Session Spikes Warn Before Network CVE Disclosures
The useful signal is not raw scan volume. It is a rise in session volume against a vendor’s internet-facing infrastructure, which often appears days before the advisory and gives defenders a measurable head start that IP counts alone miss.
GreyNoise analyzed 103 days of telemetry across 18 network-infrastructure vendors and found 104 surge events, 68 of which preceded a vendor-matched CVE across 33 vulnerabilities in 16 vendor families. The median lead time was 11 days, 49% of surges landed within 10 days of disclosure, and Cisco CVE-2026-20127 had eight surges before Cisco’s advisory, starting 39 days out.
The practical risk is that pre-disclosure activity is now a repeatable warning pattern for network gear, not a one-off anomaly. When session volume and IP count rise together, the warning gets stronger and the lead time stretches, which makes these spikes useful for prioritizing exposure before vendors publish names and fixes.