Vulnerabilities

Vulnerability Management Evolution

July 14, 2026 16:03 · 12 min read
Vulnerability Management Evolution

Vulnerability Management in the Age of AI

The traditional timeline of vulnerability management has been disrupted by two key factors: the sheer volume of new flaws and the speed at which they can be turned into working exploits. With a new CVE emerging every 7.4 minutes, and AI capable of turning advisories into live exploits in under a day, security teams are struggling to keep pace.

The Volume Problem

The first half of 2026 has already produced more CVEs than any full year prior to 2024, with the number of new flaws growing at an alarming rate. This has created a significant challenge for security teams, as they struggle to prioritize and patch the most critical vulnerabilities.

The Speed Problem

The second factor is speed. AI has erased the cushion between vulnerability disclosure and exploitation, allowing attackers to turn advisories into live exploits in a matter of hours. The Zero Day Clock, which tracks time-to-exploit across tens of thousands of CVEs, now puts the median time for 2026 at well under a day.

Proving Exploitability Without Firing an Exploit

However, it is possible to prove whether an exploit works against a system without having to actually pull the trigger. By mapping a vulnerability to the steps its exploitation depends on, and testing each step against the defenses that have been deployed, security teams can determine whether an exploit is genuinely exploitable.

The Logic of Rocket Engineering

This approach is similar to the logic of rocket engineering, where engineers qualify each component of the rocket separately before attempting a launch. If a critical component fails its test, the engineers know that the vehicle cannot fly, without having to risk a launch.

A Worked Example: Nightmare-Eclipse

A recent example of this approach is the Nightmare-Eclipse exploit, which was disclosed in early April 2026. By converting each attacker's behavior into a discrete action and testing each step against the defenses that had been deployed, security teams were able to determine whether the exploit was genuinely exploitable.

Replicating Behavior

The process of replicating the behavior of the Nightmare-Eclipse exploit involved several key steps, including creating a new service, dumping the SAM hive via Volume Shadow Copy, and disabling the Windows Defender service. By emulating these steps, security teams were able to test whether their defenses would hold against the exploit.

Covering the Whole Surface

Live exploitation and TTP-chaining are not competing methods, but rather complementary approaches that can be used together to provide the strongest possible proof of exploitability. By running both live exploitation and TTP-chaining, security teams can continuously ask the question of exploitability, rather than simply ticking a box once.

The result is a platform that provides one on-demand answer: 'What can actually be exploited here, right now?' This approach allows security teams to prioritize patching and hardening where the chain would actually complete, and to make defensible decisions without firing a single exploit.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free