×

Book a Demo

*First Name

*Last Name

*Work Email

*Company

Tell Us How We Can Be Successful Together

Submit →

Thank you. The form was submitted successfully. You can now close this modal.

The Patch Window

The patch window is the gap between the moment a vulnerability is disclosed and the moment a fix is deployed on your systems. For most of the last two decades that gap was measured in weeks or months, and enterprise patch cycles were built around that assumption.

That assumption no longer holds. In 2018 the median interval between disclosure and first observed exploitation was over two years. By 2021 that had compressed to 110 days, by 2023 to 12 days, and today it is measured in hours, with close to half of exploited vulnerabilities hit on or before the day they were publicly disclosed. The live view below carries the current year's figures.

The figures come from the Zero Day Clock, a dataset of 5,250 exploited vulnerabilities compiled from CISA KEV, VulnCheck, CIRCL and the ENISA EUVD, 4,100 of them disclosed since 2018, which is the span charted here. The live view below tracks it so the trend can be checked rather than asserted.

Why the patch window matters

A patch cycle that takes 30 to 45 days is not a defect of the organizations running it. Testing, change approval and staged rollout exist for good reasons, and skipping them causes outages. The problem is arithmetic. When the interval to a working exploit is shorter than the interval to a deployed patch, the exposure is structural rather than operational, and no amount of patching faster closes it.

What closes the gap when a patch cannot

Exploiting a vulnerability still requires making an unauthorized change to a protected component: writing a new binary, modifying a registry key, loading a driver, altering a service. Known-good enforcement evaluates that change at the kernel against a verified baseline of the system's authorized state, and blocks it when it falls outside. The vulnerability can exist and the exploit can run. The change it depends on does not execute.

This is how Mimic Virtual Patching covers the exposure window between disclosure and patch deployment, and how it covers end-of-life systems that will never receive another fix. Related reading: The Exploit Path and the Known-Good Enforcement Glossary.

About this data

Figures are compiled from public vulnerability and exploitation reporting. The live view below is updated as new records are published.