Citrix customers post the slowest remediation of any vendor studied, at a median of 461 days.
AI models collapse vulnerability discovery from months to hours
A report by SentinelOne and Tenable Holdings finds that "new frontier AI models compress vulnerability discovery from months to hours," shrinking the calendar that defenders have to react. The research warns that current attacker timelines are already moving faster than standard patch cycles can address, and that AI is accelerating that trend: the time from public disclosure to working exploit code is now "about a week" in many cases.
That compression changes the arithmetic of risk. Where a routine patch cycle once absorbed weeks or months of exposure, the report says attackers equipped with advanced models can discover and operationalize flaws at a tempo that outstrips typical remediation schedules.
Exposure and runtime detection converge on the same edge-device vendors — 79%
The report quantifies alignment between two measurement sources: exposure data and runtime detection. Those sources "converge on the same edge-device vendor surfaces 79% of the time," while they show only a 21% overlap at the individual vulnerability level. In plain terms, organizations and defenders are seeing the same handful of affected vendors repeatedly, even if the exact vulnerabilities flagged by each method do not perfectly match.
SentinelOne and Tenable also note that both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities — reinforcing that certain vendor and device families are focal points for multiple attacker types.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTwelve "multi-nexus" vulnerabilities span nation-state and criminal operators
The researchers identified twelve vulnerabilities that carry confirmed "multi-nexus" attribution — meaning state-sponsored and ransomware operators independently exploited the same flaw. Those multi-nexus flaws occurred "across five distinct threat categories, including China, Russia, DPRK, Iran-nexus and criminal (financially motivated) actors."
That overlap indicates a shared utility in some vulnerabilities: the same technical weakness is valuable to actors with divergent motives, increasing the chance a flaw will be weaponized quickly and repeatedly.
F5 exposure, remediation complexity, and the 24-day operational gap
Product-line findings in the dataset are stark. More than half — 54% — of organizations running F5 products "carry at least one exposed, actively exploited vulnerability." At the other end of the remediation spectrum, Citrix customers show the slowest response times, with a median remediation interval of 461 days — a "concrete illustration of how specific product lines stay exposed long after a patch exists."
The report further isolates remediation complexity as a measurable latency: "Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap," widening the window attackers have to operationalize an exploit. The authors use that figure to underscore why simply patching faster is insufficient without parallel efforts to reduce attack surface and reinforce endpoint defenses.
What this means for security teams, F5 and Citrix customers, and attackers
- Security teams: Visibility has never been greater, the report notes, and it argues for a new decision layer that turns alerts into "decision-ready context." The recommendation is to reduce reliance on manual triage so teams can act on critical findings faster than attackers can weaponize them.
- F5 and Citrix customers: Organizations running F5 products should expect continued exposure pressure — 54% carry at least one actively exploited vulnerability — while Citrix customers face outsized remediation timelines (median 461 days), creating prolonged windows of risk even after fixes are available.
- State-sponsored and criminal actors: The same small set of high-severity vulnerabilities attracts both groups; twelve confirmed multi-nexus flaws show independent exploitation by nation-linked and financially motivated operators, increasing the likelihood that a discovered weakness will see follow-on attacks.
The report's central lesson is succinct: attackers are accelerating, and defenses must change in lockstep. Shortening the time from detection to decision — and coupling faster patching with attack surface minimization and stronger endpoint protections — are the concrete steps the authors highlight to blunt a model-driven surge in vulnerability discovery and exploitation.
Read the original report: https://www.securitymagazine.com/articles/102530-ai-models-are-finding-vulnerabilities-faster




