Organizations now take longer to patch vulnerabilities even as attackers break into networks in under half an hour, according to Dataminr’s 2026 Mid-Year Threat Landscape Report.
The report highlights concerning trends across cybersecurity in the second half of the year, particularly in addressing vulnerabilities amid AI-powered threats.
Attackers are moving faster than defenders
Citing data from Verizon and CrowdStrike, Dataminr said the median time to patch vulnerabilities increased from 32 to 43 days in the first half of 2026, while the average attacker breakout time has fallen to just 29 minutes.
Drawing on Dataminr’s real-time analysis of more than 1 million public data sources and more than 43 TB of daily signals, the report highlights a widening gap between vulnerability disclosure and exploitation.
“Attackers are moving in under half an hour, and defenders are averaging over six weeks to patch. No team is going to out-patch a 30-minute breakout window. The only lever left is deciding which vulnerabilities are worth chasing at all,” Dataminr said in an official statement.
Dataminr questions the effectiveness of the CVSS scores
Alongside the growing disparity, Dataminr also questioned the effectiveness of Common Vulnerability Scoring System (CVSS) scores as the primary method for prioritizing remediation efforts.
“A CVSS score tells you about the technical severity of a flaw. It tells you almost nothing about whether that flaw is being actively exploited, whether it’s reachable in your environment, or what it would actually cost you if someone got through it.”
“A critical CVE sitting behind segmented networks and strict access controls is a different problem than the same CVE exposed on a flat, internet-facing network. And CVSS alone can’t tell you which one you’re looking at.”
According to Dataminr, organizations that prioritize patching solely by CVSS score overlook the vulnerabilities that pose the greatest real-world threat. Instead, they should prioritize remediation based on exploitability and potential business impact.
AI is creating a vulnerability triage problem
Aside from the widening disparity between discovery and exploitation, Dataminr also found that artificial intelligence has started to create what it calls a “vulnerability-triage problem.”
While AI enables security teams to identify more vulnerabilities than ever before, it has also dramatically increased the volume of findings that need prioritization. Dataminr’s AI models identified approximately 300 highly critical, unique vulnerabilities during the first half of 2026 that it projects will have widespread, high-impact consequences.
“More findings doesn’t automatically translate to more protection. Without a way to triage that volume, it just buries the handful of vulnerabilities that actually matter under a backlog of ones that don’t,” said Dataminr.
The company argues that the challenge is no longer detecting vulnerabilities, but determining which ones pose the greatest risk based on exploitability, exposure, and business impact.
“Detection isn’t the bottleneck anymore. What they’re missing is prioritization: mapping severity against exploitability, exposure, and business impact so teams remediate what adversaries can actually reach, instead of working a queue in the order it was generated.”
Dataminr report: key findings
Here are other key findings in Dataminr’s report:
- Malware-family detections declined 25% in the second half of 2025, while phishing campaign detections rose 23% to 318,000, driven in part by AI-enabled vishing and other social engineering attacks.
- TeamPCP poisoned the Trivy and Checkmarx KICS scanners’ CI/CD supply chains, as well as the LiteLLM AI gateway, cascading stolen secrets to at least 1,000 enterprise SaaS environments.
- Over 63% of cyber-loss events exceeded $1 million and 50% exceeded $10 million. Ransomware accounts for 25% of confirmed 2026 losses so far. This loss data will mature over time.
Taking a targeted approach to remediation
In response, Dataminr recommends shifting the focus from asking whether a CVE is critical to asking whether “This specific flaw [is] being targeted in my sector, and can an attacker actually reach my crown jewels through it?”
According to the company, this shift in thinking can make even large vulnerability backlogs more manageable and help organizations build patching programs that reduce risk rather than simply generate more work.
Coming out ahead of attackers
Looking ahead, Dataminr said the organizations that come out ahead in cybersecurity will not necessarily be those that patch the most vulnerabilities, but those that “patch the right things first.”
“That means putting those same three factors — exploitability, exposure, and business impact — ahead of a bare CVSS number when deciding what to fix.”
Earlier this year, Dataminr introduced a new AI-powered cyber defense platform built on real-time intelligence and agentic AI. Learn how the platform helps enterprise security teams identify threats earlier and streamline incident response.





