Eighteen years
The Cybersecurity and Infrastructure Security Agency adds vulnerabilities to its Known Exploited Vulnerabilities catalog only with forensic evidence of in-the-wild exploitation. The catalog is the federal government's authoritative list of vulnerabilities being actively attacked. The Binding Operational Directive 22-01 imposes remediation deadlines on Federal Civilian Executive Branch agencies for every entry. CISA additions are operational signals.
Yesterday, Wednesday May 20, 2026, CISA added seven vulnerabilities to the KEV catalog.
Five of seven are from 2008, 2009, or 2010 — between sixteen and eighteen years old.
CVE-2008-4250 — Microsoft Windows Buffer Overflow Vulnerability. Original disclosure: October 2008. Eighteen years old.
CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability. Original disclosure: 2009. Seventeen years old.
CVE-2009-3459 — Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability. Original disclosure: 2009. Seventeen years old.
CVE-2010-0249 — Microsoft Internet Explorer Use-After-Free Vulnerability. Original disclosure: 2010. Sixteen years old.
CVE-2010-0806 — Microsoft Internet Explorer Use-After-Free Vulnerability. Original disclosure: 2010. Sixteen years old.
CVE-2026-41091 — Microsoft Defender Elevation of Privilege Vulnerability. Disclosed 2026.
CVE-2026-45498 — Microsoft Defender Denial of Service Vulnerability. Disclosed 2026.
The five legacy CVEs span Windows, DirectX, Adobe Acrobat, and Internet Explorer. The vendor patches for all five were published years ago — eighteen years ago for the oldest. They are not new vulnerabilities. CISA has forensic evidence that they are being actively exploited today against systems that never deployed the patches.
The interpretation is structural. The vendor patching pipeline has produced a long tail of unpatched legacy systems large enough that exploiting an 18-year-old Windows Buffer Overflow remains a viable attack strategy in 2026. The attacker has discovered which systems remain vulnerable, automated against them at scale, and now CISA must place the 2008 CVE on the federal active-exploitation list.
The patching pipeline has an eighteen-year tail.
Five-of-seven legacy
The 5-of-7 distribution is not the normal pattern of CISA KEV additions. The catalog typically grows with recent vulnerabilities — current-quarter or current-year disclosures that have been forensically tied to in-the-wild exploitation campaigns. Adding five vulnerabilities from 2008-2010 in a single day signals that CISA's threat intelligence picture has shifted.
Three possible interpretations:
One, a state-aligned threat actor or commercial spyware vendor has rediscovered the legacy CVEs and is using them at scale against systems that never patched. The legacy attack inventory has been refreshed.
Two, a criminal extortion group has automated against the legacy CVEs in order to compromise the unpatched-system population — entities that have not maintained their software for fifteen-plus years.
Three, CISA's forensic visibility has expanded — the agency has improved the telemetry that detects exploitation of legacy CVEs in federal networks, and the May 20 additions reflect what was already happening rather than a new attack campaign.
Whichever interpretation holds, the operational implication is the same. Federal IT agencies — and by extension every organization tracking the CISA KEV catalog as part of vulnerability-management compliance — must now remediate vulnerabilities that received vendor patches before some of today's IT employees were old enough to drive.
The Verizon 2026 Data Breach Investigations Report, published on Tuesday May 19 — two days before the CISA event — found that the median time-to-patch a critical vulnerability rose from 32 days in 2024 to 43 days in 2025. A 34 percent increase. The DBIR's measure is the median. The CISA KEV May 20 additions are the tail: the 99th-percentile measure of how slow the patching pipeline runs at scale. Eighteen years.
Defender itself
The two non-legacy CVEs added to KEV yesterday are both Microsoft Defender flaws: CVE-2026-41091 (Elevation of Privilege) and CVE-2026-45498 (Denial of Service).
