P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Microsoft's median weaponisation time, 'well below 24 hours', comes with no sample, period or source

Microsoft's 2026 Digital Defense Report says the median time from discovery in the wild to weaponisation is well below 24 hours, and shows no sample, period or source for it. CISA's catalogue gives a 3 day median for new flaws, 1 day lately, which supports a direction and not the number.

By Parminder Kumar Sharma · · 19 min read

Editorial illustration for the briefing: Microsoft's median weaponisation time, 'well below 24 hours', comes with no sample, period or source

The figure that comes with nothing

Microsoft's 2026 Digital Defense Report says the median time from vulnerability discovery in the wild to weaponisation has "collapsed to well below 24 hours". That sentence appears once in the 103-page PDF, on page 14. It comes with no number, no sample size, no period, no definition of either end of the clock and no source. The report's reference list has 40 entries, and none of them covers it.

Press coverage, including BleepingComputer's report of 1 October, repeated the figure as Microsoft's. It is Microsoft's claim, and the report offers nothing to check it against. Other speeds in the same report are better defined than it is, and Microsoft's own documents treat it four different ways.

What the figure does not establish. It does not establish that the median applies to your estate, that AI caused any speed-up, whether the median covers all flaws or only exploited ones, or where the clock starts. For a zero-day the exploitation comes before the disclosure, so a time from "discovery in the wild" could be built in more than one way, and the report does not say which.

This briefing reads the report against its own other pages, against CISA's catalogue of known exploited vulnerabilities (KEV) and against the National Vulnerability Database (NVD), then sets out what the report and the NCSC each ask a UK organisation to do. The direction of the report's argument survives that reading. The headline number does not become checkable.

What the report states, and what it does not establish

Five claims carry the report's argument that attackers are ahead. The right-hand column is the one to keep.

Claims in the AI chapter and the intelligence pages of Microsoft's 2026 Digital Defense Report, with page numbers. Our reading, 3 October 2026.

  1. What the report says
    Median time from discovery in the wild to weaponisation is "well below 24 hours" (p14)
    What that establishes
    That Microsoft holds a figure it calls a median, and thinks it is under a day
    What it does not establish
    The sample, period, population, definition of either end, source, or that AI caused it. Nearby pages give 5.3 hours, about five days and single-digit days for other clocks
  2. What the report says
    Attack chain cut "from days to minutes" (pp5, 12, 13); "days to seconds" in the executive summary and landing page
    What that establishes
    That the claim is made for sophisticated actors
    What it does not establish
    A measurement. No actor is named, no sample is given, and Microsoft's documents differ by a unit
  3. What the report says
    A multi-year period of rising known but unpatched flaws; well-funded adversaries may stockpile zero-days (p12)
    What that establishes
    A forecast, worded "likely" and "may be able to"
    What it does not establish
    Any count of stockpiled flaws, or that a stockpile exists. The NCSC puts 2025 at around 40 zero-days at first exploitation
  4. What the report says
    Some Chinese state actors use AI tools to search for vulnerabilities, Russian actors use vibe coding, North Korean remote IT workers use AI for personas (pp40, 42, 43)
    What that establishes
    Microsoft's attribution, and its observation that these actors use AI
    What it does not establish
    How many actors, how often or with what result. The report states no confidence level. For Russia it says AI improves "scale and speed rather than fundamentally changing attack methods"
  5. What the report says
    Attackers are "reaching to advantages first" and defenders must close the gap (p10)
    What that establishes
    A near-term judgement, with equilibrium expected later
    What it does not establish
    A measured gap. The defender figures the report does give are Microsoft product results: threat summaries 60 to 70 per cent faster, and agents handling 75 per cent of its own incidents (p91)

Five other speeds sit in the same report

Page 14 is not the only speed in the report. Five other figures appear on pages 47, 48 and 60, and each measures something different. The diagram draws them to scale beside two counts of our own.

