In 2018, the average gap between a CVE going public and the first confirmed exploitation of it in the wild was 2.3 years. Two years and change. You could see a CVE, log it, groom it, argue about severity, wait for the next maintenance window, get pulled onto something else, come back a quarter later, […] The post Time to Exploit Went Negative.