The Fix Window Has Closed — Why 'Find It, Fix It Fast' Is the 2026 Default

PentaTrail Team···10 min read
Contents

"Once a vulnerability goes public, how long do you have to fix it?" The answer has changed dramatically in the last few years: it used to be weeks, then days.

For internet-facing devices, there are now cases where the gap has all but disappeared. What follows walks through what the public data actually demands.

01 / For internet-facing devices, the gap between disclosure and exploitation is essentially gone

Verizon's 2025 Data Breach Investigations Report looked at 17 vulnerabilities in internet-facing devices such as VPNs and firewalls, and found a median of zero days between CVE disclosure and the vulnerability appearing on the catalog of confirmed exploited flaws (CISA KEV).

Diagram of the days between disclosure and confirmed exploitation for internet-facing device vulnerabilities. Across 17 vulnerabilities the median from disclosure to KEV listing was zero days, and 9 of them were already listed on the day of disclosure or earlier

Figure 1: Days from disclosure to confirmed exploitation (Verizon DBIR 2025)

Deep dive: the scope this number covers

Nine of the seventeen were already on the catalog on the day the CVE published, or before it. Exploitation was a live problem essentially at the moment of disclosure. It matters that the scope is limited to internet-facing devices; the same figure does not transfer to internal software generally.

02 / Intrusions concentrate on the devices visible from outside

Japan's National Police Agency reported that in the first half of 2025, 84% of ransomware cases where the intrusion route was identified came in through externally exposed devices such as VPN appliances and remote desktop.

Diagram of ransomware intrusion routes. Among cases where the route was identified, 84 percent came in through externally exposed devices such as VPN appliances and remote desktop

Figure 2: Breakdown of cases with an identified intrusion route (National Police Agency, H1 2025)

Deep dive: unpatched flaws are not the only thing being used

Leaked credentials and misconfiguration come through the same doors. The picture is that the opening visible from the internet gets tried well before anything exotic. What an attacker is looking at is not your asset register but what is actually visible from outside.

03 / Assets you didn't know about are an ordinary intrusion route, not an edge case

In a Trend Micro and CSO Online survey, 73% of security leaders said they had experienced an incident originating in an asset they hadn't known about or wasn't under management.

Diagram of how often incidents originate in unmanaged assets. 73 percent of security leaders reported an incident originating in an asset they had not known about or that was outside management

Figure 3: Rate of incidents originating in unmanaged assets (Trend Micro / CSO Online 2025)

Deep dive: where the growth comes from

Cloud migrations, subdomains stood up per department, a server exposed briefly for testing. How they accumulate is covered in our piece on shadow IT, and how to enumerate them from outside in our piece on ASM.

04 / With all three true at once, an annual assessment cannot structurally keep up

The way in is an externally visible asset, some of those assets are ones nobody listed, and the weakness gets attacked at roughly the moment it publishes. Between one assessment and the next, assets appear, vulnerabilities publish, and exploitation can begin.

Diagram contrasting a one-off assessment with continuous operation. With an annual assessment, new assets appear, new vulnerabilities publish and exploitation can begin in the interval, whereas running continuously removes the interval itself

Figure 4: What can't keep up is the interval, not the capability

Deep dive: which is why it becomes a loop

Discover external assets continuously, order them by danger, confirm whether they are genuinely exploitable, and fix them through. Running that loop to shrink the attack surface is what CTEM describes. Rather than one inspection, it removes the interval.

05 / Order by exploitability, not by severity

Hundreds of findings a week is realistic, and nobody gets to all of them. Some high-severity flaws are never targeted, and some middling ones have confirmed exploitation.

Diagram of the difference in ordering. Sorting by CVSS alone puts severe but untargeted flaws on top, while combining CVSS with KEV, EPSS and the asset's business impact puts the exploitable ones on top

Figure 5: Ordering by severity alone versus ordering with exploitability

Deep dive: there is a confirmation step after the ordering

A stage that narrows a scanner's candidates down to the ones genuinely exploitable comes next. How to read the individual scores is in CVSS, EPSS and KEV, and the confirmation stage in Validating vulnerabilities with AI.

06 / What has to rise is both noticing fast and fixing fast

With the gap gone, one without the other does not arrive in time. PentaTrail scans daily, orders by exploitability, and carries through to turning the fix into a concrete task.

Diagram pairing the ability to notice fast with the ability to fix fast. The noticing side scans daily and detects new assets and newly opened ports by the following day, while the fixing side orders by exploitability and turns remediation guidance into tasks

Figure 6: Raising the noticing side and the fixing side together

Seeing how your attack surface looks from outside right now is free to try for 14 days.

Appendix: the public data cited, and what PentaTrail covers

Table 1: the figures used above, and their sources

Figure What it measures Source
Median 0 days Days from CVE disclosure to KEV listing across 17 internet-facing device vulnerabilities Verizon DBIR 2025
9 of 17 Already listed on the day of disclosure or earlier As above
84% Share of ransomware cases with an identified route that entered via externally exposed devices National Police Agency, H1 2025
73% Share of security leaders reporting an incident from an asset they hadn't known about Trend Micro / CSO Online 2025

Table 2: what PentaTrail covers

Capability Detail
Daily scanning New assets and newly opened ports are detected by the following day
Ordering by exploitability Not CVSS alone, but combined with KEV, EPSS and the asset's business impact
AI remediation guidance Groups many findings by remediation approach and turns them into concrete tasks
Access from an AI agent Your attack surface data can be queried directly

If the attacking side is raising its speed through automation, the defending side has no option but to answer in the speed of its judgment and its execution. With the window gone, the answer is not periodic inspection but continuous sight and fast repair.

The scan cadence was checked against PentaTrail's scheduled-job configuration on 2026-08-17.

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose