Share on social
Sep 16, 2026
Lorem ipsum

Key Takeaways
- The exposure window, the time between a vulnerability or exposure existing and an attacker exploiting it, is the metric that matters most in security today, more than time-to-detect or time-to-respond.
- AI is compressing that window from both directions: it's speeding up how fast attackers find vulnerabilities and how fast they turn those vulnerabilities into working exploits.
- Mean time to exploit (TTE) has fallen from roughly 2.3 years in 2018, to about 56 days in 2024, to a matter of hours in 2026
- The majority of CVEs are now exploited as zero days, before public disclosure, meaning defenders often have no advance warning at all.
- Traditional patch-and-respond cycles were built for a world with weeks or months of buffer. That buffer is disappearing, which means organizations have to shift from reacting to exploitation toward preempting it - finding and fixing what matters before attackers get there.
Time Used to Be on the Defender's Side
Defenders used to have one advantage…time. A vulnerability would be discovered, a disclosure or advisory would follow, and security teams would have days, weeks, sometimes months to patch or mitigate before attackers caught up and built a working exploit. Entire security programs, from vulnerability management to incident response, were built around that assumption.
That assumption no longer holds. AI is changing the economics of vulnerability discovery, exploit development, and attack execution - making all three faster, cheaper, and accessible to a much broader range of threat actors. The result isn't a marginal improvement in attacker efficiency. It's a fundamental compression of the timeline defenders have relied on, and it's forcing a rethink of what "effective security" even means.
How Is AI Speeding Up Vulnerability Discovery?
Finding a vulnerability used to require significant manual expertise, reading source code or binaries line by line, fuzzing systems for unexpected behavior, and testing hypotheses by hand. That work took time, which meant the number of people capable of finding serious vulnerabilities quickly was limited.
AI removes much of that bottleneck. Frontier models are increasingly capable of analyzing code and systems at a scale and speed no human team could match, surfacing vulnerabilities that would previously have taken weeks of dedicated research to uncover. This doesn't just make skilled attackers faster, it lowers the skill floor required to find exploitable weaknesses in the first place, expanding the pool of actors capable of discovering vulnerabilities that were once the domain of specialized researchers.
The consequence is straightforward: the supply of newly discovered vulnerabilities is growing, and it's growing faster than most organizations' capacity to triage and address them. Gartner has forecast that documented CVEs will exceed one million by 2030, compared with roughly 277,000 in 2025 - a scale of growth that reactive, manual triage processes were never designed to absorb.
How Is AI Accelerating Exploit Development?
Discovering a vulnerability is only half the equation. Turning that vulnerability into a working, reliable exploit has traditionally required its own specialized skill set and its own chunk of time. AI is collapsing that step too.
Tasks that once required an experienced exploit developer; reasoning, chaining together exploits, working around mitigations, can increasingly be accelerated or partially automated. That means the gap between the existence of a vulnerability and a working exploit for it is shrinking in parallel with the speed at which novel vulnerabilities are found in the first place.
Put the two effects together - faster discovery and faster weaponization - and the entire attacker pipeline compresses. What once took a sequence of distinct, time-consuming stages can now happen in rapid succession, sometimes before a vulnerability has even been publicly disclosed.
Attack Timelines: Then vs. Now
The numbers make the shift concrete:
- 2018: Mean time to exploit (TTE) for weaponized exploits was approximately 2.3 years. Only about 16% of CVEs were exploited as zero days, before public disclosure.
- 2024: Organizations had, on average, 56 days between a vulnerability's disclosure and its exploitation.
- 2026: Mean time to exploit has fallen to roughly 8 hours. The majority of CVEs are now zero days - at the time of writing, around 76% of CVEs in 2026 were classified as zero-day exploitation.
That trajectory represents a collapse of years down to hours in less than a decade. It also reflects a more fundamental shift: a majority of exploitation now happens before disclosure, not after. Vulnerabilities are increasingly being discovered, researched, and weaponized in the shadows, with exploitation already underway by the time the wider market becomes aware a threat exists at all.
