ZERO-DAY INTELLIGENCE

The Zero-Day Clock
is already running.

A 10-year view of vulnerability disclosure, weaponization, and exploitation - and why modern vulnerability management has to assume that some high-value vulnerabilities may already be under attack.

SEE THE FAST EXPLOITATION TIMELINE ↓

ZERO-DAY CLOCK
BEFORE Exploitation observedDAY ZERO Patch availableAFTER Defend and verify

Mandiant’s 2025 incident dataset estimated exploitation began seven days before patch availability on average. This is a research finding, not a live countdown.

2020 average TTKE42 daysRapid7 dataset
2021 average TTKE12 days71% faster vs. 2020
2022 median TTKE1 day56% exploited ≤ 7 days
2025 mean exploit lead7 days before patchMandiant incident dataset
Zero-day is different from “fast exploitation.”

A true zero-day is already being exploited before defenders receive the normal benefit of public disclosure and a broadly available fix or mitigation. For that reason, the practical defender reaction window can be zero - or effectively negative.

TIME ON THIS PAGE00:00

A record-speed attacker could still be establishing a foothold.

Illustrative threat-velocity monitor. The marker uses real elapsed time on a logarithmic scale; it does not monitor an active attack.

Fast exploitation

How fast? Follow the decade.

Follow the evidence from 2016 to the latest 2026 findings. Duration, zero-day prevalence, and catalog timing are labeled separately.

PATCH WINDOW7 days early

On average, exploitation began seven days before a patch was available in Mandiant’s 2025 incident dataset.

63 days in 2018–2019 → past zero
BREAKOUT WINDOW29 min

Average 2025 eCrime time from initial access to lateral movement.

9h 42m in 2019 → 29 min
DETECTION WINDOW14 days

Global median dwell time in Mandiant’s 2025 investigations.

416 days in 2011 · up from 11 in 2024

2016–2026

The decade timeline: 2016–2026

These figures measure different populations and timing definitions; averages, medians, and KEV inclusion are not a single comparable annual series. They do not measure private attacker intent.

The strongest directly comparable exploitation-speed series begins around 2020. Earlier years are shown as historical context rather than given invented annual averages.

Then vs. now

2016: no comparable exploitation-time baseline in these sources. Latest H1 2026 evidence: 23.43% exploited on or before CVE publication. A reliable “X times faster than 2016” calculation is not available.

A directly comparable change: 2020 → 2021

Rapid7 average time to known exploitation · Same reported comparison

2020 · 42 days
2021 · 12 days

30 days shorter · approximately 71% less time. Bar lengths share a 0–42 day scale.

Rapid7 comparison ↗
2016
Context
Threat and vulnerability discussion was increasingly appearing outside formal vulnerability databases, giving both defenders and adversaries earlier visibility than NVD publication alone.
2017
~7-day lead
Recorded Future reported a median seven-day lead between early web/social disclosure and NVD publication for 75% of vulnerabilities studied since 2016.
2018
Pre-baseline
No directly comparable annual TTKE figure in the cited Rapid7 series. The key trend was widening reliance on intelligence sources beyond formal vulnerability publication.
2019
Pre-baseline
Rapid7's later multi-year analysis includes data dating back to 2019, immediately before the sharp acceleration visible in 2020–2022.
2020
42 days avg.
Average time to known exploitation in Rapid7's comparison was 42 days; about 30% of vulnerabilities were exploited within seven days.
2021
12 days avg.
52% of known exploited vulnerabilities in the report came under attack within one week. More than half of widespread threats began with zero-day exploitation.
2022
1 day median
56% were exploited within seven days of disclosure. Rapid7 reported a one-day median in its 2022 dataset.
2023
Zero-day norm
53% of widely exploited CVEs tracked in 2023 and early 2024 began as zero-day attacks. Rapid7's cumulative 2020–2024 median TTKE was one day.
2024
8.5 days
For high/critical vulnerabilities published in 2024 and later added to CISA KEV, Rapid7's 2026 analysis found an 8.5-day median from publication to KEV inclusion. This is not the same metric as TTKE.
2025
7 days before patch
Mandiant estimated that exploitation preceded patch availability by seven days on average in its 2025 incident dataset. In a different high/critical set, Rapid7 measured a five-day median from publication to CISA KEV inclusion.
2026
23.43% by publication
H1 2026: exploitation evidence on or before CVE publication in VulnCheck’s known-exploited set. This is a share, not an average duration. 2026 sources and definitions ↓

Why the public response clock can start too late

23.43%

of VulnCheck’s H1 2026 known-exploited set showed exploitation evidence on or before CVE publication.

Explore the evidence ↓
01 / BEFORE

Zero-day exploitation

An attack can precede public awareness and an available fix. Prepare detection and containment before an advisory arrives.

02 / AFTER

Fast exploitation

Attacks can follow disclosure quickly. Prioritize exposed, known-exploited systems and apply vendor mitigations promptly.

03 / RESPOND

Act on exposure

Identify affected assets, reduce access, investigate compromise, and verify remediation. A catalog delay is not a safe patching window.

CVE publication alone does not establish zero-day status. Source: VulnCheck, July 28, 2026 ↗

2026 evidence update · Reviewed September 9, 2026

Different clocks. Different response windows.

Separate research published in 2026 from activity observed during 2026. These studies cover different populations: zero-day counts, catalog timing, and movement after compromise cannot be combined into one time-to-exploit average.

23.43% exploited by CVE publication

VulnCheck identified 495 known-exploited vulnerabilities in the first half of 2026. Nearly one-quarter showed exploitation evidence on or before CVE publication; this does not make every case a confirmed zero-day.

Published July 28, 2026 · Observation period: January–June 2026.

VulnCheck: H1 2026 research ↗
Early exploitation volume stayed roughly steady

VulnCheck reports about 200 CVEs reaching known-exploited status within 31 days in H1 2026, broadly in line with its comparison cohorts. Its reported median publication-to-KEV interval fell from 120 to 80 days. This broader VulnCheck dataset is different from Rapid7’s high/critical CISA KEV dataset.

Evidence can emerge late; the 2026 cohort is still developing.

Read the methodology and limitations ↗
90 confirmed exploited zero-days

Google Threat Intelligence Group tracked 90 zero-days exploited in the wild in 2025. Enterprise technologies accounted for 43, or 48%, of that total. This measures zero-day prevalence, not exploitation speed.

Published March 5, 2026 · Observation period: 2025.

Google: 2025 Zero-Days in Review ↗
29-minute average criminal breakout time

CrowdStrike reports an average eCrime breakout time of 29 minutes in 2025, with the fastest observed at 27 seconds. Breakout concerns movement beyond the initial compromised system; it is not time from vulnerability disclosure to exploitation.

Published February 2026 · Observation period: 2025.

CrowdStrike: 2026 Global Threat Report ↗
5-day median to CISA KEV inclusion

Rapid7’s analyzed high/critical set shows the median from publication to CISA KEV inclusion declining from 8.5 days in 2024 to 5 days in 2025. Catalog inclusion can follow the first attack, so this is not a guaranteed five-day patch window.

Published March 18, 2026 · Observation periods: 2024 and 2025.

Rapid7: 2026 Global Threat Landscape Report ↗
Exploitation began 7 days before patch availability

Mandiant’s M-Trends 2026 analysis estimates that exploitation occurred seven days before a patch was available on average. The figure comes from more than 500,000 hours of incident investigations conducted in 2025 and uses patch availability as its reference point.

Published March 23, 2026 · Observation period: 2025.

Mandiant: M-Trends 2026 ↗

Operational takeaway: use exposure and confirmed exploitation to prioritize remediation, and prepare to contain an intrusion quickly. The latest evidence supports urgency, but not a claim that every exploitation measure accelerates each year.

Inside the response window

Attackers measure progress in minutes.

Breakout time and dwell time measure different parts of an intrusion. Explore each trend, then follow what can happen inside the current 29-minute average breakout window.

ATTACKER CLOCK

Average breakout time

Lower means attackers are moving laterally faster.

DEFENDER CLOCK

Median dwell time

Lower means defenders are detecting intrusions sooner.

00:0001

Initial access

Stolen credentials, phishing, or an exposed vulnerable system starts the clock.

00:2702

Fastest breakout

The fastest observed 2025 eCrime actor reached another system in 27 seconds.

MINUTES03

Expand access

Discovery, privilege escalation, persistence, collection, and defensive evasion can follow quickly.

29:0004

Average breakout

By the average mark, the incident has moved beyond the initially compromised host.

Sources: CrowdStrike 2026 Global Threat Report ↗ and Mandiant M-Trends 2026 ↗. Vendor datasets and methods differ.

Operational interpretation

What this should change

Internet-facing systems need emergency SLAs

A standard 30-day critical patch SLA is often inappropriate for known-exploited perimeter, remote-access, security-appliance, and file-transfer vulnerabilities.

CVSS alone is not prioritization

Combine exploit evidence, CISA KEV status, exposure, authentication requirements, asset criticality, ransomware use, and compensating controls.

Assume parallel exploit development

Threat actors, researchers, vendors, and brokers may be analyzing the same flaw simultaneously. Public PoC code can further compress operationalization time.

Zero-day response starts before patching

Use mitigations, isolation, access restrictions, threat hunting, telemetry, IOC validation, and configuration changes while waiting for a durable fix.

Research sources

Primary references

Rapid7 - 2021 Vulnerability Intelligence Report

42-day average TTKE in 2020; 12 days in 2021; 52% exploited within one week.

View source ↗
Rapid7 - 2022 Vulnerability Intelligence Report

56% exploited within seven days; one-day median for the 2022 dataset.

View source ↗
Rapid7 - 2024 Attack Intelligence Report

One-day cumulative median TTKE and sustained zero-day mass compromise.

View source ↗
Rapid7 - 2026 Global Threat Landscape Report

Publication-to-KEV median fell from 8.5 days in 2024 to 5.0 days in 2025 for the analyzed high/critical set.

View source ↗
Mandiant - M-Trends 2026

Estimated mean time to exploit was seven days before patch availability across the report’s 2025 incident dataset.

View source ↗
Mandiant - 2023 Time-to-Exploit Analysis

Average time to exploit fell from 63 days in 2018–2019 to five days in 2023.

View source ↗
Mandiant - M-Trends 2019

Historical baseline: global median dwell time was 416 days in 2011 and 78 days in 2018.

View source ↗
CrowdStrike - 2026 Global Threat Report

Average 2025 eCrime breakout time was 29 minutes; the fastest observed breakout was 27 seconds.

View source ↗
Recorded Future - Vulnerability Disclosure Delay

Historical context showing vulnerability intelligence often preceded NVD publication.

View source ↗
VulnCheck - Exploitation Timeline

Ongoing research on disclosure-to-exploitation timing.

View source ↗