I remember when the maintainer of an open source XML library contacted dozens of companies for support to fix a critical vulnerability, and most of them didn't even respond and aside from two the rest went basically "not our problem, get lost".
A handful of companies probably care a bit but most won't bother to pay even a penny.