Zero-Days & Rapid Vulnerability Exploitation
Originally reported viaCISA Known Exploited Vulnerabilities Catalogue · Google Project Zero 2025 Year in ReviewThe mean time from public vulnerability disclosure to active exploitation dropped to 4.4 days in 2025 — down from 15.7 days in 2023, according to Google Project Zero's Year in Review. For network perimeter appliances — VPNs, firewalls, load balancers — that figure has fallen further to 1.8 days. CISA's Known Exploited Vulnerabilities catalogue logged 87 zero-day entries in the first five months of 2026 alone, a 31% increase over the same window in 2025.
How AI is accelerating exploitation timelines
AI-assisted exploit generation is a primary driver of this acceleration. Tooling now exists that can take a freshly published CVE advisory, analyse the affected code path, and produce a working proof-of-concept exploit with minimal human input. This capability — previously limited to nation-state actors — is now accessible to mid-tier threat groups and sophisticated cybercriminal affiliates.
Highest-impact targets in 2026
High-profile zero-day targets in 2026 include Cisco SD-WAN (CVE-2026-series remote code execution), multiple Android kernel vulnerabilities exploited in targeted espionage campaigns, and Oracle WebLogic deserialization flaws actively leveraged by ransomware affiliates for initial access. Browser zero-days remain a persistent threat for targeted spear-phishing chains delivering fileless payloads.
The patching crisis — and how to manage it
The patching crisis is structural: the average enterprise has more critical vulnerabilities than it has patching capacity. The solution is not more patching — it is better prioritisation. EPSS (Exploit Prediction Scoring System) scores, combined with CVSS severity and CISA KEV membership, provide a risk-adjusted prioritisation model that consistently outperforms CVSS-only approaches. An internet-exposed asset with a CVSS 6.0 and an active KEV entry is far more urgent than an isolated internal system with a CVSS 9.8.
A critical CVE on an isolated internal box can wait. A CVSS 6 on an internet-facing appliance with an active KEV entry cannot. Exploitability context beats raw severity scores every time.
- Subscribe to the CISA KEV feed and treat every new entry as a P1 patch — target 24-hour remediation for internet-exposed assets.
- Prioritise network perimeter appliances (VPN, firewall, load balancer) over internal systems in patch workflows.
- Use EPSS scores alongside CVSS to risk-rank your vulnerability backlog.
- Deploy virtual patching via WAF and IPS rules for critical CVEs while permanent patches are being tested and staged.
- Verify patch application — not just deployment — for critical CVEs. Incomplete or failed patches are a leading cause of repeat exploitation.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.