The Numbers Have Gotten Serious
Late 2025 marked a threshold that should have triggered alarms in every security operations center running on autopilot. The CISA Known Exploited Vulnerabilities Catalog crossed 1,200 entries. That is not a vanity metric. Each entry represents a vulnerability that has moved beyond theoretical risk into active exploitation. Real attackers are weaponizing these. Real breaches are happening because of them.
For federal agencies, this crosses into binding mandate territory. Under BOD 22-01, critical-severity vulnerabilities on that list have a 15-day remediation window. Fifteen days to identify affected systems, test patches, coordinate deployment, and verify closure. That is not generous. It never was. And now with nearly 1,200 known exploited vulnerabilities in the catalog, the probability that your infrastructure touches at least one of them approaches certainty.
What troubles me most is not the size of the number. It is what the number reveals about the state of vulnerability management across the industry. The catalog has grown because vulnerabilities are not being patched before they hit that list. We are reactive, not proactive. We are managing crisis by crisis instead of managing risk systematically.
The Exploit Window Just Collapsed
There was a time when teams had weeks to patch. That era is over. The Verizon 2025 Data Breach Investigations Report confirms what careful observers already suspected: the median time from CVE publication to active exploitation has shrunk to just 5 days. Five days. That is compared to 32 days in 2021. The acceleration has been relentless.
Think through the operational reality of that timeline. Most organizations do not have automated scanning enabled across all assets. Vulnerability discovery is manual or batched. Triage takes time. Testing takes time. Change management takes time. Deployment takes time. The entire process, run efficiently, takes two to three weeks minimum. We are now operating in an environment where attackers often beat us to the punch.
January 2026 provided a sharp demonstration. CISA added 47 new actively exploited vulnerabilities in a single month. Multiple zero-days affecting Palo Alto Networks PAN-OS and Ivanti Connect Secure were documented. Both vendors had already released patches. Both products are deployed across thousands of enterprises. The lag between patch availability and active exploitation was measured in days, not weeks.
The Patch Is Available. So Why Are You Still Breached?
This one stings because it is almost entirely preventable. A 2025 Tenable research report studied breach investigations across multiple organizations and found something that should keep security leaders awake at night: 60 percent of the breaches examined involved a known vulnerability for which a patch had been available for more than 30 days. Thirty days. Not five days. Not yesterday. A month prior.
That gap between “patch exists” and “patch deployed” is where most breaches live. It is not a knowledge problem. Your organization knows the vulnerabilities. CISA publishes the list. Your tools notify you. The problem is execution. It is the mismatch between what you need to do and the processes you have built to do it.
Some of this is genuine resource constraints. Some of it is risk aversion, where teams prioritize stability over patching, or where change management procedures are so rigid they strangle velocity. Some of it is technical complexity. Legacy systems cannot tolerate rapid patching. Dependencies require coordination. Downtime windows are limited. But if we are honest, most of it is systematic weakness. Your patch process was not designed for a world where exploitation happens in days, not weeks.
The Volume Problem Is Real and Getting Worse
The National Vulnerability Database processed over 40,000 new CVEs in 2024, a 38 percent increase compared to 2022. The flood has not crested. It keeps rising. For security teams, this creates a triage problem of staggering proportions. Every single one of those CVEs requires assessment. Most are not relevant to your infrastructure. Some are critical. The noise obscures the signal.
Automated triage pipelines are struggling. Tools that worked reasonably well five years ago are now bottlenecks. They cannot ingest, parse, correlate, and prioritize 40,000 vulnerabilities per year with enough accuracy to be trusted. Teams still rely on manual review at critical junctures. That is expensive and slow. As the volume grows, triage accuracy degrades. You start missing things.
This is where the catalog enters the picture. CISA’s list of known exploited vulnerabilities acts as a filter. Instead of trying to patch everything, you patch what is actually being weaponized. That is strategic triage, using threat intelligence to drive operational priority. The problem is that your current process was not built to handle rapid response to a growing list of urgent-priority items.
What Changes Next
I do not think we have hit the bottom of this curve yet. Exploit development is accelerating. Automation is improving on the attacker side. More organizations are deploying better telemetry, so more vulnerabilities are being detected in active use. The CISA catalog will continue to grow. The timeline will continue to compress. This is not speculation. This is the trend we are already in the middle of.
Organizations that survive this transition will treat patch management as a continuous, highly automated process rather than a quarterly project. They will instrument their infrastructure so they can answer in minutes whether a given vulnerability affects their systems. They will have pre-tested patches staged and ready for deployment. They will have change management processes that distinguish between emergency patching (exploit in the wild) and routine patching (standard cycle). They will measure success not in patches deployed per quarter but in time from detection to remediation.
The 1,200-entry threshold is a milestone, but it is not the crisis point. The crisis point was somewhere around 600 entries. We already missed it. Now the work is about building operational capability that matches the threat environment we actually inhabit, not the one we inherited.
What does your current patch process look like when vulnerability exploitation windows compress to five days? Where are the gaps? I would be interested in what you are actually seeing in your environment. Reach out and share the details. This conversation needs to move beyond what the reports say and into what is happening on the ground.



