The old model — disclosure, then a race to patch — is broken. Mandiant's 2026 reporting puts the mean time to exploit at negative seven days, meaning active abuse of a flaw can begin before its CVE is even published, let alone patched. VulnCheck data shows the median time from CVE publication to entry in CISA's Known Exploited Vulnerabilities catalogue fell from 120 days in 2025 to 80 days in H1 2026. For UK security teams, this collapses the entire premise behind weekly or monthly patch cycles and demands a shift toward effective vulnerability management strategies built around exposure reduction, not just patch speed.
View the data behind this chart
| 2025 | H1 2026 | |
|---|---|---|
| Median days to KEV… | days120 | days80 |
The Alarming Truth: Time-to-Exploit Has Turned Negative
For years, vulnerability management assumed a linear sequence: disclosure first, weaponisation second, patching third. Mandiant's 2026 reporting overturns that sequence outright, putting the mean time to exploit at negative seven days — active exploitation, on average, is starting before the CVE is even publicly disclosed.
This isn't an outlier skew. VulnCheck's analysis of 2025 Known Exploited Vulnerabilities found that 28.96% were being exploited on or before the day their CVE was published — meaning attackers were already inside the door before defenders had a name for the hole, let alone a fix.
The practical implication is uncomfortable: for a meaningful share of the most dangerous flaws, there is no 'patch window' in the traditional sense. The defensive question shifts from 'how fast can we patch' to 'how exposed were we before we even knew there was a problem'.

2026 Data Deep Dive: The Numbers Behind the Collapsing Window
VulnCheck's H1 2026 State of Exploitation analysis shows the median time from CVE publication to KEV catalogue listing fell from 120 days across 2025 to 80 days in the first half of 2026 — a sharp compression, even though VulnCheck itself frames the trend as worsening year over year for defenders, since the window is shrinking faster than most patch cadences can follow.
A separate Q2 2026 exploited-vulnerabilities report found that 22% of exploited CVEs were weaponised within seven days of publication. The same report calculated an average publication-to-KEV gap of 1,072 days against a median of just 68 days — a gap that matters: the huge average is dragged upward by a handful of very old CVEs still being exploited years later, while the median is the far more realistic figure for planning a live patch programme.
Other 2026 coverage reinforces the same direction of travel. One report puts the current median time to exploit at under five days — shorter than most enterprise patch cycles — while another describes serious vulnerabilities moving from disclosure to real-world abuse in 24 to 48 hours, where such campaigns used to take weeks.
Definitions Matter: Why Mean, Median and KEV-Lag Tell Different Stories
Much of the confusion around 'time to exploit' comes from conflating different metrics. Publication-to-KEV lag measures when a CVE is formally added to CISA's catalogue of known exploited vulnerabilities — a confirmation event, not the moment exploitation first happened. Publication-to-exploitation lag, by contrast, measures when abuse is first observed in the wild, which is often earlier and harder to pin down precisely.
Mean and median figures diverge for the same reason. The Q2 2026 report's 1,072-day average publication-to-KEV gap is a mean skewed by a small number of ancient, still-exploited CVEs; its 68-day median is the number that better reflects the typical case a security team will actually face.
Pre-disclosure versus post-disclosure timing is the third axis. Mandiant's negative-seven-day mean and VulnCheck's 28.96% pre-publication exploitation figure both point to the same reality: exploitation can start before a patch — or even a public advisory — exists at all.
The AI Factor and the Regulatory Response
Regulators are now writing exploitation speed directly into compliance requirements. CERT-In's 2026 patch mandate — explicitly framed around AI-accelerated threat velocity — requires known exploited vulnerabilities on internet-facing systems to be patched within 12 hours where feasible, with a one-day deadline for critical externally exposed flaws and a five-day window for high-severity ones.
That tiered, risk-based structure is itself a tacit admission that flat, one-size-fits-all patch SLAs no longer match attacker speed. It also signals where the pressure is coming from: the same 2026 reporting that ties exploitation velocity to AI-assisted attacker tooling is the reporting driving regulators to compress mandated patch windows from weeks to hours for the highest-risk categories.
For UK organisations without a domestic equivalent mandate, the CERT-In model is worth treating as a benchmark rather than a foreign curiosity: it demonstrates what a genuinely exploitation-speed-matched SLA structure looks like in practice.
UK Focus: The Patch Gap as a Breach Multiplier
For UK IT buyers, the practical question this data forces is no longer simply 'are we patching fast enough' — it's whether asset visibility, internet-facing exposure reduction and compensating controls are fast enough to matter given real-world breach timelines. If exploitation can begin before disclosure, patch speed alone cannot close the gap.
This means patch prioritisation has to be risk-weighted rather than treating every CVE equally: externally exposed assets, confirmed known-exploited vulnerabilities, and identity-adjacent flaws should sit at the top of the queue, in line with NCSC's risk-based guidance and sector obligations under UK GDPR and the NIS regime where applicable.
