gives you a landing. You climb, you level off, you catch your breath, and you plan for the next one. What we're living through now isn't a step. It's a cliff. And the resulting gap between those two is immense.
Coming from our roots in the open source community, we at Ory are particularly invested in the security and quality of our code. This is not a talking point. It's who we are and from whence we came.
Today we have the advantage of access to various non-public, preview cybersecurity models that we run against our code base and our environments. The goal is simple: discover issues before they're discovered in the public realm. This work is carried out by talented, experienced, dedicated teams, and our scanning is constant. Not periodic. Constant.
So what does a cliff mean for the code you run in production? It means the gap between the security posture of an open source version and its supported, commercial sibling is vast.
If your organization is leveraging an open source version of software to run production workloads, you are operating in that gap. You are standing at the bottom of the cliff.
We all want our organizations to have the best possible security posture. We all want to work with the safest possible code powering our digital ecosystems. Nobody chooses to operate in the gap on purpose... most people just do not realize how wide it has become.
And the gap isn't only in the code. It shows up in what leadership can actually see. The new EY US AI Risk and Governance Survey of more than 200 senior AI decision-makers at US public companies with at least $1 billion in revenue found that 89% encountered AI-related risks during the past year. Yet 41% say their senior leaders do not have visibility into all the AI tools currently operating inside their own organization. And 36% say they've already experienced an AI incident or failure that caused a materially negative impact. You can't close a gap you can't see.
Where are you running open source versions in production? Know exactly which workloads sit in the gap today.
Who is scanning that code, and how often? If the answer is "the public, eventually," that's your exposure. The reality is that agents are scanning everything and they will eventually find every flaw.
Is your security posture keeping pace with a cliff, or still planning for a step?
If you are concerned about operating in the gap, or you want to close it and run the safest, most secure version to support your production needs, please reach out to us. We're ready to help.
The cliff is already here. The gap doesn't have to be.