Acronis Finds Patch Warning Rates Vary Widely Across SMB Windows Software

Summary
Acronis analyzed about 545,000 patch applications across SMB Windows fleets from January to May 2026, finding that 11.2% needed closer review and that warning rates varied sharply by product.
Key points
- Acronis’s analysis used patch deployment telemetry from SMB Windows endpoints; 11.2% of applications were rated caution or critical, indicating a need for closer review.
- Adobe PDF had the highest warning rate at 76.2%, followed by Google Chrome at 67.7%; Windows Server and Node.js were also above 35%.
- Chrome’s warning rate fluctuated from 18.5% in January to 83.0% in February and 85.9% in March, while Adobe PDF remained consistently high.
- Patch severity and installation quality measure different risks: severity reflects the vulnerability, while quality reflects deployment outcomes such as failures, errors, or instability.
- Chrome and Adobe PDF combine high warning rates with meaningful install bases, making them priorities for testing; lower-footprint products such as Node.js should be reviewed where deployed.
- Acronis recommends staged rollouts for high-warning products, using severity and patch quality together to guide testing and deployment.
Article Details
- Publisher
- Acronis Threat Research Unit
- Report Period
- 2026-01-01 to 2026-05-31
- Scope
- Patch installation quality across managed SMB Windows endpoints; compares warning rates by product, vendor severity, month, and application install base.
- Sample Size
- About 545,000 patch applications; 18 products had at least 50 scored patches for the per-product comparison.
- Key Statistics
- Of scored patch applications, 88.8% were classified as stable or minor issues, 11.2% as caution or critical issues, and 0.2% as critical issues.
- Warning rates exceeded 30% for Adobe PDF (76.2%), Google Chrome (67.7%), Microsoft Windows Server (35.4%), and Node.js (35.2%).
- Google Chrome was installed on 50.1% of managed Windows machines and Adobe PDF on 19.1%; their warning rates were 67.7% and 76.2%, respectively.
- Google Chrome's monthly warning rate rose from 18.5% in January to 83.0% in February and 85.9% in March, then fell to 54.3% in May.
- Among high-severity patches, 24.5% were classified as caution and 2.1% as critical issues; 11.0% of medium-severity patches were classified as caution.
- Recommendations
- Use both vendor vulnerability severity and patch quality when setting rollout order and testing scope.
- Prioritize pre-deployment testing for Google Chrome and Adobe PDF, and deploy their patches in stages: low-risk machines, a small cross-department user group, then the remaining fleet.
- Set stop and rollback criteria before broad deployment, monitor installation failures and user-impact reports, and retain the previous version for fallback.
- Reserve flexible testing capacity for products with volatile monthly warning rates; focus review of high-warning, less widely installed products on tenants where they are deployed.
- Refresh the product-level patch-quality analysis each quarter.
CVE
CVE-2025-13223time for the rest of the period. The H2 2025 Cyberthreats Report also flagged Chrome zero-days CVE-2025-13223 and CVE-2025-6558 as actively exploited Windows-targeting issues, so the volatility shows up on theCVE-2025-6558rest of the period. The H2 2025 Cyberthreats Report also flagged Chrome zero-days CVE-2025-13223 and CVE-2025-6558 as actively exploited Windows-targeting issues, so the volatility shows up on the exploit side too.
Vendors
AcronisAcronis Threat Research UnitAdobewith more than 30% of patches flagged: Adobe PDF (76.2%), Google ChromeGooglewith more than 30% of patches flagged: Adobe PDF (76.2%), Google ChromeMicrosoft(67.7%), Microsoft Windows Server (35.4%) and Node.js (35.2%).MozillaThe quiet group includes products with warning rates below 10%. This group includes Mozilla Thunderbird (7.4%), Microsoft .NET (6.3%), Visual C++/Studio (5.4%), Microsoft SQL Server (4.4%), Mozilla Firefox (4.3%),
Products
Adobe PDFwith more than 30% of patches flagged: Adobe PDF (76.2%), Google ChromeFoxit PDFeven though Windows runs on more endpoints than any individual app. Products such as Node.js, Foxit PDF and Zoom still need attention where warning rates are high, but testing can focus on the tenants andGoogle Chromewith more than 30% of patches flagged: Adobe PDF (76.2%), Google ChromeLibreOfficeemail clients, PDF readers, office suites, developer runtimes and conferencing apps. Products such as LibreOffice, Foxit PDF and Thunderbird are also included because many SMBs use them as alternatives to MicrosoftMicrosoft .NETgroup includes products with warning rates below 10%. This group includes Mozilla Thunderbird (7.4%), Microsoft .NET (6.3%), Visual C++/Studio (5.4%), Microsoft SQL Server (4.4%), Mozilla Firefox (4.3%), Microsoft EdgeMicrosoft EdgeMicrosoft .NET (6.3%), Visual C++/Studio (5.4%), Microsoft SQL Server (4.4%), Mozilla Firefox (4.3%), Microsoft Edge (3.6%), Microsoft Office (1.6%) and LibreOffice (0.0%). Most patches from these products can moveMicrosoft OfficeFoxit PDF and Thunderbird are also included because many SMBs use them as alternatives to Microsoft Office, Adobe PDF and Outlook.Microsoft SQL ServerThis group includes Mozilla Thunderbird (7.4%), Microsoft .NET (6.3%), Visual C++/Studio (5.4%), Microsoft SQL Server (4.4%), Mozilla Firefox (4.3%), Microsoft Edge (3.6%), Microsoft Office (1.6%) and LibreOfficeMicrosoft Visual C++/StudioMicrosoft Windows Server(67.7%), Microsoft Windows Server (35.4%) and Node.js (35.2%).Mozilla FirefoxThunderbird (7.4%), Microsoft .NET (6.3%), Visual C++/Studio (5.4%), Microsoft SQL Server (4.4%), Mozilla Firefox (4.3%), Microsoft Edge (3.6%), Microsoft Office (1.6%) and LibreOffice (0.0%). Most patches fromMozilla ThunderbirdThe quiet group includes products with warning rates below 10%. This group includes Mozilla Thunderbird (7.4%), Microsoft .NET (6.3%), Visual C++/Studio (5.4%), Microsoft SQL Server (4.4%), Mozilla Firefox (4.3%),Node.js(67.7%), Microsoft Windows Server (35.4%) and Node.js (35.2%).VS CodeMicrosoft products also fall into this group, including Windows 10 at 15.0%, Windows 11 at 13.9% and VS Code at 13.1%. These products may benefit from review, but they do not need the same level of testing on everyWindows 10Install base is measured as the share of managed Windows machines that report installed software. Windows 10, Windows 11 and Windows Server are excluded because the dataset does not track the OS itself as an installedWindows 11base is measured as the share of managed Windows machines that report installed software. Windows 10, Windows 11 and Windows Server are excluded because the dataset does not track the OS itself as an installedZoomthough Windows runs on more endpoints than any individual app. Products such as Node.js, Foxit PDF and Zoom still need attention where warning rates are high, but testing can focus on the tenants and endpoints