Your Vulnerability Backlog Just Became an Attack Backlog 

September 14, 2026
TO YOU: A BACKLOG.
TO AI: A SEARCH SPACE.

Security teams have always carried vulnerability backlogs. The assumption underneath that model was time: defenders could prioritize, investigate, and remediate vulnerabilities based on severity, reachability, known exploitation, and business impact.

💡 AI is collapsing that time advantage.

Mean time from vulnerability disclosure to confirmed exploitation has fallen from 2.3 years to less than one day. At the same time, software vulnerabilities have surpassed stolen credentials as the leading breach entry point. And AI can make the information defenders publish part of the attack process.

In one benchmark cited in our research, GPT-4 successfully exploited 87% of one-day vulnerabilities when provided their CVE descriptions.

What we learned

AI can reason across advisories, patch diffs, source code, dependencies, build paths, containers, and runtime behavior to generate exploit hypotheses faster and identify relationships between weaknesses.

The attack surface itself is also expanding.

Open-source downloads reached 9.8 trillion in 2025, alongside 1.233 million malicious packages tracked. AI-assisted development introduces another dimension: AI-assisted commits leaked secrets at 3.2% versus 1.5% for baseline public GitHub commits—more than 2X the rate.

More software. More dependencies. More AI-generated code. Less time between disclosure and exploitation. That changes what a vulnerability backlog represents.

Why this matters

A vulnerability backlog is no longer simply technical debt.

It is accumulated attack opportunity.

What defenders see as hundreds or thousands of issues waiting to be prioritized, AI can increasingly treat as a searchable set of weaknesses, relationships, and potential attack paths.

Yesterday's “accepted risk” doesn't necessarily carry yesterday's risk profile when an attacker can reason across vulnerabilities at machine speed.

And the pressure isn't only coming from attackers. Evidence clocks are tightening too: the EU Cyber Resilience Act introduces 24-hour / 72-hour / 14-day reporting milestones for actively exploited vulnerabilities.

Security programs therefore need to move beyond continuously finding and prioritizing vulnerabilities to continuously eliminating exploitable vulnerabilities—and proving it.

Because AI doesn't necessarily need your backlog to be critical.

It needs it to be chainable.

See why vulnerability backlogs become board-level risk

Source note Build Secure or Be Forever Insecure, pp. 3–8. The whitepaper describes exploit timelines compressing from days/weeks toward hours and says vulnerability backlogs become accumulating business exposure.