# Exploitation Timing Is Structurally Independent of Disclosure Timing

- **Artifact ID:** CHQ-SM-2026-013
- **Canonical source ID:** CHQ-ANRM-2026-010
- **Version:** v1.1
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/memoranda/chq-sm-2026-013
- **Machine-record SHA-256:** `1acba9da07f89851997044cfaa20e764d601a81131d11dc4ba8bea76b5f686d5`

## Complete structured record

```json
{
  "id": "CHQ-ANRM-2026-010",
  "aliases": [
    "CHQ-SM-2026-013"
  ],
  "title": "Exploitation Timing Is Structurally Independent of Disclosure Timing",
  "descriptor": "Exploitation Timing Is Structurally Independent of Disclosure Timing",
  "issued": "2026-04-07",
  "classification": "Analytical Research / Non-Advisory",
  "status": "ISSUED",
  "version": "v1.1",
  "memo_type": "ANRM",
  "authority_level": "ANALYTICAL",
  "referenced_by": [
    "CHQ-ASC-2026-005",
    "CHQ-SM-2026-017",
    "CHQ-SM-2026-018",
    "CHQ-SC-2026-006",
    "SC-2026-006 criterion v2.0",
    "CHQ-EX-2026-014"
  ],
  "prior_version_hashes": [
    {
      "version": "v1.0",
      "hash": "04079472444883897a0f6b504e79436a88990b7b7fd138250fc6e818eafa52a7"
    }
  ],
  "inherits_from": "CHQ-ANRM-2026-004",
  "related_artifacts": [
    "CHQ-P-2026-011",
    "CHQ-P-2026-012"
  ],
  "citable_assertion": "In a material fraction of confirmed exploitation events, exploitation precedes public disclosure by days to weeks, creating a window during which disclosure-based remediation controls have no available response. The exposure boundary is defined by the gap between attacker exploitation and public awareness, not by organizational patch velocity. Security programs that do not have a documented response model for pre-disclosure exploitation windows are operating with an unaddressed structural gap.",
  "purpose": "",
  "statement": "When exploitation of a vulnerability precedes its public disclosure, the remediation model that organizations operate under has no available response during that window. The patch does not exist. The CVE has not been published. The KEV catalog has not been updated. Every control that depends on disclosure as a triggering event fails simultaneously.\n\nThis is not a failure of patch velocity. It is a structural property of disclosure-based security operations: the model assumes that defenders gain awareness before or concurrent with exploitation. That assumption does not hold in a material fraction of confirmed exploitation events.\n\nThe boundary of the exposure window is not defined by organizational response capability. It is defined by the gap between when the attacker begins exploiting and when the vulnerability becomes publicly known.",
  "observability": "",
  "boundary": "",
  "reliance_language": "",
  "reliance_boundary": "",
  "revision_history": "v1.0 (April 2026): Initial issuance. Canonical SHA-256: 04079472444883897a0f6b504e79436a88990b7b7fd138250fc6e818eafa52a7.\n\nv1.1 (September 22, 2026): Added the quarter's validation cases: PaperCut (disclosure August 26; bypass August 27), FortiClient EMS, and Fortinet CVE-2025-25249 as the non-example that exposed the identifier-reservation proxy. Recorded that SC-2026-006 criterion v2.0 derives from this memorandum.",
  "scope": "This memo defines a structural condition affecting the timing relationship between vulnerability exploitation and public disclosure in enterprise security environments.\n\nIt does not evaluate specific vendor disclosure practices, recommend patch management architectures, or assess organizational vulnerability management maturity.",
  "context": "Three independent evidence sources document this condition with consistent directionality.\n\nVulnCheck's analysis of 2025 exploitation data found that 28.96% of Known Exploited Vulnerabilities showed evidence of exploitation on or before the day their CVE was published. This is an increase from 23.6% in 2024. The trend is moving in one direction.\n\nMandiant's M-Trends 2026 report documents mean time to exploit at negative seven days within their engaged incident caseload — organizations that retained Mandiant for active breach response. Within the population of organizations that experienced confirmed breaches, exploitation was occurring before patch availability as a statistical norm.\n\nAmazon's MadPot sensor network confirmed that Interlock ransomware was exploiting CVE-2026-20131 in Cisco's Secure Firewall Management Center since January 26, 2026. Cisco disclosed the vulnerability on March 4, 2026. The gap was 36 days. During that window, no patch existed. The Cisco FMC vulnerability allowed unauthenticated remote code execution as root on a system that manages policy and configuration for an entire firewall fleet.\n\nThese three sources describe the same structural condition from different angles: population-level exploitation statistics, breach caseload analysis, and a single confirmed instance measured precisely.",
  "governance_condition": "Disclosure-based security operations assume that public vulnerability disclosure is the event that initiates the defender response window. Patch management programs, KEV catalog monitoring, threat intelligence feeds, and vulnerability prioritization frameworks all depend on this assumption.\n\nThree organizational behaviors are invalidated by the evidence:\n\nFirst, that patching promptly constitutes a sufficient risk reduction response for internet-facing infrastructure. When exploitation precedes disclosure, prompt patching cannot address compromise that occurred before the patch existed.\n\nSecond, that KEV catalog absence constitutes evidence of non-exploitation. The catalog reflects confirmed exploitation that has been publicly attributed and processed. It does not reflect exploitation that preceded that attribution.\n\nThird, that mean time to patch is the primary risk variable in vulnerability management. When exploitation precedes disclosure, the relevant variable is what controls existed before the patch was available — a question most programs do not have a documented answer to.",
  "analytical_observations": [
    "The September validation set adds PaperCut (public disclosure August 26; first-patch bypass August 27), FortiClient EMS, and Fortinet CVE-2025-25249 as a non-example. Fortinet's identifier age did not measure defender awareness because the vulnerability was publicly disclosed and fixed in January; that failure exposed the identifier-reservation proxy and informed SC-2026-006 criterion v2.0.",
    "The pre-disclosure exploitation window is not an anomaly produced by unusually sophisticated attackers. The Cisco FMC case involved a ransomware group, not a nation-state. The VulnCheck data covers the full population of known exploited vulnerabilities, not a selected set of advanced intrusions.",
    "The window exists because vulnerability discovery, exploit development, and operational deployment by attackers are not synchronized with vendor discovery, patch development, and public disclosure. These are independent processes with independent timelines. When attacker timelines run ahead of vendor timelines, the gap is invisible to defenders operating on disclosure-based models.",
    "Management plane and fleet management vulnerabilities amplify the consequence of the pre-disclosure window. A vulnerability in an endpoint affects one endpoint. A vulnerability in a system that manages a fleet of security appliances affects every device that fleet manages, without requiring individual device compromise. The Cisco FMC case demonstrates this: one compromised management system yields authority over every firewall it manages.",
    "The pre-disclosure window is longer for vulnerabilities in management plane infrastructure than for application-layer vulnerabilities, because management plane systems are harder to monitor, have fewer independent researchers examining them, and are more likely to be targeted by actors who prioritize dwell time over immediate detection."
  ],
  "exclusions": [
    "Specific vendor disclosure timelines or practices",
    "Coordinated vulnerability disclosure program design",
    "CVE publication process reform",
    "Whether any specific organization's patch program is adequate",
    "Pre-disclosure exploitation events where the gap is measured in hours rather than days"
  ]
}
```
