AI-generated exploits now hit in 20 hours; patches take 43 days. See why vulnerability management is shifting to continuous, risk-based remediation.
Here's a number that should stop every security leader mid-sentence: attackers are now weaponizing new vulnerabilities in as little as 20 hours. Defenders, meanwhile, take a median of 43 days to fix a known-exploited flaw, according to the 2026 Verizon Data Breach Investigations Report. Mandiant's latest M-Trends data puts it even more bluntly — the average time to exploit is now negative seven days, meaning exploits often show up before a vulnerability is even publicly disclosed.
That gap is the subject of a sharp piece in SecurityWeek this month, "Is Patching Dead? Vulnerability Management in the Post-Mythos Era," by Danelle Au. Her argument: AI has broken the twenty-year model of patching one vulnerability at a time on a fixed deadline. With roughly 59,000 new CVEs projected in 2026 — more than 160 a day, with remote-code-execution flaws up 130% — no team can out-patch a machine that can write a working exploit straight from a vulnerability description.
The piece is worth reading in full, but the headline shift is this: the industry is moving from patch everything on a deadline to reduce risk continuously, based on what's actually exploitable. CISA made it official in June, retiring its old blanket patching directive (BOD 22-01) in favor of BOD 26-04, which weighs exploit status alongside public exposure, automated exploitability, and technical impact before deciding what gets fixed first and how fast.
In practice, that means five things replace the old race-to-patch playbook:
- Rethink the process. Triage by realized risk, not just severity score.
- Shrink exposure. You can't defend what you can't see — including what autonomous agents and service accounts are allowed to touch.
- Know what's actually exploitable. A CVSS 9.8 means little if the asset isn't reachable or the exploit path is already blocked.
- Validate that controls hold. Simulated attacks catch what static scanning misses.
- Prevent problems before they ship. Catch flaws in the IDE and CI/CD pipeline, not after deployment.
Instead of a scan-and-spreadsheet cycle that treats every finding the same, Mitigator gives your team a centralized dashboard that tracks vulnerabilities by asset, criticality, and exposure — so remediation effort goes where the real risk is, not just where the score is highest. Analyst-assisted services layered on top, including exploit-focused penetration testing, remediation assistance, and virtual ISO support, mean findings turn into a prioritized, workable queue instead of a backlog nobody trusts. Built-in ticketing and API integrations with JIRA, ServiceNow, and Connectwise keep remediation moving instead of stalling in a report no one opens.
That's the shift the SecurityWeek piece describes in miniature: continuous, prioritized, exposure-aware risk reduction in place of a deadline everyone quietly knows won't be met.
If your last audit of "actual patch times vs. policy" would embarrass you, that delta is your real exposure gap — and it's worth closing before the next 20-hour exploit window opens.
Want more of this in your inbox? This piece is featured in this month's InfoSight newsletter, alongside the rest of what's moving in vulnerability management, exposure validation, and AI-driven risk. [Subscribe here.]