The Fix Window Has Closed — Why 'Find It, Fix It Fast' Is the 2026 Default

PentaTrail Team··10 min read
Contents

"Once a vulnerability goes public, how long do you have to fix it?" The answer to that question has changed dramatically in the last few years. It used to be weeks, then days. For internet-facing devices, there are now cases where that gap has all but disappeared.

Verizon's 2025 Data Breach Investigations Report found that, for the 17 edge-device vulnerabilities it analyzed (VPNs, firewalls, and other internet-facing gear), the median time from CVE publication to being added to the "known exploited vulnerabilities" catalog (CISA KEV) was "zero days" (Verizon DBIR 2025). Nine of the 17 were already on that catalog on or before their publication date — flagged as exploited almost the moment they went public.

This post lays out what that collapse of the response window demands of your defenses, using public data.

The way in is an exposed asset

First, where do attacks come from? Japan's National Police Agency, in its H1 2025 statistics, found that among ransomware cases where the infection route was identified, over 80% (84%) used an externally exposed device — a VPN appliance, remote desktop, and the like — as the point of entry (NPA, H1 2025).

Before the flashy zero-days and advanced targeted attacks, what gets hit is what's exposed to the internet — through unpatched flaws, but also leaked credentials and misconfigurations. Attackers aren't looking at your asset inventory — they're looking at what's actually exposed from the outside.

The problem isn't "we didn't know" — it's "we left it unaddressed"

What makes this harder is that being caught out by an untracked asset is far from rare. In a Trend Micro / CSO Online survey, over 70% (73%) of security leaders reported experiencing an incident caused by an asset they hadn't been tracking or managing (Trend Micro / CSO Online, 2025).

Cloud migrations, subdomains stood up by individual teams, a server briefly exposed for testing — when assets like these are exposed and unnoticed, they can become the way in. For more on thinking in terms of attack surface, see our Intro to ASM.

An annual assessment can't keep up

Put those together and the demand on defense comes into focus:

  • The way in is "an asset visible from the outside"
  • Untracked or unmanaged assets can be the way in
  • A discovered weakness can be flagged as exploited almost the moment it's published

In a world where all three hold at once, "assess everything once a year" is structurally too slow. Between one assessment and the next, new assets appear, new vulnerabilities go public, and exploitation can begin.

So you have to switch to a model where discovery and remediation repeat continuously. That's the idea behind Gartner's CTEM (Continuous Threat Exposure Management): continuously discover external assets, rank them by risk, confirm what's actually exploitable, and fix it — running that loop to shrink your attack surface over time.

Prioritize by "can it be exploited," not "how severe"

Running the loop is one thing, but you can find hundreds of vulnerabilities a week. You can't get to all of them, so how you rank them becomes the crux.

Ranking by CVSS score alone is risky here. Some high-severity flaws aren't actually being exploited, while some mid-scored ones are confirmed in the wild. What works is combining CVSS with KEV (known exploited vulnerabilities), EPSS (exploit-probability prediction), and the asset's business impact to decide priority (we covered the limits of leaning on CVSS in The NVD Scoring Change and CTEM).

One step beyond prioritization is validation — confirming whether it can actually be exploited. Narrowing the scanner's candidate list down to what's genuinely exploitable is something we go into in Finding Isn't Enough.

PentaTrail's answer: see it, narrow it, fix it fast

With the response window gone, defense comes down to the ability to notice early and the ability to fix early. PentaTrail is designed to let a small team run both — without adding headcount.

  • Daily scanning — where traditional periodic assessments run monthly or weekly, PentaTrail scans every day, detecting newly appeared assets and newly opened ports by the next day.
  • Prioritization by exploitability — not CVSS alone, but KEV, EPSS, and business impact combined to surface "what to fix first."
  • AI remediation guidance — grouping many findings by remediation approach into concrete tasks. You can even ask your own attack-surface data directly from an AI agent.

The point is that this doesn't end at "found it." Find it, narrow by exploitability, and fix it through — with the goal of reducing exposure. AI supports the judgment and prioritization so you can fix faster; the aim is not to replace people, but to let even a small team run continuous management.

Answer speed with speed

In a world where a flaw can be exploited almost the moment it goes public, defenders can't stay on a once-a-year cadence while attackers accelerate with automation and AI. If the offense is raising its speed, the defense has to raise both the judgment of "what to prioritize" and the execution of "how fast we fix it" by the same measure.

Now that the grace period is gone, the answer isn't "check occasionally" — it's "see continuously, and fix fast." Making that runnable for organizations that can't staff a dedicated team is exactly why we work on CTEM.

You can start by simply confirming how your own attack surface looks from the outside right now — try it free for 14 days. For the bigger picture, see What is CTEM.

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose