Consider the ordinary logic of a security warning. A smoke alarm sounds so you can act before the fire spreads. The Common Vulnerabilities and Exposures (CVE) system, the public catalogue that tells the world a software flaw exists, is supposed to work the same way. According to Mandiant’s M-Trends 2026, the mean time to exploit a vulnerability has fallen to roughly negative seven days.
Read that again. The attack is now landing, on average, a week before the warning arrives. That is not a slow smoke alarm; it is an alarm that goes off after the building has already burned. Enterprise security budgets, cyber insurance models, and compliance frameworks were all built around a patch-on-disclosure timeline that, statistically, no longer exists.
This piece lays out what that timing inversion means for how you read cybersecurity vendor claims, weigh the risk hidden in enterprise software, and evaluate the investment thesis now forming around AI-native security tooling.
The exploit window is now measured in negative days
Start with the trend line. VulnCheck’s State of Exploitation 2026 report found that 28.96% of the vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) catalogue, the US government’s authoritative list of flaws confirmed to be under active attack, were exploited on or before the day their CVE was published in 2025. That is up from 23.6% the year before. The first half of 2026 sits at 23.43%, and the median time from CVE publication to KEV listing has fallen to 80 days.
One report is a data point. Several independent reports pointing the same direction is a pattern.
CrowdStrike observed that 42% of exploited vulnerabilities were attacked before public disclosure. Mandiant put a single number on the whole phenomenon.
Mandiant’s M-Trends 2026 reports the mean time to exploit has dropped to approximately negative seven days: exploitation now precedes disclosure by roughly a week on average.
Then there is the network telemetry, which removes any doubt that this is measurement noise. GreyNoise, which watches real-world attack traffic, documented a median 11-day gap between exploitation surges and the disclosure that was supposed to precede them. For specific vendors the lead was far longer: 39 days of pre-disclosure attack activity against Cisco, 36 days against VMware, and 24 days against MikroTik.
| Source | Key Metric | Time Period | Trend |
|---|---|---|---|
| VulnCheck | 28.96% of KEVs exploited on or before CVE publication | 2025 | Rising from 23.6% in 2024 |
| Mandiant M-Trends | Mean time to exploit approximately -7 days | 2026 | Exploitation now precedes disclosure |
| CrowdStrike | 42% of exploited flaws attacked before disclosure | Recent | Pre-disclosure attack the norm |
| GreyNoise | Median 11-day exploitation-to-disclosure gap | Recent | Cisco 39 days, VMware 36 days pre-disclosure |
Verizon’s 2026 Data Breach Investigations Report ties it back to outcomes: vulnerability exploitation is now the top initial access vector, present in 31% of studied breaches.
Put the four intelligence sources together and the conclusion is not that patching is slow. It is that the CVE disclosure system is no longer a warning at all. It is a post-incident record. Any security posture built on patch-on-disclosure is, by construction, a posture built around being late. For anyone assessing enterprise software risk or a compliance-driven security vendor, that reframes the entire incumbent tooling category as defending a timeline that has already moved.
CISA’s BOD 26-04 implementation guidance formalises the KEV catalogue’s role as a risk-based prioritisation tool, requiring federal agencies to complete forensic triage steps within defined windows whenever a vulnerability is added to the list, a mandate that implicitly acknowledges how little time defenders have once exploitation begins.
When big ASX news breaks, our subscribers know first
Case studies that put a face on the timeline failure
Statistics establish the shape of the problem. Named incidents show what it costs when a real organisation is on the receiving end.
Consider three cases in sequence:
- Ivanti Connect Secure (CVE-2023-46805 and CVE-2024-21887). Mandiant and Google Threat Intelligence documented zero-day exploitation by suspected China-nexus actor UNC5221 beginning 3 December 2023. Public disclosure did not arrive until 10 January 2024. Mass exploitation followed the very next day, on 11 January 2024. The disclosure did not warn defenders ahead of the attackers; it fired a starting gun for the wider criminal field.
- Ivanti Connect Secure again (CVE-2025-0282). Exploitation of Connect Secure, Policy Secure, and Neurons for ZTA gateways began in mid-December 2024, weeks before Ivanti released patches and disclosed the flaw in January 2025. Same vendor, same sequence. That tells you the first case was not a one-off but a repeating institutional failure.
- Fortinet FortiClient VPN. In late 2024, Volexity disclosed that Chinese state-sponsored actor BrazenBamboo was exploiting a credential disclosure zero-day. It had been reported to Fortinet in July 2024. As of November 2024, it remained unpatched, with no CVE assigned at all.
