Attackers Aren’t Waiting for Vulnerabilities to Be Disclosed

By Pascal Geenens, VP Cyber Threat Intelligence, Radware [ Join Cybersecurity Insiders ]
4

Security teams used to have some breathing room after a vulnerability was disclosed. It was never enough, but there was at least a window between the publication of a CVE and the first exploits in the wild. That window has now moved into negative territory.

The zero day clock project revealed that the average time between an official CVE announcement and the first detected attack has fallen below zero in July 2026, compared with 21.5 days after disclosure in 2025 and 53 days in 2024. The zero-day exploitation rate has also surpassed 80%, meaning more than four out of every five exploits detected in the wild targeted vulnerabilities before their official CVE announcement.

This is a difficult shift for defenders because so much of vulnerability management begins with disclosure. A CVE is published, a vendor issues guidance and security teams determine whether the vulnerability affects their environment. By the time that process starts, attackers may already know what they are looking for.

The Patch Is Arriving After the Attack

The problem is not that organizations have suddenly forgotten how to patch. Many have spent years improving their vulnerability management programs and reducing the time it takes to deploy critical updates. Attackers can now find and exploit vulnerabilities faster. Automated tools can scan internet-facing systems continuously, identify vulnerable software and begin testing possible exploits. AI adds another level of speed by helping attackers reason across large codebases and connect weaknesses that traditional scanning tools may evaluate separately. Once an attacker develops a working exploit, automation makes it possible to search for exposed targets at scale. The time between finding a weakness and launching an attack can shrink from days to hours.

As evidenced by the Radware H1 2026 Threat Report, this acceleration is already visible in the attack data. Vulnerability exploitation accounted for 62.1% of all web application and API attacks observed by Radware during the first half of 2026. Malicious application and API transactions increased 104% compared with 2025 levels, exceeding 14,000 malicious transactions per application per day. Web DDoS attacks also increased 110.6% compared with the first half of 2025. These figures point to a threat environment where attacks are increasing across multiple layers while defenders have less time to understand what is happening.

Patching remains essential, but it cannot protect organizations before a vulnerability is known and a fix is available. Even an efficient vulnerability management team cannot remediate an issue it does not know about. When exploitation begins before disclosure, organizations need protections that can recognize malicious behavior without waiting for a CVE number or an attack signature.

Attackers See What Organizations Miss

There is another reason disclosure-led security is struggling. An organization can only patch the systems it knows about, while attackers are free to look for everything exposed to the internet.

APIs are a good example. More than 70% of organizations surveyed by Radware increased their use of internally developed APIs over the past year, and 81.2% now push API updates into production at least weekly. Only 6.9% said they fully document their internal APIs. The number of APIs is growing much faster than the ability of many organizations to track them.

An undocumented API does not disappear when it falls out of an inventory. It may continue exposing sensitive data or providing access to a business process without appearing in a vulnerability management system. The same applies to forgotten endpoints, older applications and services that teams believe have been retired. These systems often sit outside the normal patching process because no one currently owns them. Attackers can still find and target these systems.

Organizations are now adding AI agents to environments they already struggle to document. Radware found that 77% of organizations are deploying or implementing AI agents and autonomous workflows, while only 17.2% report full visibility into the agents operating across their environments. These agents may call APIs, access internal systems or execute tasks on behalf of users. They can also download software dependencies and interact with external content. An agent with broad permissions can give an attacker a useful path through the organization if it is manipulated through prompt injection or another technique.

The agent itself is only one part of the risk. Security teams also need visibility into the tools it can call, the data it can reach and the actions it is allowed to take. Even an approved agent can introduce risk if its permissions are too broad or its behavior is poorly monitored. Every agent should have a defined identity and purpose, with access limited to the job it performs. Its activity should also leave a record that investigators can follow when something goes wrong.

Security Has to Start Before Disclosure

Vulnerability management was built around known flaws. Defenders now have to prepare for attacks against vulnerabilities that have no public name, available patch or entry in a scanner’s database. That requires an accurate view of what is exposed and protection that can recognize malicious behavior before the underlying flaw is understood.

Asset inventories and continuous API discovery can help teams find systems that would otherwise sit outside the security program. Behavioral and intent-based runtime application and API protection can detect active exploitation. Red teaming and security research can uncover attack paths before criminals find them. Human judgment remains critical throughout this process to validate findings, understand the business impact and decide where action is most urgent.

The 80% zero-day rate should change how security leaders measure their readiness. The speed of patching after disclosure is no longer enough. They also need to know whether their defenses can identify and contain an attack before the vulnerability has a name. Organizations that wait for a CVE and a patch are behind.

_____

Pascal Bio:

As the VP of Cyber Threat Intelligence for Radware, Pascal helps execute the company’s thought leadership on today’s security threat landscape. Pascal brings over two decades of experience in many aspects of Information Technology and holds a degree in Civil Engineering from the Free University of Brussels. As part of the Radware Security Research team Pascal develops and maintains the IoT honeypots and actively researches IoT malware. Pascal discovered and reported on BrickerBot, did extensive research on Hajime and closely followed new developments of threats in the IoT space and the applications of AI in cyber security and hacking. Prior to Radware, Pascal was a consulting engineer for Juniper working with the largest EMEA cloud and service providers on their SDN/NFV and data center automation strategies. As an independent consultant, Pascal got skilled in several programming languages and designed industrial sensor networks, automated and developed PLC systems, and led security infrastructure and software auditing projects. At the start of his career, he was a support engineer for IBM’s Parallel System Support Program on AIX and a regular teacher and presenter at global IBM conferences on the topics of AIX kernel development and Perl scripting.

 

Join our LinkedIn group Information Security Community!

No posts to display