Agentic Pentesting Proves Attack Paths but Has Coverage Limits

Agentic pentesting can establish whether a vulnerability is exploitable and can confirm chained attack paths from initial access to a critical asset. But the method has material limits in the speed with which proof arrives and the portion of an enterprise estate it can safely test.
The distinction is increasingly important as vulnerability volume and attacker speed rise. The article cites 35,364 CVEs identified in the first half of 2026, a 49.5% year-over-year increase. It also puts mean time from disclosure to exploitation at eight hours in 2026, down from 21.5 days in 2025.
What live validation can establish
An autonomous assessment can safely execute an exploit rather than infer risk from a software version banner. It can also enumerate, pivot and chain techniques to show a confirmed route through privilege escalation or lateral movement. On assets it reaches, that evidence gives remediation teams a concrete basis for prioritising and retesting fixes.
The approach is particularly suited to the question raised by an infrastructure change: did it create a new attack path? Its sequential workflow—foothold, enumeration, pivot, chaining and proof—can provide the live evidence required to answer that question.
Why speed and scope remain constraints
Scale changes the calculation. The article says a complete agentic assessment of a 250,000-endpoint estate can take weeks. That is considerably faster than a human-led engagement lasting a quarter, but the environment can change while a large sweep is running. Results from early stages may no longer describe conditions at completion.
Annual pentests can leave a blind window of up to 365 days after a change, while weekly automated runs can still leave up to seven days. Gartner's Continuous Offensive Security Testing model instead describes trigger-driven, risk-tiered testing completed in risk-aligned timeframes, often minutes or hours. Gartner expects more than 60% of enterprise pentest programmes to operate as continuous validation by 2028.
Exploit-dependent testing cannot reach every asset
Live exploitation may be unsuitable for business-critical production systems, very large segments, and restricted or air-gapped zones because of safety, stability and access constraints. It also cannot test a vulnerability for which no working exploit exists. The article estimates that autonomous pentesting by itself may see only 20% to 30% of real exploitability in a typical enterprise.
Its proposed operating model assigns validation to the change that triggered it. Exploitability validation tests the techniques on which an emerging vulnerability depends across affected assets, without requiring a working exploit. Security control validation emulates observed campaign techniques against live defences to determine whether they are prevented, detected or missed. Agentic pentesting is then used where live, chained proof is safe and appropriate.
One evidence model for remediation
Picus argues that these methods should feed a shared, deduplicated and asset-aware findings model rather than create separate queues. Its Picus Platform groups Autonomous Penetration Testing, Exposure Validation and Breach and Attack Simulation around shared evidence, one backlog and one closure state for each exposure.
For security teams, the practical implication is to treat agentic pentesting as a high-value method for proving reachable attack paths, not as a substitute for validation across the entire estate. Matching the test method to each change and consolidating the resulting evidence can help teams route mitigations and revalidate fixes within the available response window.

