TL;DR: Frontier AI models are compressing the time between vulnerability discovery and exploitation, prompting organisations to rework vulnerability management cadences, according to Commvault. Scheduled disclosure rhythms help create predictability, but they do not remove the need for urgent out-of-cycle handling when a high-risk issue demands immediate action.
NHIMG editorial — what this means for NHI practitioners
Questions worth separating out
Q: How should security teams handle manual patching for actively exploited vulnerabilities?
A: Treat manual patching as a risk exposure window and compensate accordingly.
A: A software flaw becomes more dangerous when the impacted system can reach privileged accounts, tokens, or secrets stores, because attackers can convert one foothold into broader access.
Q: What signals show that a patch programme is too slow for current exploit timelines?
A: Warning signs include repeated exceptions, long triage queues, and critical assets that still wait for normal change windows after public disclosure.
Practitioner guidance
- Separate routine patches from active exploit response Create two paths in the vulnerability programme: a scheduled monthly release track and an emergency track for exploited or high-severity issues.
- Link every critical patch to identity and secrets review When a vulnerability affects a system that stores or reaches secrets, require immediate review of tokens, certificates, service accounts, and administrative sessions.
- Shorten approval chains for actively exploited issues Pre-authorise compensating controls, rollback steps, and temporary isolation actions so teams can act without waiting for a full change window.
What's in the full announcement
Commvault's full article covers the operational detail this post intentionally leaves for the source:
- The scheduled Patch Tuesday cadence and how Commvault plans to use it for future security advisories.
- The Security Advisories page, Trust Center, and Security Center resources that practitioners can monitor for updates and documentation.
- The stated process for urgent off-cycle vulnerabilities when disclosure cannot wait for the monthly schedule.
👉 Read Commvault's explanation of its monthly Patch Tuesday vulnerability disclosure cadence →
Patch tuesday disclosure rhythms: what security teams should expect?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Predictable patch cadence is only valuable when vulnerability governance and identity governance are joined. A monthly release rhythm helps normalise response, but the real risk sits in the overlap between exposed software and exposed identity material. If service accounts, API keys, or cached credentials remain reachable, the patch date becomes less important than the time attackers have to abuse access. Practitioner conclusion: teams should treat patch governance and identity containment as one operating model.
A few things that frame the scale:
- 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches, according to The 2025 State of NHIs and Secrets in Cybersecurity.
- 62% of all secrets are duplicated and stored in multiple locations, causing unnecessary redundancy and increasing the risk of accidental exposure, according to The 2025 State of NHIs and Secrets in Cybersecurity.
A question worth separating out:
Q: Who is accountable when exposure remains open after a vulnerability is disclosed?
A: Accountability should sit with the asset or service owner, but only if ownership records are current and tied to privileged access paths. In practice, that means IAM, infrastructure and security teams need a shared operating model for assigning remediation, approving exceptions and proving closure. Otherwise, gaps linger because no one can act decisively.
👉 Read our full editorial: Patch-tuesday vulnerability disclosure reflects faster exploit timelines