CrowdStrike found attackers began using the flaws within two days in 88% of the cases it observed.
Key Takeaways
- 88% of the attacks CrowdStrike observed involving publicly available instructions for exploiting software flaws began within 48 hours of their release.
- China-linked attackers exploited a critical web application flaw within 24 hours of its public disclosure.
- AI agents generated potential attacks at 2.5 times the rate of humans during the reporting period.
Cybersecurity company CrowdStrike released its 2026 Threat Hunting Report, finding attackers began exploiting software flaws within 48 hours of working attack instructions becoming public in 88% of the cases it observed during the first half of 2026.
Companies may have less than two days to patch a weakness after researchers publicly demonstrate how it can be attacked. CrowdStrike said the window between disclosure and widespread exploitation is now measured in hours rather than days.
AI is accelerating attacks using working attack instructions
Researchers sometimes publish code or technical instructions showing that a newly disclosed software flaw can be exploited. These demonstrations are known as proofs of concept.
CrowdStrike found that once instructions for attacking a software flaw appeared online, attacks followed within 48 hours in 88% of the cases it observed.
AI is speeding up the work that leads to those attacks. CrowdStrike said researchers and attackers can use AI to find software flaws and develop working attacks more quickly.
For example, a critical flaw affecting React and Next.js applications was publicly disclosed with patches on Dec. 3, 2025. Within 24 hours, working attack instructions were circulating online. Criminals, state-backed hackers, and unidentified attackers had begun using the flaw. During the first four days after the React and Next.js flaw was disclosed, CrowdStrike investigated more than 800 possible attacks affecting more than 80 victims.
In a separate case, researchers released instructions for exploiting a Linux flaw on April 29. CrowdStrike detected a Belarus-linked attacker using the instructions against a Ukrainian government organization just over 20 hours later.
CrowdStrike expects more capable AI systems to reduce the time between finding a software flaw and attacking it, leaving companies even less time to install security fixes.
AI agents generate more potential attacks
CrowdStrike also found AI agents generated potential attacks at 2.5 times the rate of humans during the 12 months ending June 30.
The company described the activity as “detection leads,” meaning possible attacks that required investigation.
The report did not disclose the underlying number of potential attacks or how many were confirmed as malicious.
CrowdStrike’s earlier 2026 Global Threat Report recorded an 89% increase in attacker activity involving AI during 2025. The latest report also documents attackers using generative AI to create malicious commands and software, stealing access to corporate AI models and exploiting weaknesses in AI server software.
CrowdStrike expects AI-assisted security research to continue shortening the time companies have to address newly disclosed software flaws.

