UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber Security

CVE Exploitation Speed Index 2026: The Patch-Gap Race

Servnet Editorial · IT infrastructure analysis6 min read
Share

The old model — disclosure, then a race to patch — is broken. Mandiant's 2026 reporting puts the mean time to exploit at negative seven days, meaning active abuse of a flaw can begin before its CVE is even published, let alone patched. VulnCheck data shows the median time from CVE publication to entry in CISA's Known Exploited Vulnerabilities catalogue fell from 120 days in 2025 to 80 days in H1 2026. For UK security teams, this collapses the entire premise behind weekly or monthly patch cycles and demands a shift toward effective vulnerability management strategies built around exposure reduction, not just patch speed.

Median days from CVE publication to KEV catalogue listing
120 days90 days60 days30 days0 days120 days202580 daysH1 2026Median days to KEV…
View the data behind this chart
Median days from CVE publication to KEV catalogue listing
2025H1 2026
Median days to KEV…days120days80

The Alarming Truth: Time-to-Exploit Has Turned Negative

For years, vulnerability management assumed a linear sequence: disclosure first, weaponisation second, patching third. Mandiant's 2026 reporting overturns that sequence outright, putting the mean time to exploit at negative seven days — active exploitation, on average, is starting before the CVE is even publicly disclosed.

This isn't an outlier skew. VulnCheck's analysis of 2025 Known Exploited Vulnerabilities found that 28.96% were being exploited on or before the day their CVE was published — meaning attackers were already inside the door before defenders had a name for the hole, let alone a fix.

The practical implication is uncomfortable: for a meaningful share of the most dangerous flaws, there is no 'patch window' in the traditional sense. The defensive question shifts from 'how fast can we patch' to 'how exposed were we before we even knew there was a problem'.

Illustration: CVE Exploitation Speed Index 2026: The Patch-Gap Race

2026 Data Deep Dive: The Numbers Behind the Collapsing Window

VulnCheck's H1 2026 State of Exploitation analysis shows the median time from CVE publication to KEV catalogue listing fell from 120 days across 2025 to 80 days in the first half of 2026 — a sharp compression, even though VulnCheck itself frames the trend as worsening year over year for defenders, since the window is shrinking faster than most patch cadences can follow.

A separate Q2 2026 exploited-vulnerabilities report found that 22% of exploited CVEs were weaponised within seven days of publication. The same report calculated an average publication-to-KEV gap of 1,072 days against a median of just 68 days — a gap that matters: the huge average is dragged upward by a handful of very old CVEs still being exploited years later, while the median is the far more realistic figure for planning a live patch programme.

Other 2026 coverage reinforces the same direction of travel. One report puts the current median time to exploit at under five days — shorter than most enterprise patch cycles — while another describes serious vulnerabilities moving from disclosure to real-world abuse in 24 to 48 hours, where such campaigns used to take weeks.

Definitions Matter: Why Mean, Median and KEV-Lag Tell Different Stories

Much of the confusion around 'time to exploit' comes from conflating different metrics. Publication-to-KEV lag measures when a CVE is formally added to CISA's catalogue of known exploited vulnerabilities — a confirmation event, not the moment exploitation first happened. Publication-to-exploitation lag, by contrast, measures when abuse is first observed in the wild, which is often earlier and harder to pin down precisely.

Mean and median figures diverge for the same reason. The Q2 2026 report's 1,072-day average publication-to-KEV gap is a mean skewed by a small number of ancient, still-exploited CVEs; its 68-day median is the number that better reflects the typical case a security team will actually face.

Pre-disclosure versus post-disclosure timing is the third axis. Mandiant's negative-seven-day mean and VulnCheck's 28.96% pre-publication exploitation figure both point to the same reality: exploitation can start before a patch — or even a public advisory — exists at all.

The AI Factor and the Regulatory Response

Regulators are now writing exploitation speed directly into compliance requirements. CERT-In's 2026 patch mandate — explicitly framed around AI-accelerated threat velocity — requires known exploited vulnerabilities on internet-facing systems to be patched within 12 hours where feasible, with a one-day deadline for critical externally exposed flaws and a five-day window for high-severity ones.

That tiered, risk-based structure is itself a tacit admission that flat, one-size-fits-all patch SLAs no longer match attacker speed. It also signals where the pressure is coming from: the same 2026 reporting that ties exploitation velocity to AI-assisted attacker tooling is the reporting driving regulators to compress mandated patch windows from weeks to hours for the highest-risk categories.

For UK organisations without a domestic equivalent mandate, the CERT-In model is worth treating as a benchmark rather than a foreign curiosity: it demonstrates what a genuinely exploitation-speed-matched SLA structure looks like in practice.

UK Focus: The Patch Gap as a Breach Multiplier

For UK IT buyers, the practical question this data forces is no longer simply 'are we patching fast enough' — it's whether asset visibility, internet-facing exposure reduction and compensating controls are fast enough to matter given real-world breach timelines. If exploitation can begin before disclosure, patch speed alone cannot close the gap.

This means patch prioritisation has to be risk-weighted rather than treating every CVE equally: externally exposed assets, confirmed known-exploited vulnerabilities, and identity-adjacent flaws should sit at the top of the queue, in line with NCSC's risk-based guidance and sector obligations under UK GDPR and the NIS regime where applicable.

Commercially, the exposure is concentrated at the edge. A weekly or monthly patch cadence is materially slower than the 68- to 80-day median publish-to-KEV window — let alone the 22% of CVEs weaponised within seven days — and edge devices, VPNs and file-transfer tools remain among the highest-value internet-facing targets feeding UK breach entry points.

Time-to-exploit metrics compared, 2026 reporting
FigureScope/ContextSourceMean time to exploit-7 days2025/26 averageMandiantMedian CVE→KEV, H1…80 daysVulnCheck datasetVulnCheckMedian CVE→KEV, 2025120 daysVulnCheck datasetVulnCheckAvg publish→KEV gap…1,072 daysSkewed by old CVEsSecurityOnlineMedian publish→KEV…68 daysTypical caseSecurityOnlineExploited before…28.96%2025 KEVsVulnCheckWeaponised within 7…22%Q2 2026 CVEsSecurityOnline
View the data behind this chart
Time-to-exploit metrics compared, 2026 reporting
FigureScope/ContextSource
Mean time to exploit-7 days2025/26 averageMandiant
Median CVE→KEV, H1…80 daysVulnCheck datasetVulnCheck
Median CVE→KEV, 2025120 daysVulnCheck datasetVulnCheck
Avg publish→KEV gap…1,072 daysSkewed by old CVEsSecurityOnline
Median publish→KEV…68 daysTypical caseSecurityOnline
Exploited before…28.96%2025 KEVsVulnCheck
Weaponised within 7…22%Q2 2026 CVEsSecurityOnline

Illustrative Timeline: A Composite 2026 Exploitation Journey

No single CVE in this brief carries a fully documented hour-by-hour timeline, so the figure below is a composite built from the aggregate 2026 data above, mapped as a typical exposure journey rather than one named vulnerability.

Reading it left to right: exploitation activity can already be underway in the week before public disclosure, consistent with Mandiant's mean of minus seven days. Within the first seven days after publication, 22% of eventually-exploited CVEs in the Q2 2026 sample are already weaponised. By the 68-day median mark, a typical exploited CVE has reached formal KEV listing under the Q2 2026 methodology; under VulnCheck's separate H1 2026 measure, the median publication-to-KEV point lands around day 80.

The gap between 'weaponised' and 'formally catalogued as known-exploited' is the real danger zone — the period where exploitation is active but an organisation relying purely on KEV-driven prioritisation may not yet see the flag.

Actionable Strategies: Building Resilience When Patching Can't Keep Up

Given a median publish-to-KEV window of 68 to 80 days but real exploitation starting within a week — or before disclosure entirely — patch speed alone cannot be the whole strategy. UK security teams need a layered approach that assumes some vulnerabilities will be exploited before a fix is deployable.

Practical steps for UK IT leaders include tightening understanding patch management around risk tiers rather than flat schedules, adopting zero trust principles so a single exploited edge device doesn't grant broad network access, and layering managed detection & response to catch exploitation activity that occurs ahead of a published advisory.

  • Maintain a live inventory of internet-facing assets and shrink that footprint wherever a service isn't operationally essential.
  • Prioritise remediation by exposure and exploitation status first — externally facing, known-exploited, identity-adjacent — rather than by severity score alone.
  • Use compensating controls (network segmentation, virtual patching, WAF rules) to buy time on flaws that can't be patched within days.
  • Build a tiered SLA structure, modelled on frameworks like CERT-In's 12-hour/1-day/5-day approach, matched to exploitation risk rather than a single blanket cadence.
  • Treat detection and response as a first-class control, not a fallback, for the window before a patch exists.

Methodology

This data study compiles figures published between March 2026 and July 2026 from vendor and industry vulnerability-intelligence research, including VulnCheck's State of Exploitation reporting, Mandiant-derived 2026 exploitation trend coverage, a Q2 2026 exploited-vulnerabilities report, and a Cloud Security Alliance research note summarising CERT-In's 2026 patch-mandate framework.

