For three decades, vulnerability management ran on a buffer: the weeks or months between a flaw being discovered and an attacker figuring out how to weaponize it. Triage by severity, schedule the fix, validate, move on. The buffer is what made that workflow function. The buffer is now gone, and its disappearance is forcing a quiet but fundamental reallocation of security budgets away from patch velocity and toward validating what is genuinely exploitable.
The cause is AI on the offensive side, and the scale of it is documented. As The Hacker News detailed, time to exploit has fallen from roughly 53 days in 2024 to about 24 hours in 2026, according to Zero Day Clock data. The discovery engines explain why. Anthropic’s Claude Mythos Preview identified more than 10,000 high or critical severity vulnerabilities in systemically important software in a single month, produced 181 working exploits against Firefox where prior frontier models managed two, and surfaced a 27 year old undetected OpenBSD bug. More than 99 percent of what it found was still unpatched. This is not a future scenario. An AWS report in February documented a threat actor running a custom server of autonomous offensive tools that touched more than 600 devices across 55 countries, with more than 2,500 additional targets queued behind them.
It is worth being precise about what changed, because the instinct is to file this under faster attackers and move on. The traditional model did not just assume attackers were slow. It assumed a stable ratio between the effort to find and weaponize a flaw and the effort to fix it, and it built every process, from monthly patch cycles to risk acceptance memos, on that ratio holding. AI did not nudge one side of that equation. It collapsed the cost of finding and weaponizing vulnerabilities while leaving the cost of remediation, which still involves testing, change control and the risk of breaking production, almost untouched. When one side of a balanced system gets ten times cheaper and the other does not, the system does not need tuning. It needs redesigning.
Patching mathematically cannot win this race
The defensive numbers describe a treadmill speeding up. The median organization had to remediate 16 known exploited vulnerabilities in 2025, up nearly 50 percent from 11 the year before. Median fix time for those flaws stretched to 43 days from 32. Only about 26 percent of vulnerable systems were fully patched, down from 38 percent, and even the best performing organizations close just 30 to 40 percent of known exploited vulnerabilities in the first week. Verizon’s 2026 Data Breach Investigations Report tied 32 percent of initial access to vulnerability exploitation, a share expected to climb as AI coding assistants put exploit building within reach of less skilled attackers. When time to exploit is 24 hours and median remediation is 43 days, faster patching is a worthy goal that still loses the race by an order of magnitude.
Severity scoring breaks down in the same conditions. The traditional model assumes a manageable volume of disclosures that can be ranked by CVSS and addressed in priority order. When AI assisted discovery means everything in the queue scores a nine or a ten, the score stops being a prioritization signal at all. Teams need a different question than which flaw is most severe.
Breach and attack simulation answers the question that matters
That question is operational: what is actually exploitable against us right now, and would our defenses catch it if someone tried. Breach and attack simulation, or BAS, answers it by safely running real adversary techniques against the live prevention and detection stack rather than against a theoretical model of risk. It does three things patch lists cannot. It separates theory from reality by identifying which flaws are already neutralized by a web application firewall, an intrusion prevention system or an endpoint tool. It validates that the ten to seventy security products a typical enterprise runs actually fire as configured. And it buys safe patching time by proving a critical asset is covered, which lets a fix move through normal change control instead of an emergency rollout that breaks production.
This is why field reports increasingly describe CISOs reserving dedicated spend for BAS that was not a separate line item a year ago. Gartner has a label for the broader move, adversarial exposure validation, which blends security effectiveness testing with business context. Vendors such as Picus are building agentic versions where an AI agent coordinates pre vetted test building blocks rather than generating unsafe payloads, collapsing the loop from threat alert to posture score and prioritized mitigations into minutes. The logic is symmetrical: machine speed attacks demand machine speed defenses, and the only honest measure of a defense is whether it stops a real technique.
None of this means patching stops mattering, and that distinction is where leaders can go wrong. The argument is not that remediation is obsolete; unpatched known exploited vulnerabilities remain the most common way in. The argument is that patch coverage is the wrong primary metric for a program operating under a 24 hour exploitation clock, because it measures effort rather than outcome. Two organizations can report identical patch coverage and have wildly different real exposure depending on whether their detection and prevention controls actually catch the techniques attackers use against the gaps that remain. Validation is what turns an unknowable backlog into a ranked, evidence based list of what to fix first, which is the only way a stretched team can make defensible decisions when the queue is full of nines and tens. It also changes the conversation with the board, replacing a number that always looks like failure, the unpatched count, with one that reflects reality, the share of real world techniques the stack stops today.
The objection worth pre empting is cost: validation tooling is not free, and a stretched security budget cannot simply add a line. The honest answer is that this is a reallocation, not an addition. Much of what teams spend chasing comprehensive patch coverage, the emergency change windows, the after hours rollbacks, the analyst hours triaging a queue where everything scores a nine, is effort spent without knowing whether any of it reduced real exposure. Validation redirects a portion of that toward proving which exposures matter, which in practice lets teams defer or batch the patches their controls already neutralize and reserve emergency response for the genuinely reachable. The spend does not grow so much as it gets pointed at outcomes instead of activity.
What it means for the security leader
Stop benchmarking your program on patch coverage alone and start benchmarking it on validated control efficacy. That reframing has budget consequences. It means funding continuous validation as core tooling rather than an annual penetration test, and it means re reading regulators in the same light, as with the federal patch clock collapsing to three days for the most dangerous flaws. A three day mandate is only achievable if you already know which exposures your stack neutralizes and which it does not. The organizations that weather the AI exploitation era will not be the ones that patch fastest. They will be the ones that can prove, on any given morning, what an attacker could actually reach.