AI-Powered Vulnerability Management: Exploits Faster Than Patches
- AUGUST 17TH, 2026
- 2min read
Artificial intelligence is fundamentally changing how organisations identify, prioritise, and remediate vulnerabilities. Anthropic’s Project Glasswing has shown that advanced AI models can uncover thousands of previously unknown vulnerabilities across widely used software. The same capabilities that help defenders identify and remediate vulnerabilities more efficiently can also enable adversaries to analyse code, identify weaknesses, and develop exploits at much greater speed.
What has Changed
The challenge is no longer simply the number of vulnerabilities organisations face; it is the speed at which they can be exploited. Research data now shows time-to-exploit outpacing time-to-patch: 88% of observed exploitation against vulnerabilities with public proof-of-concept code occurs within 48 hours of that code’s release, while the average patch cycle still runs around 43 days. Total disclosed vulnerabilities are also climbing sharply; 2026 volumes are on pace to reach roughly 66,000, up substantially from prior years driven in large part by AI-assisted discovery tooling on both sides of the fence.
Traditional vulnerability management programmes were designed around periodic scanning and scheduled patching. AI has shifted the focus towards continuous exposure management, where organisations must rapidly determine which vulnerabilities are exploitable, exposed, and most likely to be targeted, and the fastest responders will increasingly have the advantage.
How to Protect Your Organisation
1. Implement Continuous Exposure Monitoring: Use AI-assisted exposure discovery to detect issues faster than periodic scan cycles can, monitor active exploitation, and prioritise vulnerabilities targeted in the wild, publicly exposed, or affecting critical business systems over those merely disclosed
2. Accelerate Remediation: Reduce the time between detection, validation, patching, and verification through clearly defined remediation workflows and ownership.
3. Apply Compensating Controls: Use network segmentation, web application firewalls, endpoint protection, and access restrictions where immediate patching is not possible.
Explore more CIL Advisories
Backdoor.ClickFix – The Fake Verification Trap
Hackers are increasingly exploiting human trust through a clever social engineering technique known as "ClickFix" (or "Pastejacking"). They trick Microsoft…
AUGUST 31ST, 2026
Read More
Defence Against Living-off-the-Cloud (LotC) & Trusted Infrastructure Abuse
Threat actors are abandoning easily blocked, newly registered domains in favour of hosting their Command and Control (C2) servers and…
AUGUST 24TH, 2026
Read More
Active Exploitation Alert: SharePoint Authentication Bypass
A critical authentication bypass vulnerability in Microsoft SharePoint Server is now under active exploitation following the public release of technical…
AUGUST 19TH, 2026
Read MoreNever miss a CIL Security Advisory
Stay informed with the latest security updates and insights from CIL.