Vulnerabilities · 148 days ago

Session Spikes Warn Before Network CVE Disclosures

The useful signal is not raw scan volume. It is a rise in session volume against a vendor’s internet-facing infrastructure, which often appears days before the advisory and gives defenders a measurable head start that IP counts alone miss.

GreyNoise analyzed 103 days of telemetry across 18 network-infrastructure vendors and found 104 surge events, 68 of which preceded a vendor-matched CVE across 33 vulnerabilities in 16 vendor families. The median lead time was 11 days, 49% of surges landed within 10 days of disclosure, and Cisco CVE-2026-20127 had eight surges before Cisco’s advisory, starting 39 days out.

The practical risk is that pre-disclosure activity is now a repeatable warning pattern for network gear, not a one-off anomaly. When session volume and IP count rise together, the warning gets stronger and the lead time stretches, which makes these spikes useful for prioritizing exposure before vendors publish names and fixes.

CVE-2026-20127

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).

CISA federal remediation date Feb 27 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Cisco

Vendor digest: Fortinet

Vendor digest: Ivanti

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-04-20

Editions

Related stories