A Record Year for CVEs
Patching was built for a world that gave defenders time. Vulnerabilities were disclosed, vendors shipped fixes, and security teams had days or weeks to test and deploy them before attackers could act.
That world no longer exists, and security teams are beginning to see patching as an outmoded security tactic in an AI world. According to 2025 CVE reports, 48,185 vulnerabilities were disclosed in 2025, up 20.6% year over year. Of those, nearly 40% were rated Critical or High severity. That comes to roughly 52 serious vulnerabilities a day, every day, for a full year.
The volume is now straining the systems designed to track it. In September 2026, CISA announced it would discontinue its weekly vulnerability bulletin and instead direct organizations toward risk-based prioritization resources such as the Known Exploited Vulnerabilities (KEV) catalog. The reality is that defenders can no longer patch every vulnerability as it appears. Risk-based prioritization has become a necessity, and organizations need security controls that reduce exposure while patches are still being evaluated and deployed.
The Disclosure-to-Exploit Window Has Collapsed
Rising vulnerability volume would be manageable if attackers moved slowly. With AI, they aren’t anymore.
Recent research shows the disclosure-to-exploitation window shrinking at an alarming rate, to now being around 10 hours. Even worse, 29% of CVEs were exploited on or before their day of publication.
Compare these figures to a typical enterprise patch cycle. A fix must be tested, approved, scheduled, and deployed across production hosts, a process measured in days or weeks. The attacker’s clock now runs on hours, and for nearly three in ten exploited vulnerabilities, it starts the same day the CVE becomes public.
How AI Is Compressing the Vulnerability Lifecycle
AI is accelerating both sides of this equation. Automated discovery is helping researchers uncover vulnerabilities at unprecedented rates, while attackers increasingly use AI tools to analyze patches, identify exploitable changes and accelerate intrusion activity. Turning a published fix into a working exploit no longer requires the same level of specialized expertise.
The Aurora ransomware operation illustrates the trend. Aurora’s operator handed valid credentials to an AI coding agent to handle reconnaissance, scanning and exploitation, then deployed a payload built specifically for ESX. Whether used by defenders or attackers, AI is compressing timelines across the vulnerability lifecycle.
What This Means for the Hypervisor
Attackers follow leverage, and the hypervisor offers more of it than any other layer in the data center. A single host can run domain controllers, databases and critical applications side by side, and an attacker with admin access to the hypervisor can deploy ransomware that reaches every VM on it.
Ironically, the hypervisor is also one of the most operationally complex layers to patch. Each ESX host has to be evacuated, placed in maintenance mode, patched and rebooted, one host at a time so the cluster keeps capacity. Some fixes can be applied live, but many still require that full cycle. So the layer with the most to lose also has the longest route from disclosure to protection, and it now faces exploits that arrive in hours.
Attackers have noticed. The hypervisor’s share of malicious encryption climbed 8x in 2025, yet exposed VMware ESX servers had fallen 90%. Attackers stopped waiting for exposed hosts and came in through the network instead, often using compromised internal credentials to reach the hypervisor. As Aurora demonstrated, AI is shortening that path even further. And when attackers arrive with valid credentials, there may be no vulnerability to exploit and no patch capable of stopping them.
CVE-2026-59310: The Window in Practice
CVE-2026-59310 demonstrates how narrow the patching window has become. Broadcom released a fix upon disclosure, yet exploitation began within 5 days and more than 300 victim systems were identified globally. The issue wasn’t the availability of a patch. It was the reality that many organizations could not test and deploy it before attackers began taking advantage of the vulnerability. This example, amongst many others, calls for runtime exploit prevention on the hypervisor itself.
ZeroLock protects against hypervisor vulnerabilities before they’re even assigned a number.
ZeroLock provides Preemptive Hypervisor Security to enforce prevention at the hypervisor control plane itself:
- Exploit Prevention and Lockdown Rules close off the specific exploit pathway a vulnerability would use, within hours, without a reboot, requiring a signature, or waiting on a vendor’s official fix. The hypervisor stays protected between disclosure and patch deployment.
- CLI-MFA requires verified authorization for privileged hypervisor commands. A valid credential or an abused trust relationship can’t be used to silently reach host admin, which matters when attackers arrive with stolen credentials, as Aurora’s operator did.
- AI behavioral detection watches for what an attack does: unusual command sequences, encryption behavior, lateral movement. Because it doesn’t depend on known signatures, it catches novel and zero-day activity that no CVE-based defense could recognize yet.
- Automated remediation contains and stops in-progress activity in real time, without waiting for an analyst to triage an alert.