The Patch Window

The window between disclosure and exploitation has closed.

Across 3,500+ CVEs with confirmed in‑the‑wild exploitation, the median time from public disclosure to first exploitation has collapsed from two years to less than zero — the median exploited CVE is now weaponized before its advisory is published.

771 days
Median time to exploit: 2018 → today. Watch it run out.

Median days from disclosure to first exploitation

Confirmed-exploited CVEs, by the year of their CVE ID
View data as table

Still unexploited, N days after disclosure

Share of that year's exploited CVEs not yet seen exploited, by days since disclosure

View data as table

How fast was your CVE weaponized?

Try CVE-2021-44228 (Log4Shell), citrix, or exchange

Patching can’t close a window that’s already shut. Mimic enforces your servers’ known-good state at the kernel — the unauthorized change every exploit needs simply never executes, whether the patch ships in a day or never ships at all.

See how Mimic closes it

Data: Zero Day Clock (CISA KEV · VulnCheck KEV/XDB · NVD) — methodology independently auditable.