Security
Attackers Weaponize Vulnerabilities in a Week, But Patching Takes 5 Months, Research Finds
2026-08-27
SentinelOne and Tenable released joint research Wednesday suggesting a growing disconnect between vulnerability discovery, disclosure and actual exploitation, drawing on Tenable's exposure data across thousands of organizations combined with SentinelOne's endpoint and post-exploitation detection data.
The companies said the most critical takeaway is that both nation-state and criminal threat actors are focusing on vendor product lines and susceptible points in the attack surface more than specific individual vulnerabilities.
According to the research, new frontier AI models are compressing vulnerability discovery from months to hours, expanding potential risk while cutting the time attackers need to move from disclosure to working exploit code to about a week. The median organization, by contrast, takes five months to remediate known vulnerabilities, the companies found — a gap they said requires more than faster patching to close, since it also demands knowing which product lines are most likely to carry the next wave of exploitation.
Attackers converge on the same vendor surfaces
Exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, according to the research, while overlapping on individual vulnerabilities only 21% of the time. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities, the companies said, even though the specific actors targeting them vary. Tenable has termed this pattern the "Persistently Targeted Vendor," the idea that a small set of vendor product lines, rather than individual CVEs, represents the durable unit of risk over time.
The research identified 12 vulnerabilities with confirmed "multi-nexus" attribution, meaning state-sponsored and ransomware operators independently exploited the same flaw across five distinct threat categories, including China-, Russia-, North Korea- and Iran-linked actors, as well as financially motivated criminal groups, according to the companies.
Specific vendors show sharply different remediation speeds
More than half, or 54%, of organizations running F5 products carry at least one exposed, actively exploited vulnerability, the research found, while Citrix customers posted the slowest remediation of any vendor studied, at a median of 461 days. The companies said the disparity illustrates how specific product lines remain exposed long after a patch is available.
Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap, according to the research, widening the window attackers have to operationalize an exploit — a finding the companies said underscores why patching speed alone isn't sufficient without attack surface minimization and endpoint protection working together.
Steve Stone, chief customer officer at SentinelOne, said static defenses can't keep pace with attacker speed. "Speed alone is not enough. By the time a vulnerability hits a remediation queue, adversaries are already iterating the exploit," he said. "Static signatures run on human timelines, the threat does not. Runtime behavioral detection has to match that cadence, flagging exploitation patterns as they emerge rather than after the fact."
Vlad Korsunsky, chief technology officer at Tenable, said the findings should reshape how defenders prioritize remediation. "Attackers systematically target specific vendor ecosystems that could provide access. They aren't obsessing over single vulnerabilities, and neither should defenders," he said. "Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. As attackers weaponize AI to breach defenses faster, organizations that embrace exposure management will win."
According to the research, new frontier AI models are compressing vulnerability discovery from months to hours, expanding potential risk while cutting the time attackers need to move from disclosure to working exploit code to about a week. The median organization, by contrast, takes five months to remediate known vulnerabilities, the companies found — a gap they said requires more than faster patching to close, since it also demands knowing which product lines are most likely to carry the next wave of exploitation.
Attackers converge on the same vendor surfaces
Exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, according to the research, while overlapping on individual vulnerabilities only 21% of the time. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities, the companies said, even though the specific actors targeting them vary. Tenable has termed this pattern the "Persistently Targeted Vendor," the idea that a small set of vendor product lines, rather than individual CVEs, represents the durable unit of risk over time.
The research identified 12 vulnerabilities with confirmed "multi-nexus" attribution, meaning state-sponsored and ransomware operators independently exploited the same flaw across five distinct threat categories, including China-, Russia-, North Korea- and Iran-linked actors, as well as financially motivated criminal groups, according to the companies.
Specific vendors show sharply different remediation speeds
More than half, or 54%, of organizations running F5 products carry at least one exposed, actively exploited vulnerability, the research found, while Citrix customers posted the slowest remediation of any vendor studied, at a median of 461 days. The companies said the disparity illustrates how specific product lines remain exposed long after a patch is available.
Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap, according to the research, widening the window attackers have to operationalize an exploit — a finding the companies said underscores why patching speed alone isn't sufficient without attack surface minimization and endpoint protection working together.
Steve Stone, chief customer officer at SentinelOne, said static defenses can't keep pace with attacker speed. "Speed alone is not enough. By the time a vulnerability hits a remediation queue, adversaries are already iterating the exploit," he said. "Static signatures run on human timelines, the threat does not. Runtime behavioral detection has to match that cadence, flagging exploitation patterns as they emerge rather than after the fact."
Vlad Korsunsky, chief technology officer at Tenable, said the findings should reshape how defenders prioritize remediation. "Attackers systematically target specific vendor ecosystems that could provide access. They aren't obsessing over single vulnerabilities, and neither should defenders," he said. "Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. As attackers weaponize AI to breach defenses faster, organizations that embrace exposure management will win."
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




