On average, exploitation began seven days before a patch was available in Mandiant’s 2025 incident dataset.
63 days in 2018–2019 → past zeroZERO-DAY INTELLIGENCE
The Zero-Day Clock
is already running.
A 10-year view of vulnerability disclosure, weaponization, and exploitation - and why modern vulnerability management has to assume that some high-value vulnerabilities may already be under attack.
Mandiant’s 2025 incident dataset estimated exploitation began seven days before patch availability on average. This is a research finding, not a live countdown.
A true zero-day is already being exploited before defenders receive the normal benefit of public disclosure and a broadly available fix or mitigation. For that reason, the practical defender reaction window can be zero - or effectively negative.
A record-speed attacker could still be establishing a foothold.
Illustrative threat-velocity monitor. The marker uses real elapsed time on a logarithmic scale; it does not monitor an active attack.
Fast exploitation
How fast? Follow the decade.
Follow the evidence from 2016 to the latest 2026 findings. Duration, zero-day prevalence, and catalog timing are labeled separately.
Average 2025 eCrime time from initial access to lateral movement.
9h 42m in 2019 → 29 minGlobal median dwell time in Mandiant’s 2025 investigations.
416 days in 2011 · up from 11 in 20242016–2026
The decade timeline: 2016–2026
These figures measure different populations and timing definitions; averages, medians, and KEV inclusion are not a single comparable annual series. They do not measure private attacker intent.
The strongest directly comparable exploitation-speed series begins around 2020. Earlier years are shown as historical context rather than given invented annual averages.
2016: no comparable exploitation-time baseline in these sources. Latest H1 2026 evidence: 23.43% exploited on or before CVE publication. A reliable “X times faster than 2016” calculation is not available.
A directly comparable change: 2020 → 2021
Rapid7 average time to known exploitation · Same reported comparison
30 days shorter · approximately 71% less time. Bar lengths share a 0–42 day scale.
Rapid7 comparison ↗Why the public response clock can start too late
of VulnCheck’s H1 2026 known-exploited set showed exploitation evidence on or before CVE publication.
Explore the evidence ↓Conceptual sequence · Animation is not a measured timescale or live threat feed.
Zero-day exploitation
An attack can precede public awareness and an available fix. Prepare detection and containment before an advisory arrives.
Fast exploitation
Attacks can follow disclosure quickly. Prioritize exposed, known-exploited systems and apply vendor mitigations promptly.
Act on exposure
Identify affected assets, reduce access, investigate compromise, and verify remediation. A catalog delay is not a safe patching window.
CVE publication alone does not establish zero-day status. Source: VulnCheck, July 28, 2026 ↗
2026 evidence update · Reviewed September 9, 2026
Different clocks. Different response windows.
Separate research published in 2026 from activity observed during 2026. These studies cover different populations: zero-day counts, catalog timing, and movement after compromise cannot be combined into one time-to-exploit average.
VulnCheck identified 495 known-exploited vulnerabilities in the first half of 2026. Nearly one-quarter showed exploitation evidence on or before CVE publication; this does not make every case a confirmed zero-day.
Published July 28, 2026 · Observation period: January–June 2026.
VulnCheck: H1 2026 research ↗VulnCheck reports about 200 CVEs reaching known-exploited status within 31 days in H1 2026, broadly in line with its comparison cohorts. Its reported median publication-to-KEV interval fell from 120 to 80 days. This broader VulnCheck dataset is different from Rapid7’s high/critical CISA KEV dataset.
Evidence can emerge late; the 2026 cohort is still developing.
Read the methodology and limitations ↗Google Threat Intelligence Group tracked 90 zero-days exploited in the wild in 2025. Enterprise technologies accounted for 43, or 48%, of that total. This measures zero-day prevalence, not exploitation speed.
Published March 5, 2026 · Observation period: 2025.
Google: 2025 Zero-Days in Review ↗CrowdStrike reports an average eCrime breakout time of 29 minutes in 2025, with the fastest observed at 27 seconds. Breakout concerns movement beyond the initial compromised system; it is not time from vulnerability disclosure to exploitation.
Published February 2026 · Observation period: 2025.
CrowdStrike: 2026 Global Threat Report ↗Rapid7’s analyzed high/critical set shows the median from publication to CISA KEV inclusion declining from 8.5 days in 2024 to 5 days in 2025. Catalog inclusion can follow the first attack, so this is not a guaranteed five-day patch window.
Published March 18, 2026 · Observation periods: 2024 and 2025.
Rapid7: 2026 Global Threat Landscape Report ↗Mandiant’s M-Trends 2026 analysis estimates that exploitation occurred seven days before a patch was available on average. The figure comes from more than 500,000 hours of incident investigations conducted in 2025 and uses patch availability as its reference point.
Published March 23, 2026 · Observation period: 2025.
Mandiant: M-Trends 2026 ↗Operational takeaway: use exposure and confirmed exploitation to prioritize remediation, and prepare to contain an intrusion quickly. The latest evidence supports urgency, but not a claim that every exploitation measure accelerates each year.
Inside the response window
Attackers measure progress in minutes.
Breakout time and dwell time measure different parts of an intrusion. Explore each trend, then follow what can happen inside the current 29-minute average breakout window.
Average breakout time
| YEAR | AVERAGE BREAKOUT |
|---|
Lower means attackers are moving laterally faster.
Median dwell time
| YEAR | MEDIAN DWELL |
|---|
Lower means defenders are detecting intrusions sooner.
Initial access
Stolen credentials, phishing, or an exposed vulnerable system starts the clock.
Fastest breakout
The fastest observed 2025 eCrime actor reached another system in 27 seconds.
Expand access
Discovery, privilege escalation, persistence, collection, and defensive evasion can follow quickly.
Average breakout
By the average mark, the incident has moved beyond the initially compromised host.
Sources: CrowdStrike 2026 Global Threat Report ↗ and Mandiant M-Trends 2026 ↗. Vendor datasets and methods differ.
Operational interpretation
What this should change
Internet-facing systems need emergency SLAs
A standard 30-day critical patch SLA is often inappropriate for known-exploited perimeter, remote-access, security-appliance, and file-transfer vulnerabilities.
CVSS alone is not prioritization
Combine exploit evidence, CISA KEV status, exposure, authentication requirements, asset criticality, ransomware use, and compensating controls.
Assume parallel exploit development
Threat actors, researchers, vendors, and brokers may be analyzing the same flaw simultaneously. Public PoC code can further compress operationalization time.
Zero-day response starts before patching
Use mitigations, isolation, access restrictions, threat hunting, telemetry, IOC validation, and configuration changes while waiting for a durable fix.
Research sources
Primary references
42-day average TTKE in 2020; 12 days in 2021; 52% exploited within one week.
View source ↗56% exploited within seven days; one-day median for the 2022 dataset.
View source ↗One-day cumulative median TTKE and sustained zero-day mass compromise.
View source ↗Publication-to-KEV median fell from 8.5 days in 2024 to 5.0 days in 2025 for the analyzed high/critical set.
View source ↗Estimated mean time to exploit was seven days before patch availability across the report’s 2025 incident dataset.
View source ↗Average time to exploit fell from 63 days in 2018–2019 to five days in 2023.
View source ↗Historical baseline: global median dwell time was 416 days in 2011 and 78 days in 2018.
View source ↗Average 2025 eCrime breakout time was 29 minutes; the fastest observed breakout was 27 seconds.
View source ↗Historical context showing vulnerability intelligence often preceded NVD publication.
View source ↗Ongoing research on disclosure-to-exploitation timing.
View source ↗