Microsoft Defender is Microsoft's enterprise endpoint protection platform. It is what Microsoft sells as the security solution. It is the agent that detects malware, blocks lateral movement, and reports incidents to security operations centers. When Microsoft announced Microsoft Defender for AI Agents on May 12, the company positioned Defender as the security infrastructure for the agentic-AI era — with webhook-based real-time interception, asset context mapping per agent, and runtime protection. Microsoft's multi-model agentic scanning harness (MDASH), launched the same week, orchestrates more than 100 specialized AI agents to score 88.45 percent on the CyberGym benchmark and find 16 new Windows vulnerabilities.
Microsoft Defender — the tool that detects vulnerabilities — now has two of its own CVEs in the federal active-exploitation catalog.
The recursive irony is structural. When the security tool is itself a vulnerability surface, the architecture relies on the security tool's vendor to patch its own tool. The patching pipeline that the DBIR found is running at 43-day median time-to-patch is the same pipeline that must ship Defender fixes. Microsoft will ship them. They will be installed on most systems. They will not be installed on some.
The eighteen-year tail applies recursively. Some Defender installations from 2026 will, in 2044, still be running unpatched against CVE-2026-41091.
The DBIR backdrop
The Verizon Data Breach Investigations Report is the cybersecurity industry's longest-running annual benchmark dataset. The 2026 edition, published Tuesday May 19, analyzed 22,000-plus confirmed breaches and 31,000-plus security incidents across 145 countries, drawing on the reporting window November 1, 2024 through October 31, 2025.
The headline finding: for the first time in nineteen years of DBIR publication, exploiting vulnerabilities has overtaken stolen credentials as the number one breach entry point. 31 percent of all breaches in 2025 began with vulnerability exploitation. Stolen credentials — the previous leader for nineteen consecutive years — drop to number two.
The remediation finding: only 26 percent of CISA Known Exploited Vulnerabilities-catalog critical items were fully remediated by 2025 — down from 38 percent in 2024. A twelve-point drop in a single year. 58 percent partially remediated; 16 percent unaddressed. The median time-to-patch a critical vulnerability rose to 43 days — up thirty-four percent from 32 days in 2024.
The supply chain finding: third-party supply chain breaches jumped +60 percent year-over-year. They now account for 48 percent of all breaches.
The AI finding: AI is being leveraged by threat actors to shrink the time between disclosure and operational weaponization from months to hours. Employee AI tool use surged from 15 percent to 45 percent in one year. AI bot traffic is growing 21 percent month-over-month.
The CISA KEV May 20 event is the operational demonstration of all three DBIR findings. Vulnerability exploitation is the new #1 entry — and the catalog must add 18-year-old CVEs because the patching pipeline cannot keep up. The patching crisis runs from today (Exchange OWA, still no patch on day 7 of active exploitation) to 2008 (still being exploited eighteen years after disclosure). The supply chain crisis runs through every vendor that ships an unpatched dependency.
Twenty months undetected
The pattern that produces the eighteen-year tail is visible in operational form. On May 12, 2026 — nine days ago — the UK Information Commissioner's Office fined South Staffordshire Plc and parent South Staffordshire Water Plc a total of £963,900 (approximately $1.3 million) for the 2022 Cl0p ransomware breach that compromised 633,887 customers and employees of the critical-infrastructure water utility.
The ICO's published findings on what enabled the breach are a portrait of patching-pipeline failure at scale:
- The initial access vector was a phishing email; the recipient opened an attachment which installed malicious software
- The malicious software remained undetected for twenty months in the company's IT environment
- Only 5 percent of the IT environment was being monitored
- Obsolete software remained in operational use, including Windows Server 2003 — an operating system Microsoft last supported in 2015, eleven years ago
- Vulnerability management was inadequate, including unpatched critical systems
- The attacker escalated to administrative privileges with limited controls
- Personal information for 633,887 people was published on the dark web in August 2022
Windows Server 2003 was running operational critical-infrastructure systems in 2022. The Server 2003 EOL was July 14, 2015. The patches the operating system would need to defend against CVE-2008-4250 — yesterday's KEV addition — were available in 2008. The system was twenty years behind the patching pipeline at time of compromise.
This is what produces the eighteen-year tail.
The fine arrives four years after the breach. The pattern persists across countless critical-infrastructure operators worldwide that run their own unmaintained legacy stacks, against the regulator clock that catches up years later, against the attacker clock that finds them today.
