Skip to content

Security1 publisher2 min readPublished

Verizon's 43-day median patch time, against a five-day weaponization clock

Exploitation is now the top initial-access vector at 31% of breaches. The median defender needs 43 days to close a known-exploited flaw. Both figures reach operators through a guide selling the fix.

The Watch · Security desk

Illustration accompanying Verizon's 43-day median patch time, against a five-day weaponization clock

What happened

  • Verizon's 2026 DBIR, drawn from more than 22,000 confirmed breaches, has vulnerability exploitation overtaking stolen credentials as the most common way in, starting 31% of them.
  • Median time to patch a known-exploited flaw rose from 32 to 43 days. The share of CISA KEV catalog entries actually patched fell from 38% to 26%.
  • In Cobalt's 2026 pentesting report, AI and LLM applications show 2.7 times the high-risk finding rate of traditional applications.
  • The guide lists four conditions before an autonomous agent touches production: provable coverage, an independent validator, blast-radius guardrails and an audit trail.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A yearly engagement reports exposure long after the five-day weaponization window has closed, so buying a second annual test moves the calendar while coverage stays where it is.
  • decision Granting an unattended agent authenticated access to production makes this a control purchase. All four conditions are testable in a pilot: run the same target twice and compare which work items cleared.
  • exposure AI-assisted development pushes the code with the highest finding rate into the part of the estate a once-yearly sample is least likely to reach.
  • contradiction The timing figures name Verizon, Mandiant and Cobalt. The coverage share and the engagement price are unsourced estimates. Those two are what the purchase case rests on.

Mandiant's telemetry shows average time to exploit at roughly five days [5]. Set that against the 43-day patch median and the exposure window is 38 days [1]. The same median was 32 days in the prior cycle, an 11-day slip, about 34% [3][2]. KEV completion moved the same way: 12 points off, roughly a third of the previous rate [4][3].

Coverage is the second half of the problem. A manual engagement finds a bug only if the endpoint falls inside the sampled 5% to 10%, and the finding holds only until the next release [10]. The guide estimates the untested share of the estate at 90% [9].

The worked example is an IDOR in an authenticated account area. The attacker logs into an ordinary account, changes the account_id on a profile-update request, and finds the application never checks ownership; from there the chain runs ID enumeration to email rewrite to password reset to account takeover [16]. It has no CVE, and the input is well-formed [17]. A scanner matching responses against a CVE database misses it, and so does a DAST tool firing a fixed payload list, because the exploit needs a valid session and a multi-step sequence [18]. That bug class exposed 885 million mortgage and title records at First American Financial in 2019 [19].

The capability evidence is cited secondhand. XBOW's autonomous system topped HackerOne's US leaderboard in 2025 [11], and Fang et al. reported in 2024 that agents exploited 87% of one-day flaws unaided [12]. Cobalt's 4.5x figure for programmatic testing is presented as an effect of the testing model [8]. As described, that figure is an association. Teams testing on every build are also shipping on every build.

On price, the guide weighs one manual engagement at about $18,000 against IBM's $4.44M average breach cost for 2025 [14][15]. The ratio is roughly 247 to 1 [4]. The comparison lines up two prices and leaves out the probability of the breach, so it does not price risk.

The document behind the four-item bar is a free guide promoted on The Hacker News [22]. Its stated failure mode for the category is DAST with an LLM bolted on: the same fixed payload list underneath, nondeterministic coverage layered on top [20]. Work-item-enforced coverage is named as the first of three design criteria that separate a platform from a demo [21]. Cobalt's own remediation median, 39 days with a 25x gap between best and worst performers, comes from a different population than Verizon's 43 [6].

What to watch

  • Whether the next DBIR shows the 43-day known-exploited patch median moving in either direction.
  • Whether any agentic pentesting vendor moves from model claims to publishing per-run work-item pass and fail records.
  • Whether measured endpoint coverage data replaces the guide's estimated 90% untested figure.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories