N-days

Most successful intrusions do not use unknown flaws. They use ones that were fixed months or years ago, on systems where the fix was never applied.

This is worth sitting with, because attention and budget go the other way. The unknown flaw is the more frightening story, and the far likelier cause of your incident is a patch that was available in March. The window that matters is not between discovery and disclosure, it is between a fix existing and you having installed it.

Checked against the primary source.

More on Vulnerability management