The patch almost always arrives too late.
Six vulnerabilities that turned into real incidents over the past year, placed on one scale: the time between attackers starting to exploit them and anyone publishing an advisory about them. For four of the six, that difference is negative.
4/6
exploited before publication.
The exploitation window
The dashed line is the day the vendor published its advisory. Anything to the left of it was already being exploited before the vulnerability existed on paper. No patching policy, however tight, closes a window that opened before anyone knew it was there.
- CVE-2026-1281Endpoint Manager Mobile≈-181 d · exploited before publication
- CVE-2026-88771NetScaler ADC / Gateway-22 d · exploited before publication
- CVE-2026-12569Windchill / FlexPLM≈-16 d · exploited before publication
- CVE-2026-81578PaperCut NG/MF-1 d · exploited before publication
- CVE-2026-60137WordPress core0 d · exploited after publication
- CVE-2026-85706GitLab CE/EE+1 d · exploited after publication
That is why patching is necessary but not sufficient. What closes the gap is knowing what you have facing the internet, and having somebody look at it the way an attacker would before an attacker does.
From class to incident
None of these incidents rests on a new kind of mistake. They are the vulnerability classes this knowledge base explains, found in software thousands of organisations run. Understand the class and you recognise the next case before it has a name.
The six cases
- CWE-20A03:2021Citrix NetScaler ADC and Gateway (CVE-2026-88771)CVE-2026-88771 explained: how attackers turned a NetScaler log line into a root shell without logging in, and why patching alone does not clear you.
- CWE-89A03:2021WordPress core (CVE-2026-60137)CVE-2026-60137 explained: a medium-rated SQL injection in WordPress core that, chained with CVE-2026-63030 as wp2shell, hands attackers an admin account.
- CWE-502A08:2021PTC Windchill and FlexPLM (CVE-2026-12569)CVE-2026-12569 explained: how a deserialization flaw in PTC Windchill and FlexPLM was used, most likely by Cl0p, to steal engineering data.
- CWE-305A07:2021PaperCut NG/MF (CVE-2026-81578)CVE-2026-81578 explained: how an authentication bypass in PaperCut NG/MF, chained with a second flaw, let attackers take over print servers worldwide.
- CWE-22A01:2021GitLab CE/EE (CVE-2026-85706)CVE-2026-85706 explained: a path traversal in the GitLab commits API that leaked server files without a login, probed the day after the patch.
- CWE-94A03:2021Ivanti Endpoint Manager Mobile (CVE-2026-1281)CVE-2026-1281 explained: how a code injection in Ivanti EPMM let attackers take over mobile device management servers, and why patching was not enough.
Who is behind it
Attackers are not an anonymous mass. They are organised groups with a business model or an assignment, and with a recognisable way of getting in. These six shape a large part of the picture.
Cl0p
extortion
Extortion at scale, largely without encryption
Cl0p's signature is the mass campaign: one vulnerability in file transfer or enterprise software that thousands of organisations expose to the internet, used against hundreds of them in a single wave, often before a patch exists. Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo, Oracle E-Business Suite and, in 2026, very probably PTC Windchill. In these campaigns hardly anything gets encrypted: the data is stolen and the threat to publish it is the leverage.
LockBit
extortion
Ransomware as a service
LockBit supplied the ransomware and the extortion platform; separate affiliates did the break-in and shared the proceeds. Those affiliates were rarely creative about entry: unpatched edge appliances and stolen credentials, Citrix Bleed among them. In February 2024 police forces took over LockBit's infrastructure in Operation Cronos. The brand has tried to come back since, but the model it stood for now runs under other names.
Akira
extortion
Ransomware through the VPN
Akira has been active since 2023 and almost always comes in through the VPN: a login without a second factor, or a known vulnerability in the VPN appliance itself, in Cisco and SonicWall equipment among others. Rarely anything new, mostly a door that should have been closed already. That makes the group a good gauge of how sound your remote access really is.
Scattered Spider
extortion
Social engineering of the service desk
Scattered Spider rarely needs a vulnerability. The group calls the service desk, poses as an employee and has a password or an MFA token reset, then steals data to extort and in some cases deploys ransomware. Alongside that: SIM swapping and wearing users down with endless MFA prompts. What stops this is a service desk that verifies identity properly, and MFA that cannot be phished or reset over the phone.
Volt Typhoon
state-linked
State-linked pre-positioning in critical sectors
Western agencies link Volt Typhoon to China, and the group stands out for what it does not do: no ransomware, no visible loot, hardly any malware on the networks it enters. It comes in through edge equipment, hides its traffic behind hijacked end-of-life office routers, and then works with the administrative tooling already present, in order to stay inside critical infrastructure for years.
Sandworm
state-linked
Destructive state operations
Sandworm is attributed to Russian military intelligence and sits behind a series of destructive attacks, from NotPetya to repeated strikes on the Ukrainian power grid. The objective is not money but outage, which makes the group a different class of risk from an extortion gang.