#038
2026-09-20

Patching No Longer Works: 80% of Flaws Are Exploited Before Disclosure, Web DDoS Hit Last Year’s Pace in Half a Year

📰 Looking for more news?
View full news list

The industry has long operated on an unspoken assumption: between a vulnerability being disclosed and attackers actually using it, there is a buffer of days — enough time for vendors to ship patches and for ops teams to schedule a maintenance window. Radware’s freshly published H1 2026 Global Threat Analysis Report just drew a line through that assumption.

“Disclosure to first attack” went negative for the first time

The most striking figure in the report is the exploitation timeline: in 2024 the average was 53 days after disclosure before the first in-the-wild attack, 2025 shrank it to 21.5 days, and H1 2026 dropped it below zero — attacks now happen on average before the official CVE announcement. In other words, more than 80% of exploited flaws are zero-days: in more than four out of five cases, by the time the news breaks, the attack has already happened.

The traditional playbook was “track CVE advisories → assess impact → patch before the attacks arrive.” The first premise of that flow no longer holds. Patching is no longer defense — it is post-hoc inspection. What actually has to survive the attack is your system during the window before any patch exists.

Attack volume compounds: half a year ≈ 83% of all of last year

The other half of the same report is volume. H1 2026 Web DDoS attacks surged 110.6% over H1 2025; mitigations in the first six months alone already approach 83% of the entire 2025 total, and if H2 holds the same pace, full-year growth could reach 166%. By region, North America is projected to grow the fastest in 2026 (≈ +190%), versus ≈ +60% in EMEA and ≈ +27% in APAC.

Notice the scale of “110 or 509 attacks per customer per day” — for most enterprises DDoS is no longer a question of whether it happens, but a daily constant; the only question is whether your infrastructure survives it.

AI is accelerating on both sides

The report also carries an awkward survey stat for security teams: 77% of organizations are deploying AI agents, yet only 17.2% have full visibility into the agents running in their environments; over 70% have grown their internal API usage, 81.2% ship production API updates weekly, but only 6.9% fully document their APIs. The attack surface is expanding fast while defenders haven’t even finished an inventory of what they own.

Meanwhile bad-bot traffic stays elevated — H1 2026 is already near 60% of all 2025 volume, with North America at 50.1%. That crawler and automated traffic isn’t just a security problem: the CDN bandwidth and ops budget it consumes is real money (the same story we’ve covered in our AI bot traffic pieces and Cloudflare’s new AI-crawler defaults).

What this means for your servers

Stack the three facts together: negative time from disclosure to exploitation, 14,000+ malicious transactions per app per day, attackers that never sleep. The conclusion is one sentence: a defense that waits for a human to read an alert is a generation behind the attacker. Detection, blocking, and verification must happen at machine speed — in the same second the attack lands.

Concretely, three things: First, automated WAF and DDoS scrubbing at the edge, so abnormal traffic is stopped before it reaches the origin instead of waiting on a log review; second, continuous anomaly detection — behavioral baselines on your APIs and admin panels so the real exploitation buried in 14,000 bad transactions gets flagged in seconds; third, MTTR in minutes — you can’t control when a patch ships, but you can control how fast you get blocked, contained, and verified. That is why AIOps has moved from a “nice to have” to the baseline of entry.

💡 LAFA Perspective

When 80% of flaws are exploited before disclosure, the “wait for the patch” strategy officially expired this year. Lafa System’s answer is simple: automate detection, blocking, and verification so your defense reacts in the same second the attack lands — because the other side no longer waits for anyone.