When a critical vulnerability in a widely used VPN appliance or file-transfer tool hits the public record, security teams typically have days or weeks before a patch is tested, approved, and deployed. Attackers, increasingly, need less than a day. According to Mandiant’s M-Trends 2024 report, roughly 28 percent of new vulnerabilities the firm tracked were weaponized within 24 hours of public disclosure. That figure, drawn from Mandiant’s incident response and threat intelligence work across hundreds of engagements in 2023, describes a speed of exploitation that collides directly with the remediation timelines most organizations actually operate on.
“The window between disclosure and exploitation has compressed to the point where traditional patch cycles are no longer a viable primary defense for internet-facing assets,” said John Hultquist, Mandiant’s Chief Analyst at Google Cloud, summarizing the firm’s findings in the M-Trends 2024 report.
The gap is not abstract. Federal civilian agencies bound by CISA’s Binding Operational Directive 22-01 are given 14 days to patch critical vulnerabilities and 25 days for high-severity flaws once they appear in the Known Exploited Vulnerabilities (KEV) catalog. Most private-sector organizations work on 30-day patch cycles or longer. If nearly three in ten exploits are live before the first business day after disclosure ends, those timelines are not just slow. They are structurally outmatched.
What the federal framework actually tracks
The U.S. government has built a formal apparatus around known, actively exploited vulnerabilities, but it was designed to enforce accountability, not to measure speed.
CISA’s KEV catalog is a curated, public list of vulnerabilities with confirmed exploitation in the wild. Each entry triggers a remediation deadline for federal civilian executive branch agencies under BOD 22-01, which draws its legal authority from Title 44 of the U.S. Code (sections 3552 and 3553). Those statutes assign information security responsibilities across the federal enterprise and create a chain of accountability from agency CIOs up through the Office of Management and Budget.
What the catalog does not record is the interval between initial disclosure and first observed exploit activity. It confirms that exploitation happened. It does not tell defenders how quickly it happened.
On the disclosure side, NIST’s National Vulnerability Database (NVD) publishes CVE records with metadata that sometimes includes references to proof-of-concept code. NVD publication dates are the most widely used public timestamp for when a vulnerability enters the open record. But the database has no built-in field that tracks when exploit code first appeared relative to that date. Security teams can check individual entries manually, but there is no systematic, government-maintained measurement of the disclosure-to-weaponization window.
NIST’s broader ecosystem, including the National Checklist Program and the SP 800-53 security control catalog, helps organizations harden systems before a specific exploit arrives. These tools operate on planning timescales measured in weeks or months, not the hours that rapid weaponization now demands.
Where the data runs out
The core difficulty with the Mandiant finding is verification. No publicly available dataset cross-references specific CVE records from the NVD against Mandiant’s 24-hour weaponization timestamps. The 28 percent figure comes from proprietary threat intelligence, and the firm’s methodology, sample size, and the specific vulnerability families counted have not been independently replicated through open government data.
That said, the trend line is corroborated. Rapid7’s 2024 Attack Intelligence Report found that more mass compromise events in 2023 originated from zero-day or near-zero-day exploitation than from vulnerabilities with patches already available. Palo Alto Networks’ Unit 42 has documented similar compression in exploit timelines across its incident response caseload. The specific number may be Mandiant’s, but the pattern is broadly observed across the industry.
“We are seeing a continued increase in the speed at which attackers operationalize newly disclosed vulnerabilities,” noted Caitlin Condon, Director of Vulnerability Intelligence at Rapid7, in the firm’s 2024 report. “The era of leisurely patch cycles for externally facing systems is effectively over.”
What remains invisible is how federal agencies actually perform against BOD 22-01 deadlines when the underlying flaw was weaponized on day one. CISA does not publish agency-level compliance rates. The Government Accountability Office has repeatedly flagged weaknesses in federal patch management, including a 2023 report that found persistent gaps in agencies’ ability to remediate known vulnerabilities on time, but no public audit has specifically measured outcomes for vulnerabilities exploited within hours of disclosure.
Scope is another open question. BOD 22-01 applies only to federal civilian executive branch agencies. State governments, municipalities, hospitals, utilities, and private companies face no binding federal patch timeline for KEV-listed flaws. Whether the 28 percent figure concentrates in specific product categories, such as the edge devices, VPN appliances, and file-transfer tools that Mandiant’s M-Trends report highlighted as frequent targets, or distributes evenly across all software is not specified in the public evidence.
Sorting the strong evidence from the soft
Three layers of evidence sit beneath this story, and they differ sharply in what they can prove.
The strongest layer is the federal policy record. BOD 22-01 is a binding legal instrument with clear deadlines and statutory authority. The KEV catalog is a government-maintained list of confirmed exploited vulnerabilities. The NVD is the authoritative public registry for CVE records and disclosure dates. These are primary documents. They define the rules and the official timeline.
The second layer is commercial threat intelligence. Mandiant is one of the most widely cited incident response firms in the industry, now operating under Google Cloud. Its 28 percent finding aligns with corroborating research from Rapid7, Unit 42, and Google’s own Threat Analysis Group. Readers should treat the figure as expert assessment from credible commercial sources rather than as a government-validated statistic, but the convergence across multiple firms strengthens the claim considerably.
The third layer, and the weakest, is the feedback loop between policy and outcomes. No public dataset currently measures whether patches land before exploits do on federal networks, let alone on state, local, or private-sector systems. The statutory duties create accountability on paper. The directive creates deadlines. The catalog creates a target list. But the data on whether any of it works fast enough against same-day exploitation simply is not visible to the public as of June 2026.
Why patch-cycle math now favors attackers targeting internet-facing systems
For security teams outside the federal government, the math is blunt. If 28 percent of new vulnerabilities face weaponization within a single day, any patch cycle measured in weeks is operating on a timeline that attackers have already outrun. Organizations that wait for monthly vendor-scheduled updates or batch their patching into quarterly maintenance windows are accepting a window of exposure that threat intelligence data says is actively being exploited.
The first practical step is measurement. Teams should audit how quickly their own organization moves from CVE publication to deployed fix for internet-facing systems, particularly edge devices, remote-access gateways, and file-transfer platforms, the categories Mandiant flagged as most frequently targeted. Where that internal metric is measured in days or weeks against threats that materialize in hours, the risk is not theoretical. It is operational, and it is already being exploited at scale.
More from Morning Overview
*This article was researched with the help of AI, with human editors creating the final content.