The Patch Window

The patch window is the gap between the moment a vulnerability is disclosed and the moment a fix is deployed on your systems. For most of the last two decades that gap was measured in weeks or months, and enterprise patch cycles were built around that assumption.

That assumption no longer holds. In 2018 the median interval between disclosure and first observed exploitation was over two years. By 2021 that had compressed to 110 days, by 2023 to 12 days, and in 2026 it stands at 2 days — with 46% of exploited vulnerabilities hit on or before the day they were publicly disclosed.

The figures come from the Zero Day Clock, compiled from CISA KEV, VulnCheck, CIRCL and the ENISA EUVD — 4,230 exploited vulnerabilities disclosed since 2018, which is the span charted here. The live view below tracks it so the trend can be checked rather than asserted.

Why the patch window matters

A patch cycle that takes 30 to 45 days is not a defect of the organizations running it. Testing, change approval and staged rollout exist for good reasons, and skipping them causes outages. The problem is arithmetic. When the interval to a working exploit is shorter than the interval to a deployed patch, the exposure is structural rather than operational, and no amount of patching faster closes it.

What closes the gap when a patch cannot

Exploiting a vulnerability still requires making an unauthorized change to a protected component: writing a new binary, modifying a registry key, loading a driver, altering a service. Known-good enforcement evaluates that change at the kernel against a verified baseline of the system's authorized state, and blocks it when it falls outside. The vulnerability can exist and the exploit can run. The change it depends on does not execute.

This is how Mimic Virtual Patching covers the exposure window between disclosure and patch deployment, and how it covers end-of-life systems that will never receive another fix. Related reading: The Exploit Path and the Known-Good Enforcement Glossary.

About this data

Figures are compiled from public vulnerability and exploitation reporting. The live view below is updated as new records are published.

The Patch Window

The window between disclosure and exploitation has closed.

Across 4,230 CVEs with confirmed in‑the‑wild exploitation, the median time from public disclosure to first exploitation has collapsed from over two years to 2 days — and nearly half are now exploited on or before the day the advisory lands.

852 days
Median time to exploit: 2018 → today. Watch it run out.

Median days from disclosure to first exploitation

Confirmed-exploited CVEs, by the year of their CVE ID
View data as table

Still unexploited, N days after disclosure

Share of that year's exploited CVEs not yet seen exploited, by days since disclosure

View data as table

How fast was your CVE weaponized?

Try CVE-2021-44228 (Log4Shell), citrix, or exchange

Patching can’t close a window that’s already shut. Mimic enforces your servers’ known-good state at the kernel — the unauthorized change every exploit needs simply never executes, whether the patch ships in a day or never ships at all.

See how Mimic closes it

Data: Zero Day Clock (CISA KEV · VulnCheck · CIRCL · ENISA EUVD) — methodology independently auditable.