Commercially, the exposure is concentrated at the edge. A weekly or monthly patch cadence is materially slower than the 68- to 80-day median publish-to-KEV window — let alone the 22% of CVEs weaponised within seven days — and edge devices, VPNs and file-transfer tools remain among the highest-value internet-facing targets feeding UK breach entry points.
View the data behind this chart
| Figure | Scope/Context | Source | |
|---|---|---|---|
| Mean time to exploit | -7 days | 2025/26 average | Mandiant |
| Median CVE→KEV, H1… | 80 days | VulnCheck dataset | VulnCheck |
| Median CVE→KEV, 2025 | 120 days | VulnCheck dataset | VulnCheck |
| Avg publish→KEV gap… | 1,072 days | Skewed by old CVEs | SecurityOnline |
| Median publish→KEV… | 68 days | Typical case | SecurityOnline |
| Exploited before… | 28.96% | 2025 KEVs | VulnCheck |
| Weaponised within 7… | 22% | Q2 2026 CVEs | SecurityOnline |
Illustrative Timeline: A Composite 2026 Exploitation Journey
No single CVE in this brief carries a fully documented hour-by-hour timeline, so the figure below is a composite built from the aggregate 2026 data above, mapped as a typical exposure journey rather than one named vulnerability.
Reading it left to right: exploitation activity can already be underway in the week before public disclosure, consistent with Mandiant's mean of minus seven days. Within the first seven days after publication, 22% of eventually-exploited CVEs in the Q2 2026 sample are already weaponised. By the 68-day median mark, a typical exploited CVE has reached formal KEV listing under the Q2 2026 methodology; under VulnCheck's separate H1 2026 measure, the median publication-to-KEV point lands around day 80.
The gap between 'weaponised' and 'formally catalogued as known-exploited' is the real danger zone — the period where exploitation is active but an organisation relying purely on KEV-driven prioritisation may not yet see the flag.
Actionable Strategies: Building Resilience When Patching Can't Keep Up
Given a median publish-to-KEV window of 68 to 80 days but real exploitation starting within a week — or before disclosure entirely — patch speed alone cannot be the whole strategy. UK security teams need a layered approach that assumes some vulnerabilities will be exploited before a fix is deployable.
Practical steps for UK IT leaders include tightening understanding patch management around risk tiers rather than flat schedules, adopting zero trust principles so a single exploited edge device doesn't grant broad network access, and layering managed detection & response to catch exploitation activity that occurs ahead of a published advisory.
- •Maintain a live inventory of internet-facing assets and shrink that footprint wherever a service isn't operationally essential.
- •Prioritise remediation by exposure and exploitation status first — externally facing, known-exploited, identity-adjacent — rather than by severity score alone.
- •Use compensating controls (network segmentation, virtual patching, WAF rules) to buy time on flaws that can't be patched within days.
- •Build a tiered SLA structure, modelled on frameworks like CERT-In's 12-hour/1-day/5-day approach, matched to exploitation risk rather than a single blanket cadence.
- •Treat detection and response as a first-class control, not a fallback, for the window before a patch exists.
Methodology
This data study compiles figures published between March 2026 and July 2026 from vendor and industry vulnerability-intelligence research, including VulnCheck's State of Exploitation reporting, Mandiant-derived 2026 exploitation trend coverage, a Q2 2026 exploited-vulnerabilities report, and a Cloud Security Alliance research note summarising CERT-In's 2026 patch-mandate framework.
Figures were sourced from named organisations' own published reports or from named third-party summaries of those reports, and each statistic in this article retains the exact scope, time period and definition used by its original source — publication-to-KEV lag, mean versus median time to exploit, and pre- versus post-disclosure exploitation are treated as distinct, non-interchangeable measures throughout.
No figures were averaged, extrapolated or merged across sources; where the underlying research did not provide a specific data point (for example, a fully documented single-CVE exploitation timeline), this article states that explicitly rather than substituting an invented figure.
Sources
Every figure in this article traces to the sources below.
- •VulnCheck — State of Exploitation, H1 2026 (median publish-to-KEV time, 2025 vs H1 2026)
- •Mandiant / Brandefense — 2026 vulnerability exploitation trends (mean time to exploit, pre-publication exploitation)
- •SecurityOnline.info — State of Exploited Vulnerabilities, Q2 2026 (weaponisation speed, mean vs median KEV gap)
- •Cloud Security Alliance — CERT-In 12-hour patch mandate research note, 2026
- •Security Boulevard — 46 vulnerability statistics, 2026 (median time to exploit under 5 days)
- •Saptang Labs — Why time-to-exploit is shrinking faster than patch cycles, 2026
View the data behind this chart
| Layer | Detail |
|---|---|
| Known exploited, internet-facing | 12-hour patch deadline |
| Critical, externally exposed | 1-day patch deadline |
| High severity | 5-day patch window |
The 8 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).
Cite as: Servnet Research, “CVE Exploitation Speed Index 2026: The Patch-Gap Race”, servnetuk.com, 2026.
