Skip to content

Security1 publisher2 min readPublished

ENISA puts weaponisation of a disclosed vulnerability at 15 minutes

ENISA says in a July 2026 assessment that the research-and-develop delay defenders implicitly count on is disappearing as automated systems take over the attacker's work, with the remaining window measured in minutes.

The Watch · Security desk

Photograph accompanying ENISA puts weaponisation of a disclosed vulnerability at 15 minutes
Photo: securityaffairs.com

What happened

  • ENISA's July 2026 paper on cybersecurity in the frontier AI era argues that advanced AI compresses the attack chain from reconnaissance and vulnerability discovery through to exploitation, lateral movement and data theft.
  • The agency says vulnerability weaponisation may now happen within 15 minutes of disclosure, and cites research putting the median time from initial access to data exfiltration at 72 minutes.
  • ENISA gives the condition a name, "negative time-to-exploit", meaning attackers hold usable exploit information before defenders have received or deployed a fix.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Patch programs whose approval step takes days have to name which vulnerability classes may deploy without a human signature, because the paper itself stops short of endorsing blanket automation.
  • exposure Findings parked as low severity become reachable, because a path assembled from a modest bug, a weak credential and an exposed API never surfaces in a queue sorted one CVE at a time.
  • cost The spend moves to reading: at 500 reports a day, verification and triage headcount is the budget line.
  • contradiction ENISA writes the collapse as a possibility and the 15-minute figure as something that may now happen, so a remediation target rebuilt on those clocks is planning against a forecast.

ENISA's argument turns on chaining, not on the count of bugs found [1]. The paper says frontier models can reason about application logic, credentials, configurations and API access instead of only identifying isolated coding flaws [3]. Its example of the result is a modest vulnerability combined with a weak credential, an exposed API or a poorly configured service [4].

The volume figure comes from one organisation. It went from roughly 80 CVEs in the first quarter of 2025 to almost 500 in the first quarter of 2026, a rise of about six times [9][3]. With frontier-AI tools in use, the same organisation reached about 500 reports per day [9]. A quarter is roughly 90 days, so almost 500 in a quarter is about 5.5 per day, and 500 per day is close to 90 times that rate [1].

Weaponisation within 15 minutes of disclosure [5], then a median of 72 minutes from initial access to exfiltration [6], is 87 minutes from published advisory to data leaving the network [2]. ENISA does not make that composite claim, and the account of the paper leaves the research behind the 72-minute median unidentified. The defender sequence in the same account runs: receive the advisory, send it through a change process, test the update, obtain approval, schedule deployment [13].

ENISA's term for the resulting lag is the "Authority Gap", the case where an organisation takes longer to approve a defensive action than an AI-assisted attacker needs to exploit the weakness [8]. The paper does not turn that into a mandate for autonomous patching. It says automated patching can break systems, disrupt critical services or introduce new bugs, and it identifies verification of AI-generated patches as a new bottleneck [10].

What the agency asks for is triage capacity: resources moved from discovery toward faster triage, prioritisation and remediation, with EPSS and VEX used to pick out the vulnerabilities most likely to matter [11]. The same pressure is on the disclosure side, where ENISA says AI-generated reports have begun to overwhelm parts of the open-source reporting pipeline, and that their quality is improving, which makes them harder to filter out [12]. On the defensive side it recommends continuous threat modelling and automated testing inside the software development lifecycle [14].

What to watch

  • Whether ENISA or any vendor publishes the dataset behind the 15-minute weaponisation estimate.
  • Whether a regulated operator states publicly that a class of patches now deploys without human approval, and reports what it broke.
  • Whether major open-source maintainers begin refusing AI-generated vulnerability reports outright.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories