Desk live·
ForensicPost
Cloud/Analysis/File 25-1216

Newly Disclosed Vulnerabilities Weaponised Within Hours Through 2025

The 2025 record shows newly disclosed vulnerabilities weaponised within hours. The patch cycle was designed around a window that no longer exists.

Constructed geometry · not a chart of case data
TargetEnterprise software estates
ActorMultiple
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Reviews of the 2025 vulnerability landscape describe sustained pressure on enterprise infrastructure, edge devices and developer tooling, with attackers weaponising newly disclosed vulnerabilities within hours of publication.

Coordinated Disclosure Assumed A Head Start

The model this industry runs on is that a vulnerability is reported privately, a fix is prepared, and publication happens with the patch available. Defenders then have a period — historically days or weeks — during which they are informed and attackers are catching up.

That period was the entire point. It is what made responsible disclosure defensible against the argument that publishing helps attackers.

At an interval measured in hours, the head start is gone. Publication is now a starting gun heard equally by both sides, and the side that has to schedule a change window is at a structural disadvantage against the side that has to run a script.

The Asymmetry Is In The Work, Not The Skill

Weaponising a published advisory is increasingly mechanical: the fix shows what changed, the advisory shows where, and building a working exploit from those two facts is a solved problem for a competent researcher.

Deploying a patch across an enterprise is not mechanical. It requires inventory, testing, change approval, maintenance windows, and coordination with people whose systems will be interrupted — and 25-0723 established that even completing it may not remediate.

What This Does To The Argument In 26-0405

This desk has argued that patching failed as a primary control because volume exceeded capacity. This file makes the sharper version of the point: even for the small subset an organisation would drop everything for, the timeline no longer permits winning.

That is an argument for architecture over remediation — segmentation, least privilege, monitoring that assumes compromise — which is unsatisfying because it is expensive, slow and cannot be reported as a percentage.

A Caution

"Within hours" describes the fastest observed cases and the ones worth writing about. It is not the median. Most disclosed vulnerabilities are never exploited at all, and treating the extreme as typical would produce exactly the misallocation this desk criticises elsewhere.

Graded medium accordingly. The direction is well supported; the distribution behind the headline is not published by anyone we reviewed.

This is an analysis file

Built on published 2025 vulnerability reviews, listed below. Timing claims describe observed cases rather than a measured distribution. Corrections: corrections@forensicpost.com.

Sources
  1. Vulnerability report for the year 2025Vulnerability-Lookup
  2. Lessons from 2025: zero-day exploitation shaping 2026Outpost24
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary