Build1 distinct publisher3 min readPublished
Root Evidence rebuilt the exploitation clock on vendor advisory dates rather than NVD publication, and Jeremiah Grossman's team reads the resulting four-month median as a measure of inventory that stopped being maintained.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Ninety-two days separate the 2018 median from the 2026 one, and the reported average of 11.5 days a year across eight years reproduces exactly that figure, none of it from defenders getting quicker [1][7][2]. In 2018 nothing was exploited more than a year after its patch shipped; by 2023 that described 47% of n-day exploitation [11].
The measurement swap is real. It does not carry the whole distance. NVD publishes a median of about 25 days after the vendor's own advisory [5], so a fix that has sat in the customer's update channel for three weeks still scores as a zero-day under a clock anchored to NVD [4]. That clock was measuring a database's backlog. Re-anchoring it moves 25 of the roughly 115 days between the retracted one-day median [1] and 116, call it a fifth [4]. The rest is population. Root Evidence's median runs over 3,769 exploitations confirmed in CISA's KEV merged with VulnCheck's [2][3], which is 1.48% of the 253,912 CVEs published in the same period [3]. The two statistics are computed over different sets, so relabelling one of them does not make them reconcile.
Exploitation still leads the initial-access tables while the window widens. Mandiant's M-Trends 2026 has it at 32% of initial infection vectors, first for a sixth consecutive year [12]; IBM X-Force counts 40% of incidents and a 44% rise in attacks starting at a public-facing application [13]; in Verizon's DBIR it is 20% of breaches, second to stolen credentials at 22% [14]. Grossman's explanation for the patience is mechanical: researchers publish faster than defenders remediate, so racing gains an attacker nothing when the same unpatched host will still be answering in month sixty [10].
What survives the correction is the queue. 2025 published roughly 44,800 CVEs against 17,800 in 2018, two and a half times the volume [17][7], while the exploited share has never crossed 2.2% in any year [17], which caps last year's real working set near 986 items [6]. The occupants are known in advance. The same fifteen vendors have topped the n-day table for nine straight years, Microsoft leading in eight of them [18], and one in three n-days lands in five flaw classes headed by OS command injection at 313 CVEs, then path traversal at 228 and SQL injection at 208 [19]. Those are the classes with mature public exploit tooling and broad scanner coverage, which is why they keep coming back [21].
Scoped to that list, remediation is a scheduling problem. Scoped to all 44,800 published CVEs [17], it is a staffing problem, and a four-month median gap between fix and first exploit is what the staffing problem looks like after eight years of compounding [6].
Ranked by verification strength, evidence, and original report placement.
Cyril Simonnet, writing on his Substack, retracted a figure he had published six weeks earlier: that the median gap between disclosure and first exploitation had fallen to roughly a day, with one minute projected for 2027.
The Vulnpocalypse Report, published in August by Jeremiah Grossman's team at Root Evidence, traced every confirmed in-the-wild exploitation of a published CVE from January 2018 through mid-July 2026, all 3,769 of them, against the 253,912 CVEs published in the same period.
The report's exploitation data comes from CISA's Known Exploited Vulnerabilities catalog merged with VulnCheck's KEV, with patch dates pulled from vendor advisories rather than from a database.
The Zero Day Clock counts a CVE as a zero-day when exploitation lands on or before the NVD publication date.
NVD runs a median of about 25 days behind the vendor's own advisory.
Measured from the vendor patch date, the 2026 median gap to first exploitation is 116 days; in 2018 it was 24 days.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 5, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Two datasets, one vendor list: edge risk is a procurement problem, not a CVE queue2 distinct publishers
security
A 22-second handoff makes the triage queue the vulnerability, not the headcount1 distinct publisher
product
CrowdStrike and Fortinet co-sign a letter that dates the security tooling they sell5 distinct publishers
security
Keycloak's forgotten-password flow hands over admin accounts, and the fix is already tagged4 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
A public recount, read at one remove
The chain is unusually specific for a single-author piece: named catalogs (CISA's KEV merged with VulnCheck's), patch dates from vendor advisories, 3,769 exploitations against 253,912 CVEs, and a definitional gap of about 25 days between vendor advisory and NVD record that anyone can test. What holds the score down is that all of it reaches us through Simonnet's summary of a report our coverage never examines directly, and the Mandiant, IBM and Verizon figures corroborate exploitation's prevalence rather than the 116-day median itself.
One writer changing his own number
Simonnet withdrawing a figure he printed six weeks earlier is the extent of the uptake so far. By his own account the one-day median is still in everyone's slides, and every tool, program and other outlet in our coverage keeps running on the old clock rather than the vendor-advisory one. Against that, the exploitation the report describes is being observed in the field: 5,500 devices taken through one unpatchable Cisco flaw, and three annual incident datasets still ranking exploitation at the top of initial access.
Restrained numbers, a reaching cause
Every number here moves downward: a scary metric gets deflated, the zero-day share turns out flat at 15% to 26% since 2021, and the exploited slice has never exceeded 2.2% of published CVEs. The stretch is the headline causal move, that the extra 92 days came from an inventory somebody stopped maintaining. First-exploitation dates cannot distinguish patient adversaries from neglected hosts, and ViciousTrap, where no patch existed at all, illustrates the thesis without testing it.
Vendor research, relayed by a vendor writer
Grossman's team has a stake in the recount, and so does Simonnet: the field evidence comes from the research team at his own employer, which he says so plainly. Pushing the other way, the correction dismantles a number that helps sell fast containment, including the argument Simonnet himself made in June, and he keeps the distinction between a 116-day patch window and CrowdStrike's 29-minute breakout time intact rather than collapsing the two.
Checkable, so far unchecked
One publisher, one report, and arithmetic that holds everywhere it can be tested from the text. The load the whole story carries sits on a definitional claim, NVD trailing vendor advisories by a median of about 25 days so that three-week-old n-days get filed as zero-days, and that is precisely the kind of thing a second researcher could confirm or demolish quickly. Until someone does, the 116-day median stands on Root Evidence's counting alone.