
Vulnerability exploitation timelines have been falling steadily for years. Frontier AI tools have made them collapse. The exposure window - the time between vulnerability disclosure and remediation - has all but disappeared.
This new reality leaves vulnerability management (VM) teams in something of a conundrum. Merely patching flaws faster, the approach they have relied on for years, doesn’t work with exposure windows as tight as they now are. The solution, then, is not just to patch vulnerabilities faster but to patch the right vulnerabilities faster.
Fixed patch cycles can’t keep pace with frontier AI
Patch cycles tend to run one of three cadences. Emergency updates block active attacks within 12 to 72 hours. Routine updates fix unexploited high risks every 7 to 14 days. Deferred updates handle low-risk or offline systems every 30 to 90 days.
The most recent Mandiant M-Trends report found that the mean time-to-exploit is now an estimated -7 days. Exploitation routinely happens before a patch exists.
Clearly, patch cycles can’t keep pace with that kind of speed. So, organizations are left with a patch gap - the time delay between when a software security vulnerability is discovered or disclosed and when a patch is fully created, released, and installed.
The size of your backlog isn’t as important as you think
Most organizations have thousands of open common vulnerabilities and exposures (CVEs) sitting in their backlogs, and that number is growing faster than teams can clear it.
The 2026 Verizon Data Breach Investigations Report found the median time to fully patch a vulnerability is now 43 days, up from 32 days the year before, and only 26% of vulnerabilities on CISA's Known Exploited Vulnerabilities list were fully remediated last year, down from 38% the year prior.
The good news is that most of them don’t present much risk.
In fact, only about 6% of CVEs are ever exploited in the wild. 6% is the number patch management teams need to worry about. That subset tends to sit on active, exploitable attack paths - the kind that frontier AI models are very good at finding. The other 94% may pose theoretical risk, but they aren't the ones causing breaches.
To protect themselves, organizations should identify those attack paths and focus on minimizing exposure through risk-based vulnerability prioritization, not just reducing backlogs. Shut down the attack path, and you shut down the risk.
Risk-based prioritization narrows huge queues
Closing those attack paths means looking beyond Common Vulnerability Scoring System (CVSS) scores.
CVSS scores identify how much of a threat a vulnerability poses in theory. However high a vulnerability score is, if it’s not exploitable in your specific environment or reachable by an attacker, it poses little immediate risk to your systems.
Instead, VM teams should look to business-context prioritization - taking asset criticality, exploitability, and exposure into account. That’s how you decide what needs addressing first, so your team doesn’t waste time and money fixing vulnerabilities that might be a huge threat for an organization, but not necessarily yours.
Agentic AI remediation speeds things up further - but with caveats
As noted, time-to-exploit is now measured in the negative. Prioritization alone isn’t enough to keep up with that pace. Even if you’re picking the right vulnerabilities to patch, that means nothing if you’re not patching them fast enough.
That’s where AI agents come in.
Agentic AI remediation does more than automation. Automation executes pre-defined playbooks. AI agents make decisions based on context - that means even if it hasn’t seen a specific vulnerability before, it can reason through the threat, analyze system dependencies, and synthesize a unique remediation strategy on the fly.
The result is machine-speed remediation, fast enough to compete with frontier AI-assisted attackers.
Of course, AI agents come with serious governance requirements. If you choose to use AI agents for remediation, you must implement human-in-the-loop oversight for the highest impact patch decisions. That means if a mistaken patch could knock out critical systems, a human must approve it.
What good exposure-window reporting looks like
Finally, you need to work out whether your efforts have been worth it. And patch-compliance percentages don’t tell you what you need to know. A 95% patching rate sounds impressive, but what use is it if the 5% sits on internet-facing systems tied to critical assets?
Critical-path exposures are an important metric. You want to know how long a known-exploited vulnerability stayed open, and how that number is trending against your industry’s benchmarks. If you’re a CISO, ask your team to report exposure by business impact rather than by ticket count.
Exposure windows are only getting smaller
These trends are going to continue. Vulnerability counts will continue to rise, backlogs will grow, and frontier AI will get better. This problem is not going away.
That’s why it’s so important to start working on the solution today.