That is not even close to an excuse. A remote code execution vulnerability has the potential to destroy your whole company.
> The company's internal review of the incident continued. Upon discovering a vulnerability in the Apache Struts web application framework as the initial attack vector, Equifax patched the affected web application before bringing it back online.
That bullet point lies between the "July 30th" and "August 2nd" bullet points. Based on that timeline, the vulnerability took days to patch.
Equifax's core business is about giving out credit scores. I'd bet their biggest fear is giving someone a high score when they deserve a low one. Data breaches, moderately inaccurate information... a nuisance, but a sideshow.