Horizontal bars on a logarithmic hour axis from 1 hour to 60 days. Microsoft's figures: 5.3 hours, below 24 hours with no value stated, as little as 24 hours for one actor, about five days, 1 to 9 days, and 30 to 60 days. Our counts from CISA and CVE records: median 1 day for 47 new flaws in the last 60 days and 3 days for 97 new flaws from November to May. A dashed line marks the report's 72 hour fix target.
Drawn from Microsoft Digital Defense Report 2026 (pages 14, 47, 48 and 60) and from our counts of CISA catalogue 2026.10.02 against CVE.org publication dates, read 3 October 2026.

5.3 hours (page 60) is the only one with both ends named: a median from container start to first exploit attempt for exposed cloud workloads, where default credentials, exposed APIs and unpatched images drive most compromises. The executive summary and the corporate landing page call the same figure an average. As little as 24 hours (page 47) is one actor, tracked as Storm-1175, going from web-facing exploitation to deploying Medusa ransomware. It is a minimum for one group, not a median. Single-digit days (page 47) is the disclosure-to-exploitation window, stated as a trend, and the executive summary softens it to "often to just a few days". About five days (page 48) is a median time-to-exploit from "research published in 2025", which the report does not name. 30 to 60 days (page 48) is median enterprise remediation for critical external CVEs, with no source.

These figures do not contradict each other, because they measure different things. They are a warning about how the headline gets used. Microsoft's landing page sets "well below 24 hours" against "30 to 60 days" and says the mismatch gives attackers "a widening window to act". That subtracts an undefined median from an uncited range. The report's own fix target is 72 hours for newly identified flaws on internet-facing and identity systems (page 48), more than three times its claimed weaponisation median, and the report does not say how the two fit.

The same claim in four Microsoft documents, as read on 3 October 2026. Quotations are exact, apart from straight quotation marks and apostrophes.

  1. Document
    Full report, page 14
    Wording
    "The median time from vulnerability discovery in the wild to weaponization has now collapsed to well below 24 hours"
    Called a median?
    Yes
  2. Document
    Security Insider landing page
    Wording
    "The data shows that the median time from vulnerability discovery in the wild to weaponization has fallen to well below 24 hours"
    Called a median?
    Yes
  3. Document
    On the Issues blog, 1 October
    Wording
    "A vulnerability's discovery in the wild to active weaponization can be well below 24 hours"
    Called a median?
    No: "can be"
  4. Document
    Executive summary
    Wording
    Not stated. It says the window between disclosure and exploitation is shrinking "often to just a few days"
    Called a median?
    Not stated

The BleepingComputer quotation that the attack chain falls "from days to seconds" is the executive summary's sentence. The full report's body says "days to minutes" three times and never says seconds in that sense. The two documents differ by a unit, and neither says why.

What the public record shows

The nearest public check on speed is CISA's KEV catalogue. It lists flaws with evidence of exploitation, and each entry can be set against the date its CVE record was published. We read all 280 additions from 1 November 2025 to 2 October 2026 and fetched the CVE.org publication date for each.

Microsoft's report says CISA added "over 110" flaws to the catalogue from November 2025 to May 2026, "most within a week of disclosure" (page 47). The catalogue holds 154 additions in that window. Within a week of their CVE record, 61 of the 154 were listed: 40 per cent. The sentence holds only if the 57 older flaws are left out. Those were listed a median 785 days after their records appeared. Of the 97 whose records appeared inside the window, 61 (63 per cent) were listed within a week.

KEV additions set against CVE.org publication dates. Our count from catalogue version 2026.10.02 and CVE.org records, read 3 October 2026. The 60 and 30 day windows were chosen after looking.

  1. Set of additions
    All additions, 1 Nov 2025 to 31 May 2026
    Flaws
    154
    Median gap
    24 days
    Within 1 day, within 7 days
    41 (27%), 61 (40%)
  2. Set of additions
    Of those, CVE record published inside that window
    Flaws
    97
    Median gap
    3 days
    Within 1 day, within 7 days
    41 (42%), 61 (63%)
  3. Set of additions
    New flaws added in the last 60 days, 4 Aug to 2 Oct
    Flaws
    47
    Median gap
    1 day
    Within 1 day, within 7 days
    26 (55%), 37 (79%)
  4. Set of additions
    New flaws added in the last 30 days, 3 Sep to 2 Oct
    Flaws
    27
    Median gap
    0 days
    Within 1 day, within 7 days
    18 (67%), 25 (93%)

What this supports, and what it does not. It supports a direction. For flaws that were new, the gap between a CVE record appearing and CISA listing exploitation was 3 days at the median across the report's window and 1 day across the last 60. It does not reach "well below 24 hours" for the earlier window, and the fall from 3 days to 1 is suggestive, not established: monthly medians for new flaws run from 0 to 14 days, and September's 43 additions make it the busiest month of 2026.

