Cyberattackers are finding and weaponizing software flaws far faster than many organizations can patch them, according to Microsoft’s newly released 2026 Digital Defense Report. The company says the median time between a vulnerability being discovered in active attacks and being weaponized has fallen to well under 24 hours, while critical fixes at large organizations can still take 30 to 60 days.
Artificial intelligence is helping both sides move faster. Microsoft says defenders are using AI to analyze code, connect security signals and investigate threats. Attackers are applying it to reconnaissance, phishing, vulnerability discovery, malware development and activity after they gain access.
The findings matter beyond corporate security teams. Faster attacks increase the value of automatic updates, strong account protection and skepticism toward instructions that ask a user to paste commands or disable security tools.
Nearly 40,000 vulnerabilities were reported in six months
Microsoft says nearly 40,000 publicly reported Common Vulnerabilities and Exposures, or CVEs, were published during the first half of 2026. If that pace continues, the yearly total would be roughly double the previous rate cited by the company.
More reported flaws do not necessarily mean every device is becoming less secure. Some of the increase may reflect better discovery. The immediate problem is the gap between discovery and repair: attackers can increasingly automate the search for exposed systems while software owners, IT teams and users still need time to test and install patches.
Microsoft’s report is based on its own security products, investigations and threat-intelligence visibility. That gives the company an unusually broad dataset, but it is not a complete census of every attack on the internet. The numbers should be read as indicators from Microsoft’s environment rather than universal measurements.
Old vulnerabilities remain highly useful to attackers
The report’s most sobering lesson is that attackers do not always need a new zero-day flaw. Among detections connected to the five leading CVEs Microsoft analyzed, 58% involved CVE-2020-1472, the “Zerologon” Windows Server vulnerability disclosed in 2020.
That finding illustrates why routine maintenance still matters in an AI-driven threat landscape. AI can help find a way into an exposed system more quickly, but an unpatched five- or six-year-old flaw may already provide the opening.
For households and very small businesses, the practical response is straightforward: allow operating systems, browsers, routers and frequently used applications to update automatically when possible. Devices that no longer receive security updates should be isolated, replaced or used only for low-risk offline tasks.
AI speeds up familiar attack methods
Microsoft cautions that fully autonomous cyberattacks are not suddenly the norm. Most complicated intrusions still involve meaningful human direction. What has changed is the amount of repetitive work an AI system can accelerate or perform on an operator’s behalf.
The company reports seeing AI used across vulnerability research, target reconnaissance, tailored phishing, exploit development, data analysis and post-compromise activity. In a controlled evaluation, one frontier system completed a 32-stage attack sequence. Microsoft also says it has observed early AI-orchestrated activity in real incidents, though current volumes remain low.
That distinction is important. The report does not say every phishing message or malware campaign is now run by an autonomous agent. It says AI is lowering the time and expertise required for parts of an attack, potentially allowing more campaigns to run at greater speed and scale.
Do not paste commands from an unexpected prompt
One fast-growing method highlighted by Microsoft is often called “ClickFix.” A fake error or verification message tells the victim to copy and run a command—commonly through Windows Run, PowerShell or a terminal—to solve a problem. The command actually installs malware or gives an attacker access.
Microsoft Defender recorded attacker-supplied ClickFix-style commands executing on more than 1.1 million unique devices between February and early May 2026, roughly eight times the earlier level cited by the company.
A legitimate website should not require visitors to paste an unfamiliar command into an operating-system tool to prove they are human, update a browser or open a document. If a page gives those instructions, close it. Download updates from the application itself, the device’s app store or the vendor’s official support page.
Accounts remain a primary entry point
In the Microsoft Defender Experts dataset discussed in the report, user execution represented 30% of observed initial access and valid accounts another 20%. Separate incident figures summarized by Cybersecurity Dive identified vulnerable public-facing applications and phishing as leading access routes. The percentages describe different datasets, but they point to the same basic lesson: attackers still rely heavily on people, credentials and exposed software.
Consumers and small organizations should use a password manager to generate a unique password for every important account. Multifactor authentication is better than a password alone, and phishing-resistant methods such as passkeys or physical security keys provide stronger protection than codes that can be copied into a fake login page.
Business owners should also separate administrator accounts from everyday accounts and remove access that employees or contractors no longer need. AI does not create excessive privileges, but it can help an attacker exploit them more efficiently after an account is compromised.
Five practical steps to take now
- Turn on automatic updates for operating systems, browsers, security tools, routers and internet-facing business software.
- Use unique passwords and passkeys, stored in a reputable password manager.
- Refuse copy-and-run instructions from websites, emails, pop-ups or unsolicited support messages.
- Keep recoverable backups, including at least one copy that ransomware cannot rewrite from the affected computer.
- Review access regularly and give apps, employees and AI agents only the permissions required for their current task.
What the report does—and does not—prove
Microsoft sells security products, so its report also supports the company’s case for faster, AI-assisted defense. Its findings deserve scrutiny alongside reports from other vendors, independent researchers and government agencies.
Even with that limitation, the evidence supports a practical conclusion: waiting weeks to fix an exposed system is increasingly risky when attackers can move in hours. The most useful response is not panic over an all-powerful AI hacker. It is to close the ordinary openings—old software, reusable passwords, excessive privileges and deceptive prompts—that faster automation can exploit.
Sources
- Microsoft: 2026 Digital Defense Report overview and findings
- Microsoft Security Blog: report context and recommendations
- Cybersecurity Dive: independent summary of access techniques and AI risks
Featured image: official Microsoft report-cover artwork.