Day seven of Exchange
While the eighteen-year tail is the legacy end of the patching crisis, the current end of the same crisis is operational this week.
Microsoft Exchange Server CVE-2026-42897 — a critical Outlook Web Access spoofing flaw rooted in cross-site scripting, CVSS 8.1 — was disclosed by Microsoft on May 14. The disclosure included a statement that the vulnerability was already being actively exploited in the wild on day one. CISA added it to the Known Exploited Vulnerabilities catalog the next day, May 15, with a Federal Civilian Executive Branch remediation deadline of May 29.
Today is day 7 of active exploitation. The remediation deadline is 8 days away.
There is still no permanent patch. Microsoft has released an automatic mitigation that applies only to customers with the Exchange EM Service enabled. Customers without EM Service must apply manual mitigation steps. Federal IT operations must comply with the May 29 FCEB deadline using mitigation rather than patching.
The pattern is the same as the Palo Alto PAN-OS CVE-2026-0300 case from May 9-13: the CISA Binding Operational Directive 22-01 deadline preceded the vendor patch. Federal civilian agencies had to mitigate, not patch. The vendor patch cycle is structurally trailing the regulator cycle and the attack cadence.
The Verizon DBIR finding that AI has shrunk exploit-time-to-weaponize from months to hours applies here. Microsoft published the vulnerability disclosure with active-exploitation confirmation on the same day. There was no "patch first" window. The attacker is operating on a tighter clock than the defender.
The Anodot pattern
The third Verizon DBIR finding — supply chain breaches up 60 percent year-over-year, now 48 percent of all breaches — is being demonstrated through a single SaaS analytics platform's compromised authentication tokens.
In April 2026, the ShinyHunters extortion group exploited compromised Anodot analytics platform authentication tokens to access cloud data belonging to multiple downstream customers via stolen Anodot tokens that granted BigQuery access. Two of those downstream breaches landed in May:
Zara — 197,400 email addresses exposed. Inditex, Zara's parent company, disclosed in April 2026 that an unauthorized actor had accessed databases hosted by a "former technology provider." Have I Been Pwned confirmed 197,400 unique email addresses alongside product SKUs, order IDs, and the market identifier for support tickets. ShinyHunters subsequently listed Zara on its dark-web leak portal with an April 21 deadline for Inditex to make contact, then leaked a 140 GB archive when ransom negotiations failed.
Vimeo — 119,000 users. On May 5, 2026, Vimeo confirmed that hackers stole personal information from approximately 119,000 of its users in April via the same Anodot integration. The attacker gained access via that integration rather than breaking into Vimeo directly. ShinyHunters released a 106 GB archive when ransom negotiations collapsed.
The single Anodot compromise produced downstream breaches at multiple major customers. This is the supply chain pattern: targeting the SaaS provider yields lateral access to every downstream tenant. The DBIR finding that supply chain breaches now account for 48 percent of all breaches is the macro view; the Anodot incident is one operational micro-demonstration.
The node-ipc supply chain hijack of May 14-15 — 10 million weekly downloads compromised via an expired-domain account hijack on the maintainer's recovery email — is another. The Grafana / Coinbase Cartel pull_request_target GitHub Actions misconfiguration exploitation of May 17-18 is another. The NYC Health + Hospitals 1.8 million-person biometric breach (May 18 disclosure) via an unnamed third-party vendor is another.
Every one of these is the same DBIR finding visible in operational form.
Twenty-four hours to audit close
While the centralized vendor patching pipeline cannot keep up with the AI-accelerated exploit pipeline (the DBIR finding) and cannot remediate vulnerabilities published eighteen years ago (the CISA KEV finding), the open-source community's audit-driven cryptographic upgrade pipeline ratifies a major upgrade tomorrow.
The Monero FCMP++ Trail of Bits audit is in day 11 of its 11-day window. The audit closes May 22 — twenty-four hours from now.