Four limits apply to every number above. The catalogue records when CISA accepted evidence of exploitation, not when exploitation began. A CVE record date is not a disclosure date: Zimbra shipped a fix on 20 July, Microsoft's own telemetry shows probing from 28 July, and the CVE record appeared on 13 August (our briefing). Only exploited flaws are in the catalogue, so this is a median over the flaws attackers used, not over all flaws, and the report does not say which population its own median covers. And for a flaw exploited before any fix exists, the clock starts before disclosure. The FortiMail flaw (CVE-2026-104286) was listed on 1 October, the day its CVE record was published (our briefing), and Apple's CoreGraphics flaw one day after its record (our briefing).

The last fortnight shows both clocks at once. CISA added 17 flaws between 19 September and 2 October. Seven were listed the day their CVE record appeared, 11 within three days, and the median gap was 2 days. Six were far older at listing: 13, 20, 44, 45, 49 and 97 days. The 20 was the MikroTik flaw, patched on 3 September, with attack logs that predate the patch, and the 45 was the SharePoint flaw, shipped on 11 August (our briefing). A WordPress flaw was reported exploited by a security vendor on the day its fix was announced, on a timestamp that firm later moved by almost six hours (our briefing). A median of one or two days and a tail of 45 and 97 days is what a real fortnight looks like.

Volume. Microsoft puts 2026 "on track" for a record 72K CVEs (page 14). The NVD lists 73,711 CVE records published in 2026 as read between 19:46 and 19:48 UTC on 3 October, with a quarter still to run: 35,841 in the first half and 36,970 in July to September alone. On the NVD's count the forecast was low, and the direction is right. Volume is not exposure, though. CISA's catalogue has 249 additions dated 2026, which is 0.34 per cent of those records, and 245 dated 2025 against 48,152 records published that year, 0.5 per cent (our counts, a rough ratio because additions include old flaws). The NCSC makes the same point for 2025 and says only about 40 flaws were zero-days when first exploited (NCSC, 11 May 2026). It puts the exploited total at about 400 where the catalogue file counts 245, and does not say what it counted.

From measured to forecast

The second diagram sorts the report's speed and volume claims by what a reader can check. The bottom rung is Microsoft's own telemetry, and it points somewhere quieter than the chapter that frames it.

A four-rung ladder, from measured to forecast. Measured by Microsoft: 5.3 hours, the top five detected CVEs, exploitation shares of intrusions, password attacks down 26 per cent. Taken from public records: KEV additions, the five day median, the first automated ransomware. Stated with no sample or source: the 24 hour median, 30 to 60 days, 72K CVEs, days to minutes or seconds. Forecast: a multi-year spike, stockpiled zero-days, AI worms.
Drawn from Microsoft Digital Defense Report 2026 (page numbers on the diagram) and our counts of CISA catalogue 2026.10.02 against CVE.org dates, read 3 October 2026.

The telemetry points at old flaws. The five CVEs most often detected by Microsoft Defender were disclosed between 2020 and 2023, and 58 per cent of those detections were one 2020 Netlogon flaw (page 34). The report adds that detections are not confirmed exploitation. One of the five, CVE-2023-28231, is not in CISA's catalogue (version 2026.10.02). Our inference: four of the five are Windows components, so the list reflects what Defender detects as much as what attackers use.

Two datasets, two directions. Exploiting public-facing applications is 4.8 per cent of the intrusions Microsoft Defender Experts observed, and the report says its volume "declined sharply from mid-2025 onward" (page 45). In the incident response caseload the same vector rose from 15 to 24 per cent of cases (page 33). The report does not reconcile the two. Our inference is that response cases skew towards the serious ones, but the report does not say so.

