Proofpoint launches Active Exploits Protection to cut patch priority lag

Proofpoint says its new solution translates exploit intelligence into network-wide protection in under 18 minutes, ahead of public vulnerability catalogues.

Proofpoint launches Active Exploits Protection to cut patch priority lag

Proofpoint has launched Active Exploits Protection, a new product designed to help enterprise security teams prioritise vulnerability remediation based on observed attacker behaviour rather than generic severity scores. The solution is available globally from 29 June 2026, delivered via the company's existing platform and an API layer.

The product draws on Proofpoint's telemetry across more than two billion emails analysed daily and a sensor network of over 5,000 nodes, which the company says has generated more than three million exploit-related alerts so far in 2026. On the basis of that data, Proofpoint claims to have identified 12 actively exploited CVEs in 2026, compared with eight currently listed in CISA's Known Exploited Vulnerabilities catalogue, suggesting its internal visibility leads public tracking frameworks.

How the product works

Once a vulnerability is confirmed as actively exploited in Proofpoint's telemetry, the platform automatically converts that intelligence into protection controls in approximately 35 seconds, with propagation across a customer's network completing in under 18 minutes. The company says this closes the exposure window even when patching has not yet begun.

Prioritisation is driven by observed attacker activity across more than three million organisations and 14,000 large enterprises in the vendor's customer base. The solution integrates with third-party SOC tools, vulnerability management platforms, and automation pipelines, and exposes an API for teams that want to incorporate the intelligence into custom workflows.

Sumit Dhawan, chief executive of Proofpoint, framed the launch in the context of AI-accelerated threat cycles. "It's no longer enough to identify vulnerabilities," Dhawan said. "Organisations need to understand what attackers are exploiting in real time and reduce their exposure immediately."

The company also cited a figure that fewer than 6% of all disclosed vulnerabilities are ever observed being exploited in real-world attacks, arguing that severity-score-led triage wastes security-team capacity on theoretical risks.

Market context

The vulnerability prioritisation market has expanded sharply as organisations struggle with the volume of disclosures generated by automated scanning and, increasingly, AI-assisted research. Established players in this space include Tenable, Qualys, Rapid7, and a range of exposure-management startups. The differentiator Proofpoint is betting on is proprietary telemetry from its email and messaging security estate, which it argues provides earlier, more operationally grounded signals than threat-feed aggregators that rely on public databases such as the NIST National Vulnerability Database or CISA KEV.

This matters commercially because the enterprise buyer increasingly wants consolidation: a single vendor that can close the loop between threat detection and protection deployment without requiring a separate tool for each layer. Proofpoint's pitch is that its email telemetry gives it a unique vantage point on the delivery mechanism for many exploit chains, not just the vulnerability itself.

Regulatory and standards read-across

The NIS2 Directive, which requires in-scope EU operators to demonstrate timely vulnerability handling and incident response, and the UK's Cyber Resilience Act trajectory both increase the compliance pressure on large enterprises to evidence prioritised patching. Products that can generate audit-ready logs of when a vulnerability was identified, when protection was applied, and when a patch was deployed will have a clearer value proposition in regulated sectors such as financial services and critical national infrastructure.

Proofpoint's claim of leading CISA's KEV catalogue by four CVEs is notable but unverifiable from the release alone. The company has not published the specific CVE identifiers or disclosed the methodology for confirming active exploitation, which means security buyers will need to run proof-of-concept trials before placing material reliance on those figures. The 99.999% detection precision figure cited for email analysis similarly lacks an independent audit reference in the release.