Vulnerability Management

Hours till Exploitation

AI-assisted security review is producing CVEs faster than most organizations can patch them, and half of all disclosed vulnerabilities now have working exploit code within 15 hours. What that means for the fundamentals.

A very large number of new CVEs

Anthropic's Claude Mythos Preview made headlines recently for its ability to identify previously missed vulnerabilities in Mozilla Firefox, where it is credited with discovering 271 new security vulnerabilities, all fixed in Firefox 150. It is also the model behind Project Glasswing (opens in a new tab), an industry effort announced in April 2026 to find and fix flaws in critical software, with founding partners including AWS, Apple, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks.

I understand if anyone looks at this with a degree of skepticism — you should. The incentives are there to exaggerate and market the findings, and we do not have enough independent examples yet, because Mythos is a closed research preview rather than something the rest of us can point at our own code.

The trend line is the part that matters

Mozilla's earlier collaboration used Claude Opus 4.6 and led to fixes for 22 security-sensitive bugs in Firefox 148. The follow-on evaluation with Mythos Preview produced 271 in Firefox 150. Whatever you make of any single number, one generation of model to the next changed the volume by an order of magnitude — against the same browser, by the same vendor.

What we do know is that AI-based security reviews are leading to a significantly larger number of CVEs, and to a significantly larger amount of patching, for organizations that were already struggling to patch quickly, to prioritize what to patch, and to keep full visibility into their attack surface.

Fifteen hours, start to finish

Making this worse, the gap between the announcement of a vulnerability and the existence of working exploit code is now measured in hours rather than weeks. Zero Day Clock, which tracks time-to-exploit across more than 83,000 CVEs, puts the median at 15 hours — half of all disclosed vulnerabilities have working exploit code inside that window.

Those threat actors may also be aided by AI, or may have simply built pipelines to reverse engineer vulnerabilities in high-reward systems. The mechanism matters less than the arithmetic.

Fifteen hours is shorter than a change window. It is shorter than most approval workflows. If your patching cadence is measured in weeks, the gap between disclosure and exploitation is no longer a race you are losing slowly.

Revisit the basics

If your organization is lagging behind on vulnerability management, this should be a wake-up call to revisit the fundamentals of your security program:

  • A solid inventory of software and assets. You cannot patch what you do not know you run.
  • Timely patching of systems, with a cadence that reflects how fast exploit code actually appears.
  • Strong segmentation and attack surface reduction, so an unpatched system is not a path to everything else.
  • Least privilege identity practices, which limit what an exploited system can reach.

None of that is new advice. That is rather the point — the fundamentals did not change, but the amount of time you have to execute them did.

Sources

Time-to-exploit figure updated August 2026. These metrics move; check the tracker for the current number.

15

hours, median

From disclosure to working exploit code, across 83,000+ tracked CVEs. Zero Day Clock · updated August 2026

Not moving fast enough?

ETHOS ARC was designed to give a jolt to any security program that needs to show results.

Explore ETHOS ARC
Nicholas Pier
>_ whoami

Nicholas Pier

Principal Geek

Founder and principal engineer of ETHOS. Nicholas provides fractional CISO and red team services to customers, along with secure architecture thought leadership.

ISC2 CISSP & CSSLP #2071270, CEH, CKA, CCNP