Why Traditional Patch-and-Respond Cycles Can't Keep Up
Most vulnerability management programs are still architected around a cycle that assumes a meaningful buffer exists: scan periodically, generate a backlog of findings, triage by severity score, schedule remediation, patch. Each of those steps takes time, and the whole cycle assumes attackers are working on a similarly unhurried timeline.
When mean time to exploit is measured in hours rather than months, a patch cycle measured in weeks is incapable of closing the gap before exploitation occurs. The volume of findings has grown well beyond what any team can triage manually, while the time available to act on the findings that matter has collapsed at the same time.
This is also why measuring success by the sheer volume of vulnerabilities identified has become counterproductive. Most organizations already have more findings, alerts, and exposures than they can realistically address. Generating more of them just grows the backlog rather than actually closing the window of exposure.
How Can Teams Close the Gap?
If reacting faster isn't a viable strategy anymore, the alternative is to stop waiting for exploitation to start the clock. That means shifting security effort further left - identifying and reducing exploitable exposure before attackers can take advantage of it, rather than detecting and responding after they already have.
Practically, that shift involves a few connected changes:
- Move from periodic to continuous assessment: Point-in-time scans can't keep pace with exposure windows measured in hours; exposure identification needs to be ongoing.
- Prioritize by exploitability, not just severity: Not every vulnerability is equally likely to be exploited - validating what's actually reachable and exploitable focuses limited remediation effort where it counts.
- Incorporate real-world attacker signals: Evidence that threat actors are actively developing exploits or targeting a given technology is a stronger prioritization signal than a severity score alone.
- Reduce the volume of what needs manual triage: Automating discovery and validation frees security teams to spend their time on remediation and risk reduction rather than investigation.
- Measure success by exposure reduced, not findings generated: The goal isn't a bigger dashboard of alerts - it's a measurably smaller exposure window.
Focus on capabilities that enable your team to consistently find and fix what matters most before an attacker ever gets the chance to act on it. That's the essence of preemptive security: closing the exposure window before attackers can exploit it, instead of racing to close it after they already have.
FAQs
What is the exposure window in cybersecurity? The exposure window is the period of time between a vulnerability or exposure existing and an attacker successfully exploiting it. It's distinct from detection-and-response metrics, which only measure how quickly a team reacts after an attack has already started.
How much has mean time to exploit (TTE) changed in recent years? TTE for weaponized exploits was around 2.3 years in 2018, fell to about 56 days by 2024, and has dropped to roughly 8 hours by 2026 - a collapse of years down to hours in under a decade.
Why are so many vulnerabilities now exploited as zero days? AI-assisted vulnerability discovery and exploit development allow attackers to research and weaponize vulnerabilities before they're publicly disclosed. As of 2026, a majority of CVEs are classified as zero-day exploitation, up from only about 16% in 2018.
Why doesn't traditional patch management work anymore? Patch-and-respond cycles were designed around the assumption of a meaningful gap between disclosure and exploitation. With mean time to exploit now measured in hours, and vulnerability volumes rising toward a projected one million CVEs by 2030, manual triage and scheduled patch cycles can't move fast enough to close the gap in time.
What does it mean to shift from reactive to preemptive security? It means focusing on identifying, validating, and reducing exploitable exposure before an attack occurs, rather than relying solely on detecting and responding to compromise after it happens. The goal shifts from responding faster to preventing the attack from having a viable opening in the first place.
Preemptive Threat Exposure Management helps security teams find, validate, and prioritize exposures before they become incidents. It combines visibility into your external attack surface with real-world threat context, so teams can focus on what attackers are actually targeting.
CTEM is about continuously managing exposure. PTEM operationalizes and evolves this by incorporating adversary-informed threat intelligence and real-time attacker insight, shifting from continuous validation to active prediction and prevention of attacks before they are launched.
Searchlight observes which exposures attackers are actively discussing and targeting, and moves those to the top of your queue with the actor context attached. Two findings with the same severity score can carry very different real-world risk, and your prioritization follows the risk.
Yes. Submit the form at the top of this page to receive a high-level overview of the risks that were identified using only your company name and domain. We’ll then cross-reference these details against over 475 billion recaptured datapoints in the Searchlight Cyber platform to deliver your dark web exposure report.







