This document summarizes the key findings of a SANS 2021 survey on vulnerability management. The percentage of organizations with a formal vulnerability management program increased to 75% from 63% in 2020. While identifying vulnerabilities is not difficult, fixing them remains challenging due to lack of budget, resources, and prioritization. The survey assessed organizations' maturity across various phases of the vulnerability management lifecycle. It found that maturity is lower for managing vulnerabilities in cloud, containers, and custom software compared to traditional infrastructure. Responsibility for vulnerability management is increasingly shared between security and IT teams.