People and identities lead. In the Defender Experts data user execution is 30 per cent of initial access, valid accounts 20, malicious copy and paste 13 and phishing 11 (page 44). Password attacks are down 26 per cent year on year (page 64). The case for identity controls rests on this measured rung, not on the forecast one.

Lab results are labelled as lab results. Two frontier models completed a 32-step attack chain in a mock network "with no defenders" (page 14). The report says "Most observed campaigns still retain human direction" (page 17) and that volumes of the first automated ransomware cases remain low. On the JADEPUFFER case it cites, our earlier briefing found that Microsoft's own Azure account supports automated or scripted execution, and that the agentic label comes from Sysdig's July report.

Nation-state claims are Microsoft's attribution. The report states no confidence level for the Chinese, Russian or North Korean observations. It says "some actors" for China, names no group for the AI claims, and for Russia calls AI a force multiplier "rather than fundamentally changing attack methods" (page 42).

Research and marketing in one PDF

Microsoft sells the tools the report recommends. Its three-part answer is to get ready for AI, secure AI and defend with AI, and its defender evidence is its own products: Security Copilot users summarising threats 60 to 70 per cent faster, a Phishing Triage Agent saving "nearly 200 hours" a month, and Microsoft's own team using agents to investigate 75 per cent of incoming incidents (page 91). Those are product results reported without method. That is normal for a vendor report, and it does not make them wrong.

The same report is candid about Microsoft. SharePoint Server is the most frequently exploited product in its Defender Experts data (page 45). A cybercriminal service obtained genuine Microsoft-signed certificates for malware through Microsoft's own artifact signing (page 83). An intrusion tracked as Storm-2885 used Microsoft's device management and cloud identity as its control plane (page 61). A vendor selling a fix and a vendor documenting its own exposure are both in the PDF, and a reader should credit both.

The friendly-name fallacy. "Closing the vulnerability discovery gap", "persistent defense" and "the agentic defense stack" are names, not controls. The controls the report can be held to are the ones with numbers: fix internet-facing and identity flaws within 72 hours, keep a complete inventory, deploy phishing-resistant MFA, and treat revocation latency as a measured outcome (pages 7, 24 and 48). Microsoft's own answer to whether defenders can win by finding flaws first is that finding is not fixing, because patching needs coordination with maintainers, testing and uptime risk (page 28).

The NCSC says the same without the product. It writes that "just finding vulnerabilities does nothing to improve your security" and asks whether you have a process to manage what an AI model finds (10 questions to ask when using AI models to find vulnerabilities), and its blog of 21 September argues that defenders cannot use AI the way attackers do because their problems are mostly organisational, not technical.

What the report says about the UK and smaller organisations

UK and Europe figures in Microsoft's 2026 Digital Defense Report. The report does not say whether the ransomware table counts leak-site listings or Defender detections.

  1. Figure
    Customers most frequently impacted, January to June 2026
    Value
    UK fifth at 3.8%, after the US (25.5%), Israel, Ukraine and Taiwan
    Page
    32
  2. Figure
    Nation-state activity events observed in Europe, July 2025 to June 2026
    Value
    UK 76, Germany 45, Ukraine 42
    Page
    38
  3. Figure
    Share of Russian state targeting
    Value
    UK third at 11%, after the US (21%) and Ukraine (14%)
    Page
    42
  4. Figure
    Share of Iranian, North Korean and Chinese state targeting
    Value
    UK 5%, 4% and 1%
    Page
    41, 43, 40
  5. Figure
    Ransomware table, 2025 to 2026
    Value
    UK 80 to 133 (up 66%); total 8,749 to 8,521 (down 3%); 5,798 entries have no country
    Page
    77

On smaller organisations the report says businesses outside critical sectors, "especially small and medium-sized businesses", remain at high risk from ransomware and business contact impersonation (page 33). Its patching example is a four-week Akira surge in September 2025 across more than 50 organisations, mostly small and medium-sized, through a SonicWall VPN flaw (page 48). That flaw, CVE-2024-40766, was added to CISA's catalogue on 9 September 2024, a year before the surge. Our inference: that points to a patching failure, not a discovery-speed one.

