TIRESIS/Patch Window

Patch Window

How many days do you have before a published vulnerability becomes actively exploited? Measured from CVE publication to CISA KEV confirmation across 35 vulnerabilities.

Median patch window
4d
Half of exploited CVEs hit before this
Average patch window
34d
Mean across all KEV CVEs
Shortest observed
1d
0-day or near-0-day exploitation
CVEs measured
35
CISA KEV with full date data
Key insight

The median patch window is 4 days — but 21 CVEs were exploited within 7 days of publication. For internet-facing systems like VPN appliances and firewalls, you should assume a 3–7 day window from patch release to active exploitation.

Average Patch Window by Vendor
appleCRITICAL WINDOW
5 KEV
3d
googleCRITICAL WINDOW
4 KEV
4d
linuxSHORT WINDOW
3 KEV
17d
debianSHORT WINDOW
5 KEV
26d
microsoftMODERATE
6 KEV
39d
netappMODERATE
2 KEV
64d
kenticoEXTENDED
2 KEV
210d
Distribution of Exploitation Speed
0-7 days21 CVEs (60%)
8-30 days6 CVEs (17%)
31-90 days3 CVEs (9%)
91-365 days5 CVEs (14%)
Based on 35 CVEs confirmed in CISA KEV catalog. Patch window = days from NVD publication to KEV addition.
Recent KEV Additions — Patch Window
CVE IDPublishedKEV AddedPatch WindowSMB Score
CVE-2026-850462026-09-032026-09-041dCRITICAL WINDOW53
CVE-2026-835492026-09-012026-09-021dCRITICAL WINDOW53
CVE-2026-835482026-09-012026-09-021dCRITICAL WINDOW58
CVE-2026-725302026-08-192026-08-201dCRITICAL WINDOW49
CVE-2026-725292026-08-192026-08-201dCRITICAL WINDOW51
CVE-2026-728982026-08-102026-08-111dCRITICAL WINDOW56
CVE-2026-185772026-08-022026-08-031dCRITICAL WINDOW49
CVE-2026-16032026-02-102026-03-0927dSHORT WINDOW76
CVE-2026-251082026-02-132026-02-2411dSHORT WINDOW80
CVE-2026-227692026-02-172026-02-181dCRITICAL WINDOW84
Cyber Weather →Active Targets →Forecast Accuracy →Methodology →