It should be pointed out that most vulnerabilities are, in fact, being exploited before they are patched. Citation in this article: https://medium.com/@xParXnoiAx/irresponsible-disclosure-52d0...
It doesn't support your assertion but it's still interesting 2008-2010 data from an antivirus vendor. It's talking about about how long some vulnerabilities were exploited by malware before getting disclosed, use in targeted attacks, and so on.
It does say "In this paper, we consider only exploits that have been used in real-world attacks before the corresponding vulnerabilities were disclosed" so it's unsurprising that in their dataset this is the case :)