What to do, in the order worth doing

Start from the NCSC's timelines and the report's own, and keep the tightest number for the systems an attacker can reach. The table sets them side by side. The NCSC rows apply when a flaw is on the KEV list and being exploited in a business-critical system.

Patch-time yardsticks. NCSC rows from its vulnerability management guidance, version 2.1, reviewed 1 May 2026. CIR means an assured cyber incident response provider.

  1. Exposure class
    KEV-listed, internet-facing, automatable, attacker gets total control
    Target
    Under 24 hours, plus a CIR check
    Source
    NCSC, responding to active exploitation
  2. Exposure class
    As above, but exploitation is not automatable
    Target
    Under 48 hours, plus a CIR check
    Source
    NCSC, same table
  3. Exposure class
    KEV-listed, not internet-accessible, automatable, total control
    Target
    Under 72 hours, plus a CIR check
    Source
    NCSC, same table
  4. Exposure class
    New flaw on an internet-facing or identity system
    Target
    72 hours
    Source
    Microsoft report, page 48
  5. Exposure class
    Internet-facing services, business as usual
    Target
    5 days
    Source
    NCSC, update by default
  6. Exposure class
    Operating systems and applications, business as usual
    Target
    7 days
    Source
    NCSC, update by default
  7. Exposure class
    Internal or air-gapped services
    Target
    14 days
    Source
    NCSC, update by default
  8. Exposure class
    Critical or high (CVSS 7 or above) fixes, for certification
    Target
    14 days from release
    Source
    Cyber Essentials v3.3, April 2026
  9. Exposure class
    US federal agencies: KEV-listed, public, automatable, total control
    Target
    3 days plus forensic triage; 14 days if not public
    Source
    CISA BOD 26-04, not binding in the UK

Take this with you

Ten actions, in this order

  • List every internet-facing and identity system, including shadow IT, remote management tools and end-of-life devices. Both the NCSC and the report put this first: a clock cannot run on a system nobody knows about.
  • Name, by role, who can call an out-of-cycle patch and take a service offline. Agree in writing that remediating an exploited internet-facing flaw gets the same priority as a total outage, as the NCSC advises, and put the same duty in supplier and managed service provider contracts.
  • Set a patch target for each exposure class using the table above, and write down the tighter number for edge devices and identity systems.
  • Measure your own clock. For each exposed fix in the last quarter record four dates: vendor fix published, your team aware, first instance patched, last instance patched. Report the median and the worst case from fix published to last instance patched, and set it against the date exploitation was first evidenced for that flaw. Do not compare it with 24 hours, because that figure has no stated definition.
  • Check for compromise during the exposure window, before and while patching. An update applied after exploitation does not undo it. The report suggests reviewing the previous 90 days for signs of use before the fix.
  • Where you cannot patch quickly, isolate, restrict or replace: take the service off the internet, or replace end-of-life equipment. The NCSC says patching alone will not always suffice.
  • Put phishing-resistant MFA and passkeys on administrators and internet-facing logins first, cut standing privilege, and measure how long it takes to revoke a compromised session or token.
  • Turn on automatic and hot patching wherever the vendor offers it, and agree staged rollout rings that can run in minutes in an emergency.
  • Give the board one patching number: the median and worst case from fix published to last exposed instance patched, not a count of patches deployed.
  • Before running AI vulnerability discovery on your own code, check that you can fix what it finds. The NCSC asks how you will avoid spending everything finding flaws and have nothing left to fix them.

The NCSC's patch wave blog (1 May 2026) and its vulnerability management guidance are the UK baseline, and the Five Eyes agencies' statement of 22 June says AI is "shrinking the window between vulnerability discovery and exploitation". It gives no figure either, and CISA's BOD 26-04 hedges: AI "may further narrow" the time defenders have to react. For how three-day federal deadlines read to organisations outside the US, see our briefing on the KEV three-day clock.

The question the report leaves open

The report's strongest sentence is not the one in the headline. It is that patch velocity, not patch availability, "is the control that matters" (page 19). That is a claim about your estate, and no vendor median can answer it for you. Microsoft's figure may well be true. Without a sample, a period and two defined ends, nobody outside Microsoft can say whether it is a median over all flaws or over exploited ones, or whether the clock starts at disclosure or at an attacker's first look. The KEV record shows a gap of days for new flaws, shortening towards a day lately.

So the useful question is not whether the median is under a day. For the last exploited flaw on your perimeter, how many days passed between the vendor publishing a fix and the last vulnerable instance being patched, and who in your organisation could have shortened it overnight?

Key facts

Sources

  1. Primary2026 Microsoft Digital Defense Report, 103-page PDF read in full with pypdf: every figure, page number and quotation in this briefing. Downloaded 3 October 2026 at 20:38 BST; last-modified header 1 October 13:42 GMT.Microsoft Threat Intelligenceaccessed 2026-10-03
  2. PrimaryCapture of the same PDF at 1 October 2026 20:35 UTC, byte-identical (SHA-256 match) to the file downloaded on 3 October, used to show the text had not changed since the day of the press coverageInternet Archiveaccessed 2026-10-03
  3. PrimaryExecutive summary PDF, 8 pages: the days-to-seconds sentence, the 5.3 hour average, the omission of the 24 hour median and the few-days wordingMicrosoft Threat Intelligenceaccessed 2026-10-03
  4. PrimaryLanding page, read as raw HTML: the median wording, 30 to 60 days, the nearly 40,000 CVE figure and days to secondsMicrosoftaccessed 2026-10-03
  5. PrimaryPolicy blog of 1 October: the 'can be well below 24 hours' wording and the 72,000 CVE projectionMicrosoft On the Issuesaccessed 2026-10-03
  6. PrimaryCorporate responsibility report page: 5.3 hours described as an averageMicrosoftaccessed 2026-10-03
  7. PrimaryMicrosoft's Zimbra analysis of 30 September: fix on 20 July, probing observed from 28 July, disclosure 13 AugustMicrosoft Security Blogaccessed 2026-10-03
  8. PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.10.02 released 2026-10-02T15:19:38Z, 1,733 entries, fetched 3 October 19:42 UTC: every addition date, due date and countCISAaccessed 2026-10-03
  9. PrimaryCVE.org record API, one example of the 280 records read for datePublished (MikroTik, published 2026-09-05)CVE Programaccessed 2026-10-03
  10. PrimaryNVD API 2.0 totalResults by publication window, queried 19:46 to 19:48 UTC on 3 October, for the 2025 and 2026 CVE countsNIST National Vulnerability Databaseaccessed 2026-10-03
  11. PrimaryBinding Operational Directive 26-04 of 10 June 2026: three day and 14 day remediation timelines for US federal civilian agenciesCISAaccessed 2026-10-03
  12. Primary10 questions to ask when using AI models to find vulnerabilities, 11 May 2026: finding does not improve security, 40,000 CVEs, about 400 exploited, about 40 zero-daysNCSCaccessed 2026-10-03
  13. PrimaryPreparing for a vulnerability patch wave, 1 May 2026: prioritise external attack surfaces, hot patching, update by defaultNCSCaccessed 2026-10-03
  14. PrimaryResponding to active exploitation of vulnerabilities, version 2.1, 1 May 2026: the under 24, 48 and 72 hour table, rapid response pathway, P1 incident agreementNCSCaccessed 2026-10-03
  15. PrimaryPut in place a policy to update by default, reviewed 1 May 2026: best-practice timescales of 5, 7 and 14 daysNCSCaccessed 2026-10-03
  16. PrimaryCyber Essentials requirements for IT infrastructure v3.3, April 2026: critical and high fixes within 14 days of releaseNCSCaccessed 2026-10-03
  17. PrimaryOne does not simply defend agentically, 21 September 2026: why defensive AI use is an organisational problemNCSCaccessed 2026-10-03
  18. PrimaryThe AI shift in cyber risk: why leaders must act now, 22 June 2026: the shrinking window between discovery and exploitationNCSC and Five Eyes partnersaccessed 2026-10-03
  19. Reported byPress coverage of the report on 1 October 2026, used as a pointer: it quotes the executive summary's days-to-seconds sentence and the 24 hour figureBleepingComputeraccessed 2026-10-03

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.