Skip to content
New field report2026 Litigation ReadinessDownload free
Litigation glossary
Legal structure

Duty to Update Software Security

The contested question of whether, and how far, a software or AI vendor owes an ongoing duty to patch known security vulnerabilities after a product has shipped.

Traditional product liability often centers on the condition of a product at the time it left the manufacturer's hands. Software complicates that model because vulnerabilities are frequently discovered after release, patches are technically feasible in a way a redesigned physical product is not, and vendors routinely push updates. Plaintiffs harmed by a breach that exploited a known, unpatched vulnerability argue this creates an ongoing duty of reasonable care distinct from any defect that existed at shipment.

Whether courts will recognize a freestanding post-sale duty to patch, as opposed to treating unpatched vulnerabilities as evidence within an ordinary negligence claim, is unsettled and varies by jurisdiction, contract terms, and industry-specific regulation. Some sectors carry statutory or regulatory patching expectations that inform the standard of care even where no common-law duty is explicitly recognized, and contractual terms of service or end-user license agreements frequently attempt to disclaim or limit any ongoing maintenance obligation — with courts divided on how far those disclaimers can go, especially against consumers.

Juricratic represents the strength of an ongoing-duty theory as a dial shaped by how long the vulnerability was known before exploitation, whether a patch was technically available, and what the vendor's contractual and regulatory obligations actually said — rather than assuming any fixed timeline (thirty days, ninety days, or otherwise) constitutes the standard of reasonable patching, since no such uniform rule exists.

In litigation

How it actually shows up

Plaintiffs build the timeline between vulnerability disclosure, patch availability, and the breach date, since a long gap between a known fix and its deployment is the strongest evidence of unreasonable delay. Defendants point to contractual maintenance-scope limits, resource and testing constraints on rolling out patches responsibly, and industry-typical patching cadences to argue their timeline was reasonable, while also contesting whether a freestanding post-sale duty exists in the relevant jurisdiction at all.

Questions
Can a company be sued for not patching a known software vulnerability?
It has been argued as a negligence theory, but whether courts recognize a distinct ongoing duty to patch, separate from the product's condition at sale, is unsettled and varies by jurisdiction, contract terms, and the industry involved.
Is there a legal deadline for how fast a company must release a security patch?
No uniform legal deadline exists across the board. Some regulated industries have specific requirements, but for most software there is no fixed rule, and reasonableness is judged case by case based on the vulnerability's severity and the vendor's typical practices.
Do terms of service disclaimers protect a vendor from a failure-to-patch claim?
They can limit exposure, but courts do not treat every disclaimer as fully enforceable, particularly against consumers or where the disclaimer is inconsistent with other obligations the vendor undertook, so the protection is real but not absolute.

This page is an educational explainer, not legal advice, and creates no attorney–client relationship. Juricratic is a simulation engine: every probability-like figure is a dial you set, not a calibrated prediction. Verify every rule, deadline, and figure against the authorities and orders that govern your matter.

Turn the concept into a modeled matter.

Juricratic makes every one of these ideas a live dial: model your case as a solvable game, then watch the optimal line and the settlement window move as the assumptions do.

Request access
simulation, not prediction — not legal advice