Product1 publisher3 min readPublished
Confirmed exploitation now lands 40 days sooner after a CVE goes public
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
The Product Desk · Product desk

What happened
- VulnCheck's first-half report puts the median time from CVE publication to confirmed exploitation at 80 days, down from 120 days across 2025.
- Roughly 200 CVEs reached exploitation within 31 days of publication, and VulnCheck says early-lifecycle exploitation has not scaled at the pace of CVE issuance.
- Known exploited vulnerabilities rose 10 percent over the previous six months while published CVE volume rose 45 percent.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision A security lead now picks between funding faster patching across every tier and keeping a slower default while spending the difference on the narrow set that meets the three-day conditions.
- constraint The binding limit is triage capacity, not patch capacity: the same analysts have to clear a much larger CVE feed to surface a KEV list that barely grew.
- exposure Whoever bought the AI stack inherits patch duty for it, because known exploitation already covers model-building tools, workload-scaling platforms, AI gateways, agents and workflow automation.
- contradiction The same report feeds both sides of the AI argument, and anyone citing rising CVE counts as proof of an attacker capability jump is running ahead of a 1.3 percent confirmed exploitation rate on AI-found bugs.
Most patch SLAs are a severity gate and a number: 30 days for critical, 60 or 90 for the rest, agreed with audit at some point and untouched since. Forty days off a 120-day median is a third faster [13]. A 90-day tier used to sit inside the 2025 median, which meant half of everything that eventually got exploited was still unexploited when the ticket closed. Against an 80-day median, it sits outside [17].
The 30-day tier is about where it was. VulnCheck's count of CVEs exploited inside the first month held steady while issuance climbed [4], so a team patching criticals in a month faces roughly the same number of fast-exploited bugs it faced last year.
The reading pile is where the growth landed. VulnCheck's ratio of new KEVs to published CVEs fell from a 2.7 percent peak in the second half of 2023 to 1.4 percent in the first half of 2026 [6]. Per CVE reviewed, the chance of turning up one that ends up exploited is about half what it was two and a half years ago [15].
Part of the population is out of reach of any SLA measured from publication. VulnCheck logged 495 KEVs in the period [2], and 23.43 percent of them had evidence of exploitation on or before the CVE's publication date, down from 28.93 percent in 2025 [3]. That works out to about 116 vulnerabilities where the first possible patch day was already late [14]. CISA's BOD 26-04, as VulnCheck describes it, recommends prioritising remediation by risk and patching as aggressively as within three days when there is evidence of exploitation, automatability, high technical impact and/or public exposure [11].
On AI-assisted discovery, the report's own numbers do not carry the alarm. Of 1,061 vulnerabilities attributed to AI-assisted discovery, 14 have been confirmed exploited in the wild, which VulnCheck puts at roughly the overall exploitation rate for the half [7]. Anthropic's Project Glasswing produced more than 23,000 findings, 126 published CVEs and one confirmed exploited case [8]; that is about 0.5 percent of findings reaching a CVE at all [16]. VulnCheck writes that it is "still too early to determine whether exploitation volumes will eventually follow the same growth trend as CVE issuance or level off at current rates" [12].
For anyone rewriting the tiers this week, the two questions that sort the queue better than a CVSS band are whether exploitation evidence exists today and whether the affected system is internet-reachable and automatable. Those are the conditions attached to the three-day window [11]. Then check who owns the content management systems: one-third of first-half KEVs were CMS, a bigger share than VulnCheck has seen historically [9].
What to watch
- Whether second-half KEV counts start tracking the 45 percent CVE growth rate or stay near 10 percent.
- Whether the roughly 200 CVEs exploited within 31 days rises, which would be the first sign AI-assisted discovery is reaching attackers.
- Whether CISA widens BOD 26-04's three-day window beyond the four conditions it currently names.