Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
blog

Patchmageddon Is Here. What Are Your Vendors Doing About It?

Published

Aug 26, 2026

Introduction

JPMorgan Asset & Wealth Management published a 28-page report on AI-accelerated vulnerability discovery, called Patchmageddon. It covers attacker time-to-exploit, the open source patch gap, unpatchable OT infrastructure, even federal policy options. What it doesn't cover is whether your vendors are doing any of this.

Why Vendor Vulnerability Management Matters

A vendor's unpatched vulnerability doesn't stay a vendor problem. In our 2026 Third-Party Breach Report, the average vendor breach cascaded into 5.28 other organizations, up from 2.56 the year before. The blast radius of a single unpatched flaw is already doubling year over year, and that's before AI-accelerated discovery has fully played out. Securing your own environment against Mythos-class vulnerability discovery is necessary. It just isn't the whole job.

What JPMorgan's Data Shows

The headline finding: organizational patch times are rising at the exact moment attacker time-to-exploit is falling toward zero. JPMorgan cites Sidero Labs data showing average remediation time climbing toward 95 days by 2026, while the average time from disclosure to exploitation keeps shrinking toward, and now past, zero. Attackers are moving faster. Defenders are moving slower. That's the same structural gap we pointed to when Project Glasswing first landed, just with new numbers behind it now.

The report also surfaces a number worth sitting with. Of the vulnerabilities Mythos-class models were finding in the wild, 95% carried no public CVE or advisory at the time of discovery. That means they were invisible to CVE feeds, National Vulnerability Database lookups, and GitHub advisory databases. If your TPCRM program still runs on checking the CVE feed, that's exactly the gap our 2026 Supply Chain Vulnerability Report was built to close, and this report shows why the problem is only getting worse.

And JPMorgan cites the same open source patch gap we flagged back in June, pulling from Anthropic's Glasswing dashboard: over 23,000 candidate vulnerabilities surfaced, and only 97 patched upstream, meaning fixed at the source, in the original open-source project itself, rather than downstream in any of the vendor products that depend on it. Discovery is scaling. Remediation isn't. And that's before the fix even has to propagate down to everyone using it.

The Checklist Only Covers Half the Ecosystem

JPMorgan's Global Technology Leadership Team lays out ten concrete actions for AI-ready cyber resilience. Every single one is written for your own environment.

Run current software versions. Maintain a continuous inventory of your hardware, software, and cloud assets. Build a vulnerability management program. Filter your outbound traffic. Remove standing privileges. These are good, specific, actionable recommendations. They're also entirely first-party.

Walk through a few of them with a third-party lens and the gap shows up fast.

  • Run the latest software versions. You can verify this for your own stack. You cannot verify it for a vendor's stack unless you have external visibility into what they're actually running, not what their last security questionnaire claimed.
  • Maintain a comprehensive, continuously updated inventory of all hardware, software, and cloud assets. That's your inventory. What's your inventory of your critical vendors' dependencies? For most TPCRM programs, the honest answer is that there isn't one.
  • Move applications off third-party dependencies where you can't identify the steward. This is the one place the Patchmaggedon report brushes against our world, and it stops at the sentence. The moment a dependency crosses a company boundary, identifying the steward becomes a vendor concentration question, not an internal IT task.
  • Build and operate a robust vulnerability management program. Whose program covers the open source library sitting inside three of your critical vendors' products right now? Not yours. Not unless you're watching it directly.

None of this is a knock on JPMorgan's report. Theirs is a checklist for securing your own house, and it's a good one. It was never trying to answer the vendor question. That's exactly why it's worth naming the gap.

Self-Attestation Was Never Visibility

Here's the uncomfortable math JPMorgan's own data supports: even when a vendor wants to patch fast, the infrastructure underneath them often can't move that quickly.

Most open source software is maintained by a small number of volunteers, sometimes just one person, patching in their spare time. When Mythos found a vulnerability in that kind of dependency, JPMorgan's own numbers show it took an average of two weeks to patch, slower than most companies patch flaws in their own systems. Multiply that across every vendor running that same library, and a single unpatched dependency becomes a simultaneous exposure across your entire ecosystem. That's concentration risk in practice, not theory.

So when a vendor questionnaire comes back marked "patched," what does that actually tell you? It tells you what the vendor believes, or what they're willing to disclose. It doesn't tell you what's still running in production, and it doesn't tell you whether the fix landed before or after the exploitation window closed. As we've said before, the Vulnerability Deluge isn't a future scenario. It's already the water we're swimming in.

What Continuous Third-Party Visibility Actually Looks Like

Securing your own house and knowing your vendors' exposure are two different jobs, and only one of them shows up in most cyber resilience checklists.

That second job is what FocusTags® exist to do. Instead of waiting for a vendor to tell you whether they're affected by a given flaw, FocusTags® connect a global vulnerability event directly to the specific vendors in your ecosystem running the affected software, often before that flaw ever gets a public advisory.

Vulnerability Intelligence Briefs pinpoint exactly who's running the exposed version. The Bridge™ turns that intelligence into structured vendor outreach with evidence attached, not another generic questionnaire asking a vendor to grade its own homework.

If you want the fuller picture of what Mythos-class AI discovery means for a TPCRM program, watch the full replay of our Mythos briefing webinar. It walks through exactly how these detection capabilities change vendor risk prioritization for teams building this into their 2026 planning.

JPMorgan's checklist tells you how to defend your perimeter. Your vendors have their own perimeters, running their own open source dependencies, on their own patch timelines you can't see from a questionnaire. Closing that gap continuously, not once a year, is the work.

See how Black Kite maps vendor-level exposure to AI-accelerated vulnerabilities in real time. Book a demo.