Vulnerabilità ed exploit · Exploit zero-day

Session Spikes Warn Before Network CVE Disclosures

The useful signal is not raw scan volume. It is a rise in session volume against a vendor’s internet-facing infrastructure, which often appears days before the advisory and gives defenders a measurable head start that IP counts alone miss.

GreyNoise analyzed 103 days of telemetry across 18 network-infrastructure vendors and found 104 surge events, 68 of which preceded a vendor-matched CVE across 33 vulnerabilities in 16 vendor families. The median lead time was 11 days, 49% of surges landed within 10 days of disclosure, and Cisco CVE-2026-20127 had eight surges before Cisco’s advisory, starting 39 days out.

The practical risk is that pre-disclosure activity is now a repeatable warning pattern for network gear, not a one-off anomaly. When session volume and IP count rise together, the warning gets stronger and the lead time stretches, which makes these spikes useful for prioritizing exposure before vendors publish names and fixes.

1 fonte · 20 apr

CVE-2026-20127

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100º percentile).

Data di correzione federale CISA 27 feb · data superata

Cronologia

Fonti

Riepilogo fornitore: Cisco

Riepilogo fornitore: Fortinet

Riepilogo fornitore: Ivanti

Riepilogo fornitore: SonicWall

Part of the PlainSec briefing for 2026-04-20

Every edition of this story: Session Spikes Warn Before Network CVE Disclosures

Altro da oggi