BlackTree Security · Infrastructure · Automation · AI

Mean Time to Exploit Just Went Negative: The Patch Window Is Gone

Mandiant’s M-Trends 2026 report, published 23 March 2026, puts a number on something defenders have felt for a while: the mean time to exploit (MTTE) a vulnerability is now an estimated -7 days. Exploitation is routinely happening before a patch is even released, not after.

That single figure should reset how organisations think about patching. Not because patching stops mattering, but because it stops being the control that saves you.

What Mandiant found

The -7 day figure appears in M-Trends 2026’s section on edge devices, zero-days and extreme persistence. Mandiant attributes much of this shift to sophisticated cyber espionage groups, including UNC6201 and UNC5807, that have concentrated their efforts on edge and core network devices such as VPNs, routers and virtualisation platforms. These are the systems least likely to be covered by endpoint detection and most likely to sit outside normal patch cadence.

The report also documents rising zero-day usage through 2024 and 2025, and highlights cases such as UNC6201’s exploitation of a Dell RecoverPoint for Virtual Machines zero-day, alongside custom in-memory malware like the BRICKSTORM backdoor achieving dwell times of roughly 400 days once established. Put together, the picture is not just faster exploitation, but exploitation that is harder to see once it has landed.

A negative MTTE means the traditional sequence of vulnerability disclosure, then patch release, then organisational patch cycle, has been overtaken at the front end. By the time a CVE is public, some organisations are already compromised.

Why patching alone no longer works

Patching still matters. That is not in question. The problem is what patching was ever able to promise.

Patch windows assumed a gap that no longer reliably exists. Vulnerability management programmes are built around service level targets such as patch critical severity within 14 days, or high severity within 30. Those targets assume the vulnerability becomes exploitable after disclosure. Mandiant’s data says the opposite is now common: exploitation before disclosure, or before most organisations can realistically test and deploy a fix.

CVSS-driven prioritisation is answering the wrong question. A CVSS score describes theoretical severity, not who is actively using the vulnerability today. Teams that triage purely by CVSS will keep patching in the wrong order relative to what attackers are actually doing in the wild.

Edge devices sit in a governance blind spot. VPNs, routers and virtualisation hosts are often managed by network or infrastructure teams rather than the security function, patched on vendor-driven schedules, and rarely instrumented with the same detection depth as endpoints. That combination is exactly what espionage-focused actors are exploiting.

Dwell time turns a missed exploitation window into a much bigger problem. BRICKSTORM-style persistence measured in hundreds of days means a negative MTTE is not just about the moment of compromise. It is about how long an intrusion can sit undetected once patching has already failed to prevent it.

What this requires instead

If attackers are exploiting vulnerabilities before patches exist, or before businesses can realistically test and deploy them, the operative question has to change. Not “how fast can we patch everything”, but “how quickly can we understand what is being actively exploited, where we are exposed, and whether there are signs of compromise already present”.

That requires three things, in combination rather than in isolation:

  • Threat intelligence that prioritises based on real-world exploitation, not just CVSS scores. Knowing what is actively being used against organisations similar to yours matters more than a static severity rating.
  • Visibility across endpoints, identity, cloud, network and third-party access paths. Edge devices cannot stay outside the same detection standard applied everywhere else.
  • Detection and response capabilities that assume compromise is possible, even when patching is being managed well. If the exploit window can be negative, “we patched on schedule” is no longer evidence of safety.

This is where cyber threat intelligence (CTI) earns its place, not as a report that sits in an inbox, but as a decision-support function for the SOC, vulnerability management, infrastructure and risk teams who have to act on it.

Why this matters

  1. A negative MTTE breaks the assumption underlying most vulnerability management SLAs.
  2. Edge and network devices are now a primary target precisely because they sit outside conventional patch and detection coverage.
  3. CVSS-only prioritisation is measurably out of step with how sophisticated actors select targets.
  4. Long dwell times mean a missed exploitation window compounds rather than resolves.
  5. Governance, not just tooling, determines whether an organisation can answer “are we exposed right now” faster than an attacker can act.

What security leaders should do now

  • Re-baseline vulnerability SLAs against real-world exploitation data, not CVSS alone.
  • Bring edge devices, VPNs and network infrastructure into the same detection and monitoring standard as endpoints.
  • Treat threat intelligence as an input to prioritisation decisions, not a separate report cycle.
  • Build (and test) the assumption that compromise may already be present, rather than treating detection as a backstop for patching failures.
  • Ask, at board level, whether the organisation can say with confidence what it is exposed to today, not what it patched last quarter.

Conclusion

The patch window has not just shrunk. In some cases, according to Mandiant’s own data, it has disappeared. Organisations that keep treating “time to patch” as their primary security metric are measuring against a model of attacker behaviour that -7 days has already made obsolete. The ones that adapt fastest will be the ones that combine remediation, detection and intelligence into a single operating model, rather than running them as three separate functions reporting on three separate timelines.


Sources: Mandiant M-Trends 2026, Google Cloud Blog

Leave a Reply

Your email address will not be published. Required fields are marked *