Microsoft published on its security blog in April 2026 what security operators already knew in practice: AI has compressed the window between vulnerability discovery and exploitation. The difference is that now Microsoft's weight is behind the confirmation, with data and product announcements. At Tech86, we saw this compression happening before the official declaration — and the impact is structural, not circumstantial.
What Microsoft confirmed
Per Microsoft, AI models can autonomously discover vulnerabilities in software, chain multiple lower-severity issues into working end-to-end exploits, and produce working proof-of-concept code. The window between discovery and exploitation has been significantly compressed.
This is not theory. Microsoft used its own system — MDASH, which orchestrates over 100 specialized AI agents — to find 16 vulnerabilities in the Windows networking and authentication stack, including 4 critical RCEs in components such as the Windows kernel TCP/IP stack and the IKEv2 service. MDASH achieved an 88.45% success rate on the public CyberGym benchmark with 1,507 real vulnerabilities, per Microsoft. In less than three weeks, it jumped to 96.55%.
The strongest statement in the post, signed by Aleš Holeček, Corporate Vice President and Chief Architect of Microsoft Security: for customers who deploy Microsoft products on their own infrastructure, whether on-premises or self-hosted, staying current on all security updates "is now not only the best practice; it is a fundamental requirement for staying secure against AI exposure." Best practice was optional. Fundamental requirement is mandatory.
The structural imbalance
Previously, an attacker needed expertise, time, and specialized tools. Now, per Microsoft, an AI model can do the work of a pentester in hours, not weeks. And it can chain vulnerabilities that humans would not connect. One low-severity flaw alone is noise. Three chained together are an exploit.
The impact on the vulnerability lifecycle is asymmetric. In discovery, AI finds faster, across more codebases, with greater precision. In validation, AI can test whether a vulnerability is exploitable automatically. In exploitation, AI can generate functional PoC code and chain low-severity issues. In remediation, there is the gap. Remediation is still human. And human is slow.
Attackers with AI discover and exploit in hours. Defenders without AI apply patches in days or weeks. Attack speed has surpassed defense speed. And Microsoft is saying this openly.
Responsibility splits along the deployment model
Per Microsoft, for PaaS and SaaS customers, mitigations are applied automatically. The platform absorbs the problem. For those running on-premise or self-hosted infrastructure, the responsibility is entirely yours.
Security updates are no longer something you do when convenient. They are something you do before the next AI scan finds what you have not patched. Per its blog, Microsoft is using AI to proactively scan select open-source codebases. Identified issues are addressed through coordinated vulnerability disclosure. If Microsoft is doing this with open-source codebases, attackers are doing it with private codebases — without disclosure.
At Build 2026, Microsoft announced the expanded preview of MDASH with integration into Microsoft Defender. Per Microsoft, the system combines AI analysis with telemetry from over 100 trillion security signals per day to identify vulnerabilities that can be exploited in practice. The solution was expected to be available in preview in June 2026.
The math changed
AI is not just accelerating attacks. It is changing the math of security. Before: high attack cost, long exploitation time, significant expertise barrier. Now: low attack cost, short exploitation time, expertise democratized by AI.
The Google Threat Intelligence Group already identified, per the group itself, the first zero-day exploit written by criminals using AI — a two-factor authentication bypass in an open-source web administration tool. Palisade Research, per the organization itself, documented an AI agent that self-replicated via hacking in 2h41m, making 4 hops across 4 countries. The self-replication success rate jumped from 6% to 81% in 12 months, per Palisade Research. These are not Microsoft's data points — they are from the broader security ecosystem confirming the same trend, per the Google Threat Intelligence Group and Palisade Research, respectively.
Organizations that do not automate defense at the same speed are playing a game they have already lost. The question is not whether AI will find the vulnerability you left unpatched. It is when.
Conclusion
Microsoft's declaration is a milestone because it comes from the company with the largest installed software base in the world. When Microsoft says staying current on security updates is a fundamental requirement, not a best practice, it is because the tolerance window has closed. At Tech86, we automate defense at the speed AI demands — with EDR, real-time monitoring, and autonomous response. If you do not know how long it takes between vulnerability discovery and patch deployment in your infrastructure, it is time to find out.