Mandiant Reports Vulnerability Exploits Now Occur Before Patches Exist

The average time to exploit vulnerabilities has gone negative, fundamentally breaking the assumption that patching can outrun attackers.

Illustration: Mandiant Reports Vulnerability Exploits Now Occur Before Patches Exist
AI-generated illustration · Sylvaris

A Negative Number That Changes Everything

In a report analyzing data from the week beginning April 27, 2026, researchers noted that Mandiant's time-to-exploit analysis showed attackers exploiting vulnerabilities an average of seven days before patches become publicly available. In 2026, 28.3 percent of CVEs were exploited within 24 hours of disclosure, meaning they are exploited before patches are available.

The AI Acceleration Factor

The cause is AI and its ability to act before organizations can defend. AI-assisted exploit generation allows attackers to weaponize vulnerabilities from CVE descriptions alone. University research has demonstrated that GPT-4 could autonomously exploit 87 percent of one-day vulnerabilities when given only the CVE description, at a cost of roughly nine dollars per exploit.

The shift has profound implications for security strategy. Organizations spending the majority of their security budget on preventive controls are optimizing for a threat model that expired in 2023. The decisive control becomes time to detection, not time to patch.

What Security Teams Must Do Differently

On Friday during the target week, the UK National Cyber Security Centre released a paper entitled 'Preparing for a vulnerability patch wave,' stating that organizations must act now to prepare for a wave of patches that will address decades of technical debt. The recommendation is clear: assume exposure, hunt continuously, compress dwell time, and reduce attack surface rather than trying to patch faster.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.