CISO Risk Intel Brief: Five-Day Exploit Windows, 72-Hour KEV Clocks, and the September Regulatory Squeeze
This executive intelligence briefing covers from the past week (19-26 August 2026) and the past month (approximately 27 July–26 August 2026). Exploit velocity has overtaken patch cadence as the binding constraint. VMware vCenter moved from Broadcom patch to mass exploitation in five days, and this week’s CISA KEV due dates are measured in 72 hours, not 30 days.