Frontier AI Forces Vulnerability Programs Into Overdrive

Vulnerability management has long been a pillar of cybersecurity, with teams maintaining a delicate balance between detecting risks and deploying patches. But the rise of frontier AI models such as Anthropic’s Mythos is upending the status quo. These models can rapidly spot zero-day flaws, chain together complex exploits, and adapt at near human-impossible speed, forcing security programs to ask: are we ready for this seismic shift? Many organizations aren’t.

New Prioritization Imperative: Beyond CVSS, EPSS & KEV

Traditional risk scoring systems—CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System), and CISA’s Known Exploited Vulnerabilities (KEV) list—have become baseline tools. Yet with frontier AI turning vulnerabilities into exploits in moments, simply relying on those metrics no longer suffices. Teams must better align vulnerability prioritization with what truly matters for their business.

This is where exposure management comes in. It extends vulnerability management to map an organization’s entire attack surface, including misconfigurations and network reachability. By adding business impact and exploitability into the mix, exposure management helps zero in on the vulnerabilities that pose the gravest risks—rather than getting lost in the sea of low-risk findings.

To support this, continuous monitoring, breach simulation, and automated penetration testing become essential. These not only validate existing vulnerabilities, they also spot weak spots that legacy programs may miss. The goal: build a faster, clearer, organization-level picture of where you’re exposed—and what needs fixing first.

Patch Management Speed Becomes Decisive

Patch management teams have traditionally waited for the monthly “Patch Tuesday,” then navigated rigorous testing and deployment windows. Frontier AI’s velocity changes that. The time between vulnerability discovery and exploit creation is shrinking—meaning patches must flow faster.

This calls for automating the patch lifecycle wherever possible, adopting ring-oriented rollout models, and continuously validating stability at each stage. Every delay exposes organizations to risk. But pushing patches faster risks upsetting uptime guarantees and operational expectations.

That tension puts security and operations teams in a challenging spot: they have to renegotiate what “availability” and “resilience” mean when threats evolve so quickly. That means tougher internal conversations—should more investment go into resilience? Should disaster recovery plans adapt? These issues need addressing now, not after a breach.

Moving From Reactive to Proactive Program Maturity

Some vulnerability programs have already been teetering under backlogs and siloed processes. CTEM (Continuous Threat Exposure Management) has been discussed for years, but few have fully moved to it. The acceleration introduced by frontier AI models makes program maturity less optional. It demands systemic change.

Upgrading your program means integrating vulnerability and patch management tightly, shifting toward exposure-centric risk, and pushing automation throughout. More than just patch issuance or vulnerability scanning, it’s a mindset overhaul—aligning with how attackers (and assistant AIs) now operate.

This isn’t theoretical: many organizations aren’t equipped to triage threats at AI speed or maintain the resilience needed after rapid, cascading patch rollouts. Security leaders need to start assessing their current state, define clearrisk problems, and implement policies that handle both detection and remediation in real time.

[Note: The author teaches two SANS LDR516 courses in late 2026, in the DC Metro area (Sept. 28–Oct. 2) and Dallas (Dec. 7–11), focused on evolving vulnerability programs.]

The rise of frontier AI is more than just another challenge—it’s an inflection point. Organizations that adapt will develop vulnerability and patch programs built for speed, clarity, and coordination. Those that don’t face ever-widening gaps between detection and exploitation—but also between policy and risk. The reckoning isn’t coming. It’s already started.