AI Is Outpacing Traditional Cybersecurity Patching
By Diego Valverde | Journalist & Industry Analyst -
Tue, 07/14/2026 - 09:00
AI is accelerating the discovery and exploitation of software vulnerabilities, shrinking the time available for organizations to respond. Fortinet argues that traditional patch management can no longer keep pace and says organizations should adopt virtual patching, continuous monitoring and zero trust architectures to reduce exposure.
AI is reshaping cybersecurity in ways that extend beyond defense. As advanced AI models become capable of identifying software flaws at unprecedented speed and scale, enterprises are facing a growing operational challenge: applying security patches fast enough to prevent exploitation.
According to Gonzalo Garcia, Vice President of Sales for Fortinet South America, AI-driven vulnerability discovery is set to overwhelm conventional patch management processes, forcing organizations to rethink how they mitigate cyber risk.
Rather than attempting to accelerate software updates indefinitely, Garcia says companies should separate immediate risk mitigation from the patching process itself by adopting virtual patching strategies.
"The question for 2026 is no longer whether organizations will be able to patch vulnerabilities on time," says Garcia. "That will not be possible. The real question is whether their infrastructure can withstand weeks of exposure while waiting for the next maintenance window."
The argument reflects a broader shift in cybersecurity as generative AI expands the capabilities available to both defenders and attackers.
Why Traditional Patching Can No Longer Keep Up
For decades, discovering critical software vulnerabilities required weeks or months of work by experienced security researchers. Garcia says new AI models can now analyze millions of lines of production code and uncover logical flaws that traditional techniques often miss, dramatically increasing the number of vulnerabilities organizations will need to address.
At the same time, attackers are moving faster. Fortinet's FortiGuard Labs reports that the average time between the public disclosure of a critical vulnerability and its active exploitation has fallen to 24–48 hours, compared to 4.76 days in 2023. As AI accelerates exploit development, traditional manual patch management cycles struggle to keep pace.
The operational gap is widening because enterprise IT teams cannot deploy patches at the same speed. Garcia cites industry research showing that organizations require an average of 16 days to patch a critical vulnerability after it has been identified.
Meanwhile, 74% of organizations report they cannot apply patches quickly enough because of staffing shortages, while 60% of organizations that experienced data breaches say attackers exploited vulnerabilities for which patches were already available but had not yet been deployed.
Garcia argues that the primary bottleneck is no longer patch availability but maintenance windows. Every critical update typically requires testing, regression analysis, business approvals and planned downtime before deployment.
Virtual Patching and Zero Trust Become Strategic Defenses
Fortinet proposes virtual patching as an alternative layer of protection. Instead of modifying vulnerable code immediately, virtual patching deploys security controls across the network, applications or endpoints that prevent attackers from exploiting known vulnerabilities while organizations prepare permanent software updates. This approach allows security teams to reduce exposure within hours while scheduling traditional patch deployment according to operational requirements.
The company also argues that organizations should prioritize vulnerabilities based on active exploitation rather than attempting to remediate every published software flaw simultaneously.
According to FortiGuard Labs, only 0.7% of Common Vulnerabilities and Exposures (CVEs) observed on endpoints are under active attack at any given time, making continuous exposure management and monitoring more effective than treating every vulnerability as equally urgent.
Garcia says effective virtual patching depends on integrating multiple security layers, including intrusion prevention systems, web application firewalls and endpoint exploit prevention into a unified platform that shares intelligence and coordinates mitigation. According to Fortinet, consolidating these capabilities reduces the time between vulnerability disclosure and protection compared with managing separate security products independently.
The company also positions zero trust as a complementary strategy. Garcia says technologies such as Zero Trust Network Access (ZTNA), Secure Access Service Edge (SASE) and microsegmentation reduce attack surfaces and limit lateral movement, minimizing the business impact of systems that remain temporarily unpatched.
By verifying identity, device posture and context before granting access, organizations can reduce reliance on immediate software updates as their only line of defense.
For enterprise security leaders, the growing influence of AI on vulnerability discovery introduces a strategic shift in cyber risk management. Rather than measuring success by the speed of patch deployment alone, organizations may increasingly evaluate how quickly they can mitigate exploitable threats while balancing operational continuity.
Fortinet argues that combining virtual patching, continuous monitoring and zero trust architectures will become essential as AI continues to compress the time between vulnerability disclosure and active exploitation.






