Zero-day vulnerability exploitation
Back to Blog
Vulnerability Research

Zero-Days & Rapid Vulnerability Exploitation

PublishedJune 8, 2026
Read time8 min read
Share
Originally reported viaCISA Known Exploited Vulnerabilities Catalogue · Google Project Zero 2025 Year in Review

The mean time from public vulnerability disclosure to active exploitation dropped to 4.4 days in 2025 — down from 15.7 days in 2023, according to Google Project Zero's Year in Review. For network perimeter appliances — VPNs, firewalls, load balancers — that figure has fallen further to 1.8 days. CISA's Known Exploited Vulnerabilities catalogue logged 87 zero-day entries in the first five months of 2026 alone, a 31% increase over the same window in 2025.

How AI is accelerating exploitation timelines

AI-assisted exploit generation is a primary driver of this acceleration. Tooling now exists that can take a freshly published CVE advisory, analyse the affected code path, and produce a working proof-of-concept exploit with minimal human input. This capability — previously limited to nation-state actors — is now accessible to mid-tier threat groups and sophisticated cybercriminal affiliates.

Source: Google Project Zero 2025 Year in Review
Google Project Zero tracked 97 zero-day vulnerabilities exploited in the wild in 2025, with the highest concentration in browser engines (21%), mobile OS kernels (18%), and network perimeter appliances (17%). 34% of exploited zero-days in 2025 targeted products that had previously been exploited — pointing to incomplete patching and inadequate patch verification as systemic failures.

Highest-impact targets in 2026

High-profile zero-day targets in 2026 include Cisco SD-WAN (CVE-2026-series remote code execution), multiple Android kernel vulnerabilities exploited in targeted espionage campaigns, and Oracle WebLogic deserialization flaws actively leveraged by ransomware affiliates for initial access. Browser zero-days remain a persistent threat for targeted spear-phishing chains delivering fileless payloads.

Source: CISA KEV Catalogue, May 2026
CISA's KEV catalogue now serves as the de facto triage benchmark for enterprise vulnerability management. Every KEV entry represents a confirmed exploitation in the wild. Organisations not tracking KEV entries are operating without the most actionable exploitation signal available.

The patching crisis — and how to manage it

The patching crisis is structural: the average enterprise has more critical vulnerabilities than it has patching capacity. The solution is not more patching — it is better prioritisation. EPSS (Exploit Prediction Scoring System) scores, combined with CVSS severity and CISA KEV membership, provide a risk-adjusted prioritisation model that consistently outperforms CVSS-only approaches. An internet-exposed asset with a CVSS 6.0 and an active KEV entry is far more urgent than an isolated internal system with a CVSS 9.8.

A critical CVE on an isolated internal box can wait. A CVSS 6 on an internet-facing appliance with an active KEV entry cannot. Exploitability context beats raw severity scores every time.

Priya Kapoor, Vulnerability Research · Furix Feed
  • Subscribe to the CISA KEV feed and treat every new entry as a P1 patch — target 24-hour remediation for internet-exposed assets.
  • Prioritise network perimeter appliances (VPN, firewall, load balancer) over internal systems in patch workflows.
  • Use EPSS scores alongside CVSS to risk-rank your vulnerability backlog.
  • Deploy virtual patching via WAF and IPS rules for critical CVEs while permanent patches are being tested and staged.
  • Verify patch application — not just deployment — for critical CVEs. Incomplete or failed patches are a leading cause of repeat exploitation.
Furix's vulnerability prioritisation engine ingests CISA KEV, EPSS, and asset criticality data to surface the highest-risk exposures in your environment in real time.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.