VulNow identifies verified vulnerabilities in your software supply chain an average of 6.6 days before they appear in public CVE feeds, before the attacker window opens. We call these Dark Matter Vulnerabilities™: security flaws that exist in production code, invisible to every CVE-based tool but exploitable by attackers.
The fix is in the code. The advisory is not. That gap (hours, days, or months wide) is where breaches happen and where CVE-based tools go blind.
Dark Matter Vulnerabilities™ are security flaws that exist in open source packages after a maintainer silently pushes a fix, but before any CVE or advisory is published. They are invisible to every scanner that relies on CVE feeds. Attackers can reverse-engineer the fix and begin exploiting unpatched systems immediately. Defenders have no signal, no patch notice, and no indication of exposure. VulNow detects these vulnerabilities in the pre-disclosure window and surfaces them as PreCVEs.
Maintainer discovers security-relevant bug in dependency
Fix pushed to repo. No CVE filed, no advisory issued
Prior versions remain vulnerable. CVE scanners show all-clear.
Attacker reverse-engineers patch, scans for exposed systems
Defenders finally receive signal, often weeks or months later
CVE records take an average of 40 days to publish after ID assignment. 80% of exploits are published before the corresponding CVE is officially released (Unit 42, 2024). 23.6% of CVEs added to CISA's KEV catalog were already being weaponized on or before the day the CVE was disclosed (VulnCheck, 2024).
A 16-day patching window against a 5-day exploitation window is not a security posture. VulNow moves the signal before the chasm begins.
Every detection below was confirmed by a subsequently published CVE. Production intelligence from the first full quarter of VulNow operation.
| # | Package | Lead Time | PreCVE ID | CVE | Severity | Status |
|---|---|---|---|---|---|---|
| 1 | axios | 154d 15h | VULNOW-2025-00485 | CVE-2026-39865 | Medium | Confirmed |
| 2 | react-router | 93d 16h | VULNOW-2025-00050 | CVE-2025-61686 | Critical | Confirmed |
| 3 | authlib | 26d | VULNOW-2026-01604 | CVE-2026-28802 | Critical | Confirmed |
| 4 | authlib | 14d 5h | VULNOW-2026-02264 | CVE-2026-28498 | High | Confirmed |
| 5 | rollup | 3d 57m | VULNOW-2026-01711 | CVE-2026-27606 | Critical | Confirmed |
| 6 | aiohttp | 4d 2h | VULNOW-2026-02808 | CVE-2026-34518 | Medium | Confirmed |
| 7 | minimatch | 1d 10h | VULNOW-2026-01829 | CVE-2026-27903 | High | Confirmed |
| 8 | cryptography | 1d 18h | VULNOW-2026-02735 | CVE-2026-34073 | Medium | Confirmed |
| 9 | undici | 1d 14m | VULNOW-2026-02472 | CVE-2026-1527 | Medium | Confirmed |
| 10 | django | 14m | VULNOW-2026-01584 | CVE-2026-1285 | High | Confirmed |
Showing 10 of 58 confirmed Q1 detections · 28 packages · npm + PyPI · 13.2B combined monthly downloads
80% of exploits are published before the corresponding CVE is officially released, with an average lead of 23 days (Unit 42, State of Exploit Development, 2024).
CVEs added to CISA's Known Exploited Vulnerabilities catalog were already being weaponized on or before the day the CVE was publicly disclosed (VulnCheck, 2024).
More than half of all Q1 2026 PreCVE detections arrived more than a full day before public CVE disclosure. Two arrived over a month early.
The EU Cyber Resilience Act mandates that manufacturers of products with digital elements actively identify, document, and address vulnerabilities, including those not yet publicly disclosed. CVE-based tooling alone cannot satisfy this requirement.
VulNow's PreCVE intelligence directly addresses the CRA's requirements for proactive vulnerability handling, giving EU-regulated organizations a defensible, documented advantage over the silent fix window.
With hard deadlines in September 2026 and December 2027, organizations that have not established proactive vulnerability intelligence programs are already behind.
CRA Article 13 requires manufacturers to identify and document vulnerabilities including those discovered before public disclosure. PreCVEs satisfy this before the CVE exists.
CRA mandates software bill of materials transparency. VulNow enriches your SBOM data with real-time PreCVE risk signals your components carry before any CVE exists.
Standard CVE scoring underweights distribution scale. VulNow's empirically refined severity (Tier 2 plan) provides defensible risk classification for regulated product portfolios.
Whether you're protecting your own software supply chain or shipping next-generation security tooling, PreCVE intelligence opens new categories of detection.
Original research on software supply chain risk, PreCVE intelligence, and the data behind modern vulnerability management.
First full quarter of production PreCVE intelligence: 58 verified detections across 28 packages and 13.2 billion monthly downloads, with average lead time of 6.6 days.
A data-driven investigation into why 83% of supply chain attacks could have been prevented, and why the solution that already exists remains ignored.
Author of Software Supply Chain Security (O'Reilly). Former VP of Supply Chain Security at Schneider Electric (a €38B global enterprise), where she led product security and cyber resilience programs across complex international supply chains. Internationally recognized speaker and authority on vulnerability management, product risk, and EU regulatory compliance. Board director at Cybeats.
20+ years in security, cloud architecture, DevOps, and resilient infrastructure across regulated and mission-critical environments. Built and secured large-scale production systems in Banking and Fintech using AWS, Kubernetes, IaC, and CI/CD automation. Leads VulNow's technical platform, translating deep engineering expertise into scalable predictive vulnerability intelligence.
Join VulNow's Predictive Pilot Program. Receive live PreCVE detections for your dependency stack, or integrate our intelligence feed into your security platform.
Contact: info@vul.now · Netherlands-based · Serving EU & US markets