Figures were sourced from named organisations' own published reports or from named third-party summaries of those reports, and each statistic in this article retains the exact scope, time period and definition used by its original source — publication-to-KEV lag, mean versus median time to exploit, and pre- versus post-disclosure exploitation are treated as distinct, non-interchangeable measures throughout.

No figures were averaged, extrapolated or merged across sources; where the underlying research did not provide a specific data point (for example, a fully documented single-CVE exploitation timeline), this article states that explicitly rather than substituting an invented figure.

Sources

Every figure in this article traces to the sources below.

  • VulnCheck — State of Exploitation, H1 2026 (median publish-to-KEV time, 2025 vs H1 2026)
  • Mandiant / Brandefense — 2026 vulnerability exploitation trends (mean time to exploit, pre-publication exploitation)
  • SecurityOnline.info — State of Exploited Vulnerabilities, Q2 2026 (weaponisation speed, mean vs median KEV gap)
  • Cloud Security Alliance — CERT-In 12-hour patch mandate research note, 2026
  • Security Boulevard — 46 vulnerability statistics, 2026 (median time to exploit under 5 days)
  • Saptang Labs — Why time-to-exploit is shrinking faster than patch cycles, 2026
CERT-In's 2026 risk-based patch deadline model
3Known exploited, internet-facing12-hour patch deadline2Critical, externally exposed1-day patch deadline1High severity5-day patch window
View the data behind this chart
CERT-In's 2026 risk-based patch deadline model
LayerDetail
Known exploited, internet-facing12-hour patch deadline
Critical, externally exposed1-day patch deadline
High severity5-day patch window
Open data

The 8 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).

Cite as: Servnet Research, “CVE Exploitation Speed Index 2026: The Patch-Gap Race”, servnetuk.com, 2026.

Share
Key takeaways
  • Mandiant's 2026 reporting puts the mean time to exploit at -7 days — exploitation can start before a CVE is even disclosed.
  • VulnCheck: median publish-to-KEV time fell from 120 days (2025) to 80 days (H1 2026).
  • 28.96% of 2025 KEVs were exploited on or before their CVE's publication date, per VulnCheck.
  • 22% of exploited CVEs in Q2 2026 were weaponised within 7 days of publication.
  • Q2 2026's 1,072-day average publish-to-KEV gap is skewed by old CVEs; the 68-day median is the realistic planning figure.
  • CERT-In's 2026 framework sets a 12-hour patch deadline for known-exploited, internet-facing vulnerabilities — a model for risk-tiered UK SLAs.
Frequently asked

FAQs — CVE Exploitation Speed Index 2026

What is the average time to exploit a CVE in 2026?

It depends on the metric. Mandiant's 2026 reporting gives a mean time to exploit of -7 days (exploitation before disclosure), while VulnCheck's median publish-to-KEV time is 80 days for H1 2026, down from 120 days in 2025. A separate Q2 2026 report puts the median publish-to-KEV gap at 68 days.

Is time-to-exploit really negative?

As a mean, yes: Mandiant's 2026 figure of -7 days reflects that some exploitation begins before public disclosure, pulling the average below zero. It doesn't mean every CVE is exploited pre-disclosure — VulnCheck found 28.96% of 2025 KEVs were exploited on or before publication, not all of them.

What's the difference between publish-to-KEV lag and time to exploit?

Publish-to-KEV lag measures when a CVE is formally added to CISA's Known Exploited Vulnerabilities catalogue — a confirmation event. Time to exploit measures when abuse was first actually observed, which is often earlier. Conflating the two overstates or understates real exposure.

Why is the average publish-to-KEV gap (1,072 days) so much higher than the median (68 days)?

Because the Q2 2026 report's average is skewed upward by a small number of very old CVEs that remain exploited years after publication. The 68-day median strips out that skew and better represents the typical exploited CVE's timeline.

How should UK organisations prioritise patching given these figures?

Focus first on externally exposed, known-exploited and identity-adjacent vulnerabilities rather than treating all CVEs equally, in line with risk-based guidance. A flat, calendar-based patch cycle is materially slower than the observed exploitation windows for high-risk categories.

Does CERT-In's 12-hour patch rule apply to UK organisations?

No — CERT-In is an Indian regulatory framework. It's referenced here as a benchmark model: its tiered 12-hour/1-day/5-day structure, based on exposure and exploitation status, illustrates what a genuinely exploitation-speed-matched SLA looks like for UK teams designing their own risk-based patch policies.

Related

Continue reading

More in Research

Got a question this study didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111