The China-nexus attribution running through all three cases is worth pausing on. This is not opportunistic crime exploiting a gap by luck; it is well-resourced state actors systematically operating inside a window the disclosure system leaves open. That elevates the issue from vendor risk to geopolitical and systemic infrastructure risk.
When disclosure never comes
The Fortinet case is the most instructive, because it breaks a hidden assumption. The CVE system is voluntary at the vendor level. No law compels a software maker to assign an identifier or publish a patch on any timeline.
So the Fortinet scenario, a live zero-day exploited by a state actor for months with no CVE and no fix, is not an anomaly. It is a structural possibility for any piece of proprietary software you rely on.
That matters for how you read a vendor’s security posture. Some fraction of the flaws in any enterprise software stack have no assigned CVE and no vendor patch timeline whatsoever. Against that fraction, patching is not merely late; it is impossible. The only available defence is finding the vulnerability yourself, before anyone assigns it a number. That is precisely where the next part of the story begins.
How frontier AI is being redirected toward pre-disclosure defence
If the problem is that vulnerabilities are exploited before humans catalogue them, the response has to operate before the catalogue too. That is the explicit design goal of the industry’s most notable recent move.
Anthropic launched Project Glasswing on 7 April 2026, describing it as a collaborative effort to secure the world’s most critical software for the AI era. Powered by its frontier model Claude Mythos Preview, the programme redirects large language model capability toward defensive discovery, finding and fixing flaws before disclosure rather than exploiting them.
The commitment behind it signals institutional seriousness rather than a marketing gesture. Anthropic pledged up to $100M in usage credits and $4M in direct donations to open-source security organisations. The founding cohort of twelve partners spanned the core of the modern technology stack:
- Cloud infrastructure: Amazon Web Services, Google, Microsoft
- Security vendors: Broadcom, Cisco, CrowdStrike, Palo Alto Networks
- Hardware and platform: Apple, NVIDIA
- Institutional anchors: Anthropic, JPMorgan Chase, Linux Foundation
By 2 June 2026, the programme had expanded from roughly 50 initial partners to about 200. The output justified the scale.
Anthropic’s institutional positioning in security carries a complication that the Project Glasswing announcement does not address: the company was removed from the US defence AI market in January 2026 after refusing to allow its models to support autonomous weapons or mass surveillance, a policy choice that shapes which enterprise and government buyers can access its frontier capability.
Project Glasswing partners used the model to identify more than 10,000 high- or critical-severity vulnerabilities across systemically important software.
That figure settles the earlier question. Frontier AI is already functioning as a pre-disclosure detection layer at scale. The open question for you as an investor is no longer whether AI can do this. It is which vendors are integrating it deeply enough to matter.
Checkmarx, an application security firm with roughly two decades of enterprise AppSec experience, joined the programme on 3-4 September 2026 and secured early access to Claude Mythos 5. It represents the practitioner layer, the people who actually run scans against enterprise code.
What hybrid scanning architecture actually means
Traditional static application security testing (SAST), which analyses source code for flaws before it runs, works by matching against known patterns and signatures. It is deterministic and auditable, but it can only catch what it already has a rule for. A vulnerability with no known signature is invisible to it.
Frontier AI reasoning works differently. It can read code logic and surface a novel flaw that no rule anticipated, with no CVE or signature attached. Checkmarx integrates both into a hybrid architecture called Checkmarx Fusion, built on a Multi-Model AI Engine, and reports an overall F1 score of 0.74.
That number is a precision-recall balance metric: it measures whether a tool catches real flaws without drowning users in false alarms. A scanner that flags everything is operationally useless at enterprise scale, because analysts cannot triage the noise. The durable competitive advantage, then, is forming in systems that fuse deterministic scanning with AI reasoning, not in either approach alone.
Where dual-use risk and governance gaps threaten the thesis
The optimism has a mirror image. The same frontier capability that finds vulnerabilities before disclosure also lowers the cost of attacking them, and the tools themselves carry fresh weaknesses. Three unresolved tensions complicate the thesis without cancelling it:
- Offensive cost reduction (economic): An IEEE/Computer Society analysis concludes that instruction-following LLMs can produce targeted malicious content far more cheaply than human effort, sharpening the economic incentive for attackers.
- Prompt injection vulnerability (technical): Meta’s CYBERSECEVAL 2 benchmarking found prompt injection success rates of 25-50% across tested models, and Checkmarx practitioners warn that AI code reviewers can themselves be tricked into executing unsafe code.
- Governance framework lag (structural): The NIST AI Risk Management Framework (NIST AI 600-1) warns that generative AI expands the attack surface via prompt injection and data poisoning, while analyses from MITRE, Censinet, and Truefoundry find existing frameworks lack technical controls for securing training pipelines or agent architectures.
