AIO APEX

The exploit weaponization window has collapsed from weeks to hours

Share:
The exploit weaponization window has collapsed from weeks to hours

The gap between a vulnerability's public disclosure and its first exploitation in the wild has collapsed from an average of 56 days in 2024 to roughly 10 hours today. In some tracked cases, exploitation begins before a patch is even released — a negative time-to-exploit that would have sounded absurd two years ago. Patch cycles built around monthly cadences and 30-day remediation windows were never designed for this, and the mismatch is now the single biggest driver of breach headlines.

This isn't a hypothetical. It's the pattern behind nearly every major exploitation story IRCNF has covered in the past two weeks, and the pattern is the story — not any one CVE.

The Numbers Behind the Collapse

A record 48,185 CVEs were published in 2025, about 131 per day, up from 40,009 the year before. That volume alone makes manual triage impossible for most security teams. Layered on top of it: 47.7% of vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog in 2025 carried that same year's CVE identifiers, meaning attackers are weaponizing current-year disclosures faster than defenders can process them. Within the first week of disclosure, more than 54% of critical vulnerabilities face active exploitation. The median time to mass exploitation of a newly disclosed flaw now sits at just 5 days.

Meanwhile, vendor response has not kept pace proportionally. Even for vulnerabilities already confirmed as actively exploited, vendors take an average of 15 days to ship a patch. For high or critical flaws generally — not yet known to be exploited — the average patch time was 54.81 days in 2025. The defender's clock and the attacker's clock are now running at completely different speeds.

Four Recent Cases That Show the Pattern

Wiz researchers traced a three-CVE chain in JFrog Artifactory that attackers used to plant Rust-based backdoors across Fortune 100 build pipelines over a 24-day campaign — fast enough to compromise CI/CD infrastructure before most affected organizations had triaged the disclosure, let alone patched it.

Acronis's Threat Research Unit documented a China-linked actor, tracked as Red Heron, turning a Gitea vulnerability (CVE-2026-60004) into a fully automated hacking framework within days of disclosure — scanning 1,386 internet-facing instances and confirming 13 compromises, deploying a new rootkit and backdoor along the way.

Cisco Talos attributed active exploitation of a CVSS 10.0 flaw in Cisco Firepower Management Center (CVE-2026-20079) to the Sandworm APT group and Qilin ransomware operators — a vulnerability serious enough that CISA added it to the KEV catalog with an emergency federal remediation deadline, yet exploitation was already underway by the time that deadline was set.

And when GitLab disclosed a CVSS 10.0 vulnerability (CVE-2026-85706) this month, CISA's remediation deadline for federal agencies landed on the same day as the disclosure itself — an acknowledgment that the old model of "disclose, then patch within 30 days" no longer reflects how fast exploitation actually moves.

Why the Gap Keeps Widening

Three forces are driving the acceleration. First, AI-assisted reverse engineering has made it dramatically faster for attackers to go from a patch diff or proof-of-concept to a working exploit — the manual analysis that used to take a skilled researcher days now takes hours. Second, the KEV-style reactive model, however useful, is fundamentally a lagging indicator: a vulnerability has to be observed as exploited before it gets flagged, by which point the highest-value targets are often already compromised. Third, sheer volume: with CVE publication running at 131 per day, even well-staffed security teams cannot manually evaluate exploitability and business impact for every disclosure before attackers do it for them.

What Defenders Should Actually Change

The practical response is not "patch faster" in the abstract — it's changing which vulnerabilities get immediate attention and how remediation is delivered. Internet-facing systems, CI/CD infrastructure, and anything with a KEV-catalog history for its vendor should be on a same-week patch SLA, not a monthly one. Prioritization should weight exploitability signals (KEV membership, public PoC availability, EPSS score) above raw CVSS score, since a CVSS 9.8 with no known exploit is a lower near-term risk than a CVSS 7.5 already in KEV.

Where patches can't be deployed within 72 hours of disclosure for actively-targeted software, virtual patching through WAF rules or network segmentation should serve as a bridge — not a substitute, but a way to buy the days that vendors and internal change-management processes still need. Threat intelligence feeds that flag exploitation attempts before a formal KEV listing are now worth the subscription cost for any organization running internet-facing infrastructure. And any team still operating on a "patch Tuesday plus 30 days" mental model should treat that model as already broken for anything with real internet exposure — the data no longer supports the assumption that a month is a safe window.

Share:
Exploit Weaponization Window Collapses to Hours | IRCNF | AIO APEX