Microsoft: median time to weaponize a new bug is well under 24 hours
Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It puts the median time from finding a vulnerability in the wild to weaponizing it at well below 24 hours. CVEs tracked for 2026 are on track for a record of about 72,000. That is a projection for the full year, not a final count. Phishing was the way in for 23% of the intrusions Microsoft's incident responders investigated, up from 7% a year earlier. The report names Anthropic's Mythos and OpenAI's GPT-5.5 as the first models to show the potential to run complex attacks on their own. These figures come via Help Net Security's coverage and were not checked against the report itself.
Microsoft expects known, unpatched vulnerabilities to pile up for several years because fixes ship more slowly than new bugs are found. If exploits show up within hours, a weekly patch cycle leaves you exposed for days. Turn on automated dependency updates for anything public-facing, and make sure you can ship a security fix the same day it lands.