Governance framework lag is not unique to the enterprise software stack: APRA’s April 2026 letter to Australian regulated entities identified the same pattern at the institutional level, flagging that board-level AI literacy and vendor exit planning have not kept pace with the AI-assisted threat environment that security teams are actually operating inside.
The prompt injection figure is the one to sit with. Prompt injection means feeding an AI system crafted input that overrides its instructions. A 25-50% success rate tells you that the AI being deployed as defensive infrastructure carries its own exploitable attack surface. So the investor question is not only whether a vendor uses AI, but whether it has secured the AI layer itself.
That points to a spending imbalance worth watching, though the specific figures below are unverified directional estimates rather than precise citations.
| Category | Estimated 2025 Spend | Status |
|---|---|---|
| AI-amplified security tooling | ~$49 billion | Unverified estimate |
| Securing AI systems themselves | ~$2.8 billion | Unverified estimate |
Even as an illustration, the gap is the point. Money is pouring into AI-powered security tools far faster than into hardening those tools against attack. The vendors that have invested in securing their own AI infrastructure are structurally better placed than those that have wrapped legacy tooling in AI branding.
What the exploit-window inversion means for your investment framework
The category is large and growing fast. Gartner projects worldwide end-user information security spending of $213 billion in 2025, with the application security testing market alone at $5.1 billion. The broader AI cybersecurity market is growing at a 73.9% CAGR, from $26 billion toward $172 billion, and Gartner expects over 75% of enterprises to use AI-amplified cybersecurity products for most use cases by 2028.
Cybersecurity sector spending forecasts from Gartner, IDC, and Forrester collectively project the market reaching US$377 billion by 2028, with software accounting for roughly 69% of that figure by 2029, a composition that favours platform consolidators over point-solution vendors whose relevance depends on a single detection category staying dominant.
Here is the trap in those numbers. A 73.9% growth rate is not a reason to buy the category broadly. Growth lifts the sector’s revenue, but it does not distribute evenly, and it is precisely when a category is expanding this fast that AI branding gets bolted onto tooling that cannot deliver on it.
The exploit-window inversion hands you a sharper filter. The vendors best positioned combine deterministic scanning with frontier AI reasoning rather than one alone, can demonstrate genuine pre-disclosure detection, and have secured their own AI layer instead of treating it as a bolt-on feature.
Compliance-driven vendor signals such as ISM certification, renewal patterns, and sovereign client rosters carry a different type of information than AI feature announcements: they represent ongoing performance verification under active institutional scrutiny rather than claimed capability, which is precisely the distinction the exploit-window inversion makes consequential.
J.P. Morgan gave the underlying condition a name.
J.P. Morgan’s Eye on the Market report of 22 July 2026, titled “Patchmageddon,” frames the environment as a “patching emergency” driven by AI-accelerated vulnerability discovery, under-resourced open-source maintainers, and long-lived operational technology.
Three structural signals are worth watching as you position:
- Compression of exploit windows: the faster the gap between exploitation and disclosure widens into negative territory, the more it accelerates demand for pre-disclosure tooling.
- Regulatory response: any move to compel faster disclosure or mandate pre-disclosure detection becomes a compliance driver for enterprise adoption.
- AI platform security spending: the gap between money spent on AI-amplified security and money spent securing AI platforms is the emerging competitive differentiator.
The right question is no longer “does this vendor use AI?” It is “can this vendor find flaws before the CVE exists, and has it secured its own AI infrastructure?”
The patching window is already gone. The question is what replaces it.
The evidence from VulnCheck, Mandiant, and CrowdStrike converges on one uncomfortable finding: the CVE-patch cycle no longer works as a primary defence. When the mean time to exploit sits at roughly negative seven days, the industry has already shifted from a patching race to a pre-disclosure detection race, and AI is the only tooling that runs at that speed. Project Glasswing’s more than 10,000 critical vulnerabilities found before disclosure show that layer is real and operating now.
The tensions are real too. The same capability that enables pre-disclosure defence lowers the cost of attack, and governance frameworks have not caught up to how frontier models actually behave inside security workflows. Several figures in the wider debate, including J.P. Morgan’s 80% pre-disclosure estimate and various CSA projections, remain contested. The investor case rests on the verified direction of travel, not any single precise number.
Treat the exploit-window inversion as a filter, not a buy signal. It is a structural market condition, and the vendors closing that gap with genuine hybrid capability, rather than AI branding, are the ones worth watching as CVE volume climbs.
This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions. Past performance does not guarantee future results. Financial projections are subject to market conditions and various risk factors, and forward-looking statements are speculative and subject to change based on market developments.

