Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Cloud Security 2 min read27 May 2026

CERT-In Mandates 12-Hour Patching for Exposed Systems

India's CERT-In now mandates 12-hour patching for critical internet-facing vulnerabilities as AI-driven attacks shrink the exploit window to hours.

Y

Yossi Pinhasov

YouCC Technologies

CERT-In Mandates 12-Hour Patching for Internet-Facing Systems

India's CERT-In has issued a new directive: critical vulnerabilities in internet-facing systems must be remediated within just 12 hours. The 12-hour patching mandate reflects a hard reality of modern threat speed, where attackers now move from disclosure to exploitation in a fraction of the time defenders once had.

What happened

The driver behind the directive is AI. Attackers now use AI to find, analyze, and exploit weaknesses at a staggering pace, sometimes within hours of public disclosure. That collapse in the exploit window is what pushed CERT-In to set a 12-hour remediation requirement for critical, internet-exposed vulnerabilities.

Why it matters

For organizations, the implications are blunt:

  • Patching once a month is no longer enough.
  • Periodic vulnerability scanning is no longer enough.

When the gap between disclosure and active exploitation shrinks to hours, any cadence measured in weeks leaves a wide-open window. The world is moving from "Patch Management" to a "Race Against Time," and the controls that worked under a monthly rhythm cannot keep up with AI-accelerated attackers probing exposed assets continuously.

What to do

Replace periodic, calendar-based remediation with a continuous model:

  • Continuous Exposure Management rather than point-in-time scans.
  • Prioritization by KEV and internet-facing status, so the most dangerous, most reachable issues are fixed first.
  • Zero Trust to limit what an exploited asset can reach.
  • Continuous monitoring and rapid response to detect and act inside the shrinking exploit window.

For the full report, see The Hacker News coverage.


Shared from the CSC - Cloud Security Community community, by Yossi Pinhasov.

Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community