Mandiant Reports Vulnerability Exploits Now Occur Before Patches Exist
The average time to exploit vulnerabilities has gone negative, fundamentally breaking the assumption that patching can outrun attackers.
A Negative Number That Changes Everything
In a report analyzing data from the week beginning April 27, 2026, researchers noted that Mandiant's time-to-exploit analysis showed attackers exploiting vulnerabilities an average of seven days before patches become publicly available. In 2026, 28.3 percent of CVEs were exploited within 24 hours of disclosure, meaning they are exploited before patches are available.
The AI Acceleration Factor
The cause is AI and its ability to act before organizations can defend. AI-assisted exploit generation allows attackers to weaponize vulnerabilities from CVE descriptions alone. University research has demonstrated that GPT-4 could autonomously exploit 87 percent of one-day vulnerabilities when given only the CVE description, at a cost of roughly nine dollars per exploit.
The shift has profound implications for security strategy. Organizations spending the majority of their security budget on preventive controls are optimizing for a threat model that expired in 2023. The decisive control becomes time to detection, not time to patch.
What Security Teams Must Do Differently
On Friday during the target week, the UK National Cyber Security Centre released a paper entitled 'Preparing for a vulnerability patch wave,' stating that organizations must act now to prepare for a wave of patches that will address decades of technical debt. The recommendation is clear: assume exposure, hunt continuously, compress dwell time, and reduce attack surface rather than trying to patch faster.