Skip to main content

Healthcare’s 30-day patch policy may already be obsolete

Errol Weiss, Chief Security Officer, on vulnerability patch deadlines shrinking from weeks to days and hours.

By Errol Weiss, Chief Security Officer, Health-ISAC

Five days: That was the median time in 2025 between the publication of a high- or critical-severity vulnerability and its addition to CISA’s Known Exploited Vulnerabilities (KEV) Catalog of flaws known to be exploited in the wild, according to Rapid7’s 2026 Global Threat Landscape Report.

Now put that beside your own remediation policy, which most likely sets a timeline of 30 days.

AI is adding speed and scale to hackers’ already effective tactics, and it’s helping blow those numbers apart. Frontier models can help discover vulnerabilities, develop exploits, and carry out complex, multi-step operations that once demanded specialized skills. And those capabilities are also beginning to appear in cheaper, open-weight models.

What’s worse, attackers might not even need a person directing the AI: In a first-of-its-kind event, OpenAI’s latest models went rogue during internal testing and hacked Hugging Face to find ways to abuse a benchmark.

According to Health-ISAC’s latest Frontier AI in the Health Sector report, the takeaway for security leaders is blunt: the deadline for fixing vulnerabilities has shrunk from weeks to days and hours.

Read the article in Cybersecurity Insiders. Read More

Topics  covered include:
  • The window from disclosure to exploit is closing
  • There’s no more Patch Tuesday. It’s Patch Now
  • The contract is now a security control
  • Redefine what’s reasonable