Jessica Entwistle
August 4 2026
Infosecurity Magazine reports that Chinese state-linked threat actors exploited the critical React2Shell vulnerability within 24 hours of its public disclosure, and that 88% of exploited vulnerabilities in the first half of 2026 were compromised within 48 hours of disclosure. The findings, based on threat intelligence analysis, show that the window between vulnerability disclosure and active exploitation has collapsed to the point where many organisations no longer have a realistic opportunity to patch before attacks begin. The React2Shell vulnerability, which affects widely deployed web application frameworks, was weaponised and used in active campaigns before most organisations had completed their initial risk assessments. This trend reflects the increasing speed and automation with which threat actors can identify, weaponise and deploy exploits at scale, particularly for vulnerabilities affecting internet-facing systems and widely used software platforms.
This represents a fundamental shift in how vulnerability management must operate. The traditional model of assessing, testing and deploying patches over days or weeks is no longer aligned to the speed at which threat actors are moving. Organisations that rely on manual patch cycles, change advisory boards or lengthy testing processes are now operating with an assumption of safety that no longer reflects reality. This is particularly acute for internet-facing systems, web applications and infrastructure that can be identified and targeted remotely. The operational challenge is not just technical but organisational: it requires clarity about who can authorise emergency patching, how quickly security teams can deploy updates, whether testing can be accelerated or bypassed for critical vulnerabilities, and whether monitoring and detection capabilities are sufficient to identify exploitation attempts during the window before patches are applied. For many organisations, this will require a fundamental review of change management processes, patch deployment capabilities and the balance between stability and security risk.
Organisations should assess whether their vulnerability management process is designed for the current threat environment. Consider whether you have the capability to deploy emergency patches within hours rather than days, whether internet-facing systems are prioritised for rapid response, and whether detection and monitoring controls are in place to identify exploitation during the patching window. Review whether change management processes allow for emergency patching without lengthy approval cycles, and whether security teams have the authority and capability to act quickly when critical vulnerabilities are disclosed. Consider whether vulnerability scanning, asset management and patch deployment tools provide sufficient visibility and control to respond at the required speed, and whether there is clear ownership and accountability for rapid response to critical vulnerabilities. Organisations should also review whether they have sufficient threat intelligence to understand which vulnerabilities are being actively exploited and whether monitoring capabilities can detect exploitation attempts before patches are deployed.
Source: Infosecurity Magazine