A Tornado Warning Is Only Useful If You Know Where it will Hit.

J.P. Morgan's Patchmageddon report is right that the vulnerability warning system works and the lead time is collapsing toward zero. The gap it leaves is relevance. A warning that cannot tell you which of your assets sits in the storm's path is a national bulletin, not a warning.

Share
Line chart: median time from disclosure to first exploitation collapsing from ~30 days in 2020 to near zero in 2026, with a callout that a patch already existed in about 60% of breaches
Time-to-exploit and patch-availability figures from J.P. Morgan's Eye on the Market: Patchmageddon, July 2026.

J.P. Morgan's July Eye on the Market opens with tornado warnings. The US Weather Bureau began issuing them in the late 1940s, and deaths per million fell by roughly 90 percent, even though the average lead time is only fifteen minutes. The argument is that disclosed vulnerabilities and their patches are the cyber equivalent of that warning system, and that the lead time is now collapsing toward zero.

The analogy is a good one. It also has a large gap.

A tornado warning works because it is geographic. It tells you that this storm is headed for your county, tonight. Strip the geography out and you are left with a national bulletin announcing that somewhere in America, today, there will be a tornado. Technically accurate. Operationally useless. Nobody moves to a basement on that.

That is close to the state of most vulnerability and threat intelligence today. The warning system works. The targeting does not.

Three numbers

The report contains a lot of alarming arithmetic. Three numbers matter more than the rest.

48,185 vulnerabilities were disclosed in 2025, a record, and the patch rate is nowhere close. The volume problem. In one May 2026 snapshot the report cites, of 530 high and critical vulnerabilities reported to maintainers, only 75 had been patched, roughly one in seven.

Median time from disclosure to first exploitation has collapsed from about 30 days in 2020 to effectively zero in 2026. The speed problem. Exploitation now routinely lands on or before the day a vulnerability is made public.

In roughly 60 percent of breaches, a patch already existed at the time of compromise. This is the one that should change how defenders think, and it is the one that gets the least attention.

The first two numbers describe an environment. The third describes a decision failure. The warning had been issued. The fix had shipped. The organization either did not act, or acted on something else first. Faster discovery does not touch that number at all.

The bottleneck was never discovery

The report lists why patching stalls, and the ranking is instructive:

  1. Inability to take critical systems down.
  2. Human error.
  3. Lack of resources to keep up with the volume.
  4. Inability to track whether anything was actually remediated.
  5. Inability to prioritize what needs patching.

None of those is a knowledge problem. They are capacity and sequencing problems. When 48,000 disclosures arrive in a year and the maintenance window is four hours on a Saturday, the constraint is not what you know. It is what you choose to do with the window you have.

Which makes prioritization, the fifth item, the crux. And ranking by severity score ranks against the world, not against your network. A critical rating on a component you run in an isolated lab and a medium rating on a component sitting on the path between an internet-facing service and your payment infrastructure are not the same finding, no matter what the score says.

Relevance is a property of the environment, not of the vulnerability. I have made that case at length in "Relevant to Your Industry" Is a Threat Intel Myth: the signal is what you run and what is reachable, not a severity number or a sector tag.

Two harder implications

Collection is no longer where the advantage lives. The report notes that 95 percent of the vulnerability disclosures produced by the newest frontier models had no public advisory at the time of the research snapshot. They were not visible in CVE feeds, national vulnerability databases, or repository advisory databases. Feed breadth was a defensible position when the feeds defined the threat universe. They are becoming a lagging subset of it.

Detection is the control of last resort, and it should be treated as a first-class output. If exploitation windows compress to minutes, patching cannot be the primary control, because deployment is bounded by change management rather than by intent. It gets worse in operational technology, where only a little more than half of all industrial networks are even patchable, which leaves close to half with no patch path at all. For those assets there is no race to lose. There is only the question of whether you would see the activity if it started.

Which leads to the last point. The report is refreshingly honest about a limitation of AI-driven vulnerability discovery: you can check for false positives, but you cannot check for false negatives, because the universe of discoverable vulnerabilities is unknown. The same logic applies to defensive coverage. A vendor telling you that a technique is covered is an assertion, not a fact. Running the technique and observing whether anything fires is evidence. In a world where the warning arrives at the same moment as the attack, the difference between those two things is most of your risk.

What to ask

The useful question for the next twelve months is not which feed to buy or how much faster the team can patch. It is narrower than that:

For a threat disclosed this morning, can you say which of your assets are actually reachable, how the attack would traverse your environment, whether your existing controls would catch it, and what to deploy in the meantime if the patch will not land in time?

If the answer to that comes back as a severity score and a link, you have a national bulletin. You do not have a warning.


Source: J.P. Morgan Private Bank, Eye on the Market: Patchmageddon, Michael Cembalest, July 2026. The 48,185 disclosure count for 2025 is corroborated by industry CVE trackers; the patch-availability and remediation-gap findings are consistent with the 2026 Verizon DBIR. Figures reflect the report as published; verify any single-source projection before quoting it.