Solutions  ·  2026-06-20

ProjectDiscovery — Vulnerability Curve Analysis: Negative Time-to-Exploit (Research)

SolutionsHigh impactGlobal
ProjectDiscovery published (June 18, 2026) research documenting that the average CVE is now exploited *before* public disclosure. CVE volume grew from ~18,000 (2018) to ~50,000 (2025), while time-to-exploit collapsed from ~2 months to negative days, driven by AI-accelerated exploit generation.
This is the foundational threat context motivating Continuum, MDASH, and agentic security platforms. Traditional reactive patching is no longer viable; defenders must shift to real-time vulnerability management and continuous monitoring. The research validates the urgency of AI-driven defensive tooling.
CISOs and security leaders should use this as evidence to shift vulnerability management strategy from patch cycles to continuous, AI-accelerated monitoring. Procurement teams evaluating Continuum, MDASH, or similar platforms should reference this data.
Sources
ProjectDiscovery Blog
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →