Source: Tenable Blog
Author: Lucas Tamagna-Darr
URL: https://www.tenable.com/blog/cyber-risk-lurks-in-the-vulnerability-disclosure-gaps
ONE SENTENCE SUMMARY:
Vulnerability management faces timing challenges with disclosure delays, increasing risk from fast-exploited vulnerabilities before detection and patching.
MAIN POINTS:
- 2.6% of 63,862 CVEs had a public PoC published from Jan 2024 to Sept 2025.
- Over half of these PoCs appeared within seven days of vulnerability disclosure.
- Average time for vulnerabilities to publish in NVD is 15 days, risking delayed mitigation.
- Vulnerability lifecycle stages: CVE issuance, NVD publication, PoC, exploit framework, known exploitation.
- Significant risk exists between CVE publication and known exploitation.
- Average delay to functional exploit is 21 days, median is three days.
- Median time for known exploitation in CISA KEV is 10 days, Tenable KEV is five days.
- Accelerated PoC publication means attackers can exploit before NVD recognizes it.
- Relying on NVD delays risk awareness by over two weeks.
- Tenable offers quicker coverage, mitigating risk effectively within 12-24 hours post-disclosure.
TAKEAWAYS:
- Timing from disclosure to exploitation is critical for vulnerability management.
- NVD delays increase risk; quicker identification and patching are essential.
- Tenable enhances timely visibility of new vulnerabilities.
- Fast PoC publication alerts attackers, requiring swift defensive action.
- Security teams must prioritize immediate awareness and response strategies.