FCMP++ replaces ring signatures with full-chain membership proofs. The anonymity set expands from 16 decoys per transaction to the entire UTXO set — more than 150 million transaction outputs. A clean audit clears the path for the consensus upgrade and eliminates the last significant technical objection to Monero's protocol-level privacy claims.
The structural test: can protocol-level cryptographic upgrades be ratified through audit-driven open-source community governance with rigor comparable to the centralized-vendor patching model, but without the centralized-vendor patching pipeline's 43-day median, 26 percent remediation, and 18-year tail?
The answer comes tomorrow.
Bitcoin BIP324 v2 (default-on encrypted P2P since Core 27.0) and BIP352 silent payments (in Core 28.0+, with BIP376 PSBTv2 tweak data and BIP392 descriptor format added in 2026) operate on the same audit-driven open-source governance. Zcash Crosslink Milestone 4 (PoW + BFT finality integrated; Vitalik Buterin's second donation to Shielded Labs supported the upgrade on February 6) operates on the same. The audit-driven cryptographic upgrade pipeline is structurally distinct from the centralized vendor patching pipeline that the DBIR found is failing.
What was running
The federal patching crisis and the eighteen-year tail do not pause the global recipient-country layer.
Iran — day 83. Iran's internet blackout enters day 83 today. Approximately 1,992 hours total. The longest internet shutdown on record. Economic cost approximately $250 million per day in direct losses, per Mahdi Ghodsi of the Vienna Institute (wiiw). Cumulative loss: NetBlocks placed it above $1.8 billion at day 48, the last published figure. Online sales fell 80 percent. The Tehran Stock Exchange overall index lost 450,000 points across a four-day window. The Internet Pro IRGC/MCI white-SIM caste tier remains in operational production with three-to-four-hour queue times at SIM-conversion offices in Tehran.
Russia — Telegram block + MAX continue. Russia blocked Telegram on March 17, 2026. Ninety-five percent of Telegram connections fail without a VPN. Telegram's April update disguising traffic as normal browser traffic restored access within hours. The Kremlin continues to push MAX, its "sovereign" state-controlled messaging app, which has 107 million registered users but limited actual usage due to surveillance features. Turkey's BiP, South Korea's KakaoTalk, and China's WeChat saw +60 percent user growth in Russia in March. The April 15 ISP VPN-detection law remains operational at Yandex, VK, Sberbank, Gosuslugi, Ozon, Wildberries, Aviasales, and Russian Railways. The May 1 mobile VPN surcharge was delayed. Per Meduza, 22 of Russia's 30 most popular Android apps now monitor VPN status at the application layer.
China — Great Unplug continues. The April physical disconnection of thousands of proxy service servers continues to constrain Chinese users' circumvention options. Only TLS-based obfuscation reliably survives.
Niger — day 13 of the international media ban. Thirteen days ago, on May 8, Niger's military-controlled Observatoire Nationale de la Communication ordered the suspension of nine international media outlets: France 24, Radio France International, Agence France Presse, TV5 Monde, Jeune Afrique, Mediapart, LSI Africa, TF1 Info, France Afrique Média. The bans remain in effect. Niger is the second-worst jailer of journalists in sub-Saharan Africa per the Committee to Protect Journalists' December 1, 2025 census.
Burkina Faso — day 16 of the TV5 Monde ban. Reporters Without Borders' May 6 report documented Burkinabé journalist Atiana Serge Oulon's detention in a Ouagadougou villa, where he was beaten with tree branches over weeks.
Pakistan — PECA wave continues. The April 29 Freedom Network report documented continued press freedom contraction. Pakistan Press Foundation tracked 233 incidents from January 2025 through April 2026.
Tanzania — Commission of Inquiry report withheld. April 23 report: 518 dead (502 civilians, 16 security, 21 children) during post-October-29-2025 election violence. Report remains withheld from public release. X (Twitter) remains suspended in Tanzania.
Mexico — 40 days to CURP Biométrica. June 30, 2026 deadline. Approximately 127 million mobile phone lines must register against biometric CURP (face, fingerprint, iris) by then or face suspension. The NYC Health + Hospitals breach of May 18 — 1.8 million fingerprints and palm prints permanently in adversarial possession — is the threat model.
