GreyNoise

17 stats3 reports

All Statistics

SonicWall CVE-2026-0400 experienced six surges with lead times compressing from 37 days to 3 days and peak session volume reaching 69 times the median.

Vulnerability DisclosureThreat IntelligenceSonicWallCVE

68 of 104 detected surge events preceded a vendor-matched CVE, spanning 33 vulnerabilities across 16 vendor families.

Vulnerability DisclosureThreat IntelligenceVendor SecurityCVE

The median lead time of vendor-targeted surges before a matched vulnerability disclosure is 11 days.

Threat IntelligenceVulnerability Disclosure

Attacker activity precedes the public disclosure of a new vulnerability in edge devices and its Common Vulnerabilities and Exposures (CVE) number in 80% of cases. This pre-disclosure activity can precede the CVE disclosure by up to six weeks.

Edge technologiesVulnerabilities

10% of vulnerabilities exploited in 2024 were from 2016 or earlier, with some dating back to the late 1990s, such as CVE-1999-0526.

Attackers are getting quicker at exploiting newly found CVEs, with exploitation observed within hours of disclosure in 2024.

A majority of the most exploited vulnerabilities in 2024 targeted home internet routers, including customer-facing fiber modems

49% of vendor-targeted surges begin within 10 days before the associated vulnerability disclosure.

Threat IntelligenceVulnerability Disclosure

78% of vendor-targeted surges begin within 21 days before the associated vulnerability disclosure.

Threat IntelligenceVulnerability Disclosure

Distributed surges average 21.3 days of lead time before disclosure.

Threat IntelligenceNetwork Security

Concentrated hosting surges average 7.5 days of lead time before disclosure.

Threat IntelligenceNetwork Security

GreyNoise sensors observe eight distinct surges targeting Cisco before the advisory for CVE-2026-20127, with the earliest surge occurring 39 days before disclosure.

Threat IntelligenceVendor SecurityCVE

Fortinet CVE-2026-24858 provides one day of warning before disclosure.

Vulnerability DisclosureThreat IntelligenceCVE

When session volume and IP count spike simultaneously, lead time extends to 21 days.

Threat IntelligenceNetwork Security

40% of vulnerabilities exploited in 2024 were from 2020 or earlier.

GreyNoise detected the exploitation of 29 vulnerabilities before they were added to CISA’s KEV catalog.

28% of the CVEs added to CISA’s KEV catalog were leveraged by ransomware groups.