Three days into TAKE IT DOWN
Today is day 3 of FTC enforcement of the TAKE IT DOWN Act Section 3. The mandatory takedown framework imposes a 48-hour window on covered platforms after a valid victim notice, with a civil penalty of $53,088 per violation per uncleaned instance. Yesterday, May 20, the FTC launched takeitdown.ftc.gov as a public consumer reporting portal. The fifteen platforms named in May 11 warning letters — Amazon, Alphabet, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok, X — remain the FTC's prioritization map.
The civil-liberties critique from EFF, ACLU, CDT, R Street Institute, and the Free Speech Center remains operational: the takedown provision is broader than the criminal NCII definition; the 48-hour deadline forces compliance over investigation; the Act provides no safeguards against frivolous or bad-faith requests; lawful satire, journalism, and political speech could be wrongly removed; end-to-end-encrypted platforms (Signal, Matrix, Briar, Threema, Tuta, Proton) cannot structurally comply. President Trump's May 19, 2025 signing statement — "I'm going to use that bill for myself too. There's nobody who gets treated worse than I do online" — remains the political risk.
Twenty-two days to Section 702 sunset
Today the Section 702 of FISA sunset is twenty-two days away — June 12, 2026.
The Foreign Intelligence Surveillance Court's March 17, 2026 opinion on FBI Section 702 query practices remains classified. Senator Wyden's 15-day expedited declassification window — negotiated April 30 as condition for the 45-day extension — closed approximately May 15 without publication. The Department of Justice has not declassified. The Director of National Intelligence has not declassified. Senator Cotton's objection to unanimous-consent passage with the declassification provision attached held.
The query-side reform debate continues without the court's structural view. The American Prospect's May 11 reporting described "AI supercharging the surveillance state" — automated downstream analytic chains run against the §702 corpus. Congress is reauthorizing surveillance without the FISC's view of FBI query practices.
The June 12 sunset is the next forcing event.
One year of logs
While the §702 reauthorization debate plays out in Washington, the European Union is preparing legislation that would impose a parallel mass-retention regime on the user side.
Per a leaked European Council document obtained by the German outlet Netzpolitik in November 2025, a majority of EU member states have agreed on the contours of a new data-retention framework. The framework's stated ambition: mandatory logging of connection metadata — IP addresses, timestamps, session length, traffic volume — by every online service. The proposed minimum retention period is one year. Some member states want the proposal to include VPN services with "the broadest possible scope of application." Effectively, the proposal would make "no-log" VPNs illegal in EU territory.
The legislative proposal is expected in summer 2026 under the "Going Dark" / ProtectEU initiative — the European Commission's pivot after losing the Chat Control 2.0 battle on November 26, 2025. The EU's stated goal under the broader Going Dark roadmap: "to enable law enforcement authorities to access encrypted data in a lawful manner" by 2030.
Mullvad VPN has stated publicly it will exit the EU market rather than retain logs. Signal President Meredith Whittaker has stated Signal will leave the European market if encryption-undermining law passes.
The architectural counter to the EU's one-year retention proposal is the user-controlled overlay — URnetwork peer-to-peer overlay, Tor, V2Ray VLESS+Reality, Shadowsocks-2022, Trojan, WireGuard with obfsproxy — that does not appear as a public-service operator in the registry. The user-controlled overlay is statute-invisible.
The user-side primitive stack
The architectural counter to the Verizon DBIR three findings, the CISA KEV eighteen-year tail, the Microsoft Defender CVEs, the Exchange OWA day-7-no-patch active exploitation, the Anodot supply chain pattern, the South Staffordshire Water 20-month undetected breach, the Section 702 sunset, the EU one-year retention proposal, the recipient-country state action, and the agentic surface deployment is the user-side primitive stack. It does not depend on the centralized vendor patching pipeline that produced the eighteen-year tail.
Open clients with user-held keys. Signal. Tuta. Proton. Threema. Briar 1.5.17 (the March 12, 2026 release runs over Bluetooth, Wi-Fi, and Tor; it functions during carrier-layer shutdowns because it does not depend on the carrier layer to forward messages). Cwtch. Session. Matrix homeserver. The architectural property: open codebases get community audits faster than legacy closed-source codebases get vendor patches over eighteen years. The Signal protocol has had eleven-plus years of public scrutiny. End-to-end encryption removes the server-side data-exfiltration surface from supply-chain attack pathways like Anodot.
Open firmware on user-inspectable chips. GrapheneOS (Pixel 6+ with Android 16 in 2026030501 preview, including April through August 2026 Android Security Bulletins). CalyxOS Android 16 test build 7.2.1.0 released May 4, 2026. /e/OS. LineageOS. OpenWRT. The Citizen Lab "Bad Connection" report of April 23 documented two carrier-side surveillance campaigns invisible to closed-firmware operating systems: STA1 (Diameter-to-SS7 downgrade across nine ghost-operator countries) and STA2 (SIMjacker zero-click via the legacy S@T browser SIM applet). Open firmware exposes cache and notification-database behavior to user inspection.
FIDO2 hardware authentication. On May 7, 2026 — FIDO Alliance World Passkey Day — five billion passkeys had been deployed globally. YubiKey. Nitrokey. SoloKey. Yubico has shipped more than 30 million hardware keys lifetime. The NYC Health + Hospitals breach exposed 1.8 million people's fingerprints and palm prints — biometric identifiers that cannot be reissued. Hardware-bound credentials replace biometrics as the second factor in any context that accepts them.
Censorship-resistant transports. Tor Browser 15.0.13 and 16.0a6 (May 7 emergency releases). V2Ray VLESS + Reality. Shadowsocks-2022. Trojan. WireGuard with obfsproxy. URnetwork peer-to-peer overlay. URnetwork's February 19, 2026 MCP server release lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting transport from the carrier layer. Iran's Internet Pro tier, Russia's April 15 ISP VPN-detection law (and delayed May 1 mobile surcharge), China's Great Unplug, the EU Going Dark / ProtectEU summer 2026 proposal — none of these statutes name the overlay because it does not appear as a public-service operator.
Privacy-preserving currencies on user-custody primitives. Bitcoin BIP324 v2 (default-on since Core 27.0; majority of global Bitcoin peer-to-peer traffic now encrypted). Bitcoin BIP352 silent payments (Core 28.0+, BIP376 + BIP392 added 2026). Monero FCMP++ — the Trail of Bits audit closes tomorrow, May 22; 150-million-output anonymity set on clean audit. Zcash Crosslink Milestone 4 (Vitalik's second donation Feb 6 supported the upgrade). The Samourai Wallet co-founder Keonne Rodriguez's May 7 letter from FPC Morgantown — appealing for $2 million in legal-debt support, with pardon hopes faded — is the threat model for what happens when user-custody primitives are criminalized.
Local-inference AI on user-controlled compute. DeepSeek V4 Pro (April 22, MIT, 1.6 trillion / 49 billion active parameters, 1-million-token context, 80.6 percent SWE-Bench Verified, 90.1 percent GPQA Diamond). DeepSeek V4 Flash (284 billion / 13 billion active). Mistral Medium 3.5 (April 29, 128 billion, 77.6 percent SWE-Bench). Qwen 3.6 Max Preview (April 27, 201 languages). GLM-5.1 (744 billion mixture-of-experts, top-ranked open-source LMArena). OpenAI Privacy Filter (April 22, Apache 2.0, browser-runnable via transformers.js + WebGPU). Per the DBIR, employee AI tool use surged from 15 percent to 45 percent in one year — and most of that growth is in cloud-hosted services. Local-inference is the architectural counter.
Federated identity with selective disclosure. W3C Verifiable Credentials 2.0 (Recommendation since May 2025; seven specifications). eIDAS 2.0 BBS+ selective disclosure (IETF finalization in progress). Privacy Pass. The Mexican CURP Biométrica deadline of June 30 (40 days from today, tying 127 million mobile lines to face, fingerprint, and iris biometrics) is the threat model. Don't upload identity to the vendor.
Self-hosted services. Matrix homeserver. Forgejo. Mailcow. Jitsi. Nextcloud. Mautic. SuiteCRM. Moodle community. Open edX. Federation bounds the blast radius of any single vendor compromise. Each homeserver is responsible for its own patching cadence — but federation distributes the third-party-supply-chain risk that the DBIR found grew 60 percent year-over-year. The Grafana / Coinbase Cartel pull_request_target exploitation is the architectural reminder.
Mesh and satellite at the carrier layer. Briar (Bluetooth, Wi-Fi, Tor). Bridgefy. Meshtastic. Reticulum. GoTenna PRO. Starlink. Iran's Internet Pro tier, Sudan's Khartoum tower power-out, Russia's 21-oblast pre-Victory-Day cuts, and the Tanzania five-day complete internet blackout that enabled 518-plus deaths during the post-October-29-2025 election violence — the carrier-independent layer is the structural counter.
Cryptographic agility ahead of the September 21 FIPS sunset and Q-Day 2029. ML-KEM (FIPS 203). ML-DSA (FIPS 204). SLH-DSA (FIPS 205). Standards live since August 2024. The average FIPS 140-3 validation cycle is approximately 542 days at the early-2024 baseline. Pre-emptive post-quantum-secure primitive deployment is the only path through the FIPS sunset. Google's 2029 quantum migration deadline and Cloudflare's matching commitment frame the next 1,228 days. The harvest-now-decrypt-later threat model is operational today. Signal's Sparse Post-Quantum Ratchet (SPQR), combined with the existing Double Ratchet and PQXDH key agreement, forms the "Triple Ratchet" — Signal's post-quantum hardening.
Closing
Eighteen years.
That is how long CVE-2008-4250 has existed. October 2008 disclosure. Microsoft patch published 2008. CISA Known Exploited Vulnerabilities catalog addition: yesterday, May 20, 2026 — eighteen years later.
The vendor patch exists. The remediation didn't happen.
That is the patching pipeline's eighteen-year tail.
Five of seven CISA KEV additions yesterday are from 2008-2010. Two are Microsoft Defender CVEs — the security tool itself in the catalog. The Verizon DBIR finding from forty-eight hours earlier is the macro context: 31 percent vulnerability exploitation as #1 entry, 26 percent remediation rate (down 12 points), 43-day median time-to-patch (up 34 percent), 60 percent supply chain jump (now 48 percent of all breaches), AI shrinking exploit windows from months to hours.
The week's demonstration cases run from yesterday's eighteen-year additions back through the May 12 South Staffordshire Water £963,900 fine (20 months undetected, Windows Server 2003 in operational use, 5 percent of IT environment monitored), the May 14 Exchange OWA active exploitation with no permanent patch as of day 7, the May 14-15 node-ipc 10-million-downloads supply chain compromise, the May 17-18 Grafana / Coinbase Cartel pull_request_target source code exfiltration, the May 18 NYC Health + Hospitals 1.8-million-person biometric breach, the Anodot tokens enabling Zara (197,400) and Vimeo (119,000) downstream breach in April-May.
The Monero FCMP++ Trail of Bits audit closes in twenty-four hours.
Section 702 sunsets in twenty-two days. The FISC opinion remains classified.
The Mexico CURP Biométrica deadline is forty days away.
Iran is on day 83 of the longest internet blackout on record.
The EU "Going Dark" one-year-retention proposal drops in summer 2026.
The FIPS 140-2 sunset is 123 days away.
Q-Day is 1,228 days away.
The user-side primitive stack — open clients, open firmware, hardware keys, censorship-resistant transports, privacy-preserving currency, local-inference AI, federated identity, self-hosted services, mesh and satellite, cryptographic agility — operates outside the centralized vendor patching pipeline that produced the eighteen-year tail.
Eighteen years is the tail.
The stack is the response.
URnetwork is a peer-to-peer overlay for censorship-resistant transport that does not appear in the public-service operator registry of any of the statutes named above. URnetwork's MCP server release of February 19, 2026 lets agentic clients establish VPN sessions over the peer-to-peer overlay, abstracting transport from the carrier layer.
https://ur.io