Q2 2026 · 320+ PreCVE Detections Confirmed

Eliminate the
40-Day Disclosure Chasm.

VulNow identifies verified vulnerabilities in your software supply chain an average of 10 days before they appear in public CVE feeds, before the attacker window opens. We call these Dark Matter Vulnerabilities™: security flaws that exist in production code, invisible to every CVE-based tool but exploitable by attackers.

Q2 2026 PreCVE Confirmation Data
320+
Confirmed PreCVE Detections
~10d
Avg Lead Time
154d
Max Lead Time (axios)
97
Packages Across 6 Ecosystems
The Problem

Dark Matter Vulnerabilities™

The fix is in the code. The advisory is not. That gap (hours, days, or months wide) is where breaches happen and where CVE-based tools go blind.

Definition

Dark Matter Vulnerabilities™ are security flaws that exist in open source packages after a maintainer silently pushes a fix, but before any CVE or advisory is published. They are invisible to every scanner that relies on CVE feeds. Attackers can reverse-engineer the fix and begin exploiting unpatched systems immediately. Defenders have no signal, no patch notice, and no indication of exposure. VulNow detects these vulnerabilities in the pre-disclosure window and surfaces them as PreCVEs.

Vuln Identified

Maintainer discovers security-relevant bug in dependency

Silent Patch Committed

Fix pushed to repo. No CVE filed, no advisory issued

Releases Unprotected

Prior versions remain vulnerable. CVE scanners show all-clear.

Threat Actor Window

Attacker reverse-engineers patch, scans for exposed systems

CVE Published

Defenders finally receive signal, often weeks or months later

40d

CVE records take an average of 40 days to publish after ID assignment. 80% of exploits are published before the corresponding CVE is officially released (Unit 42, 2024). 23.6% of CVEs added to CISA's KEV catalog were already being weaponized on or before the day the CVE was disclosed (VulnCheck, 2024).

15m
Attacker scan start after CVE announcement
12h
Avg time defenders identify exposed systems
5d
Mean time to exploitation in 2025 (Mandiant)
16d
Avg time to patch a critical vulnerability

A 16-day patching window against a 5-day exploitation window is not a security posture. VulNow moves the signal before the chasm begins.

Q2 2026 Production Data

320+ Verified PreCVE Detections

Every detection below was confirmed by a subsequently published security advisory — a CVE record, a GitHub Security Advisory, or both. Roughly 85% arrived more than a full day before that advisory existed; the mean lead time across the set is approximately 10 days.

#PackageEcosystemSeverityLead TimeAdvisory Outcome
1axiosnpmMedium154d 15hGHSA + CVE
2react-routernpmMedium93d 17hGHSA + CVE
3authlibPyPIMedium90d 9hGHSA + CVE
4sqlparsePyPIHigh73d 4hGHSA only
5authlibPyPIMedium55d 21hGHSA only
6python-dotenvPyPIMedium50d 21hGHSA + CVE
7undicinpmHigh48d 16hGHSA + CVE
8v8Source repoHigh39d 6hCVE only
9pillowPyPIHigh37d 16hGHSA + CVE
10laravel/frameworkPackagistHigh28d 2hGHSA only
11wsnpmHigh24dGHSA only
12markdown-itnpmHigh22d 11hGHSA only
13cassandra-allMavenMedium20d 18hGHSA + CVE
14dompurifynpmCritical20d 7hGHSA only
15symfony/symfonyPackagistHigh20d 7hGHSA only
16shell-quotenpmCritical17d 23hGHSA + CVE
17activemq-coreMavenCritical17d 15hGHSA + CVE
18twig/twigPackagistCritical16d 8hGHSA only
19jdbi3-freemarkerMavenCritical7d 15hGHSA only

Selected findings from a snapshot of 328 confirmed detections (late July 2026) · 97 packages · npm, PyPI, Packagist, Maven, Go, and container images

View the full confirmed dataset →
196
Resolved to both a GHSA and a CVE
59.8% of confirmed findings
117
GHSA only — no CVE record
35.6% of confirmed findings
15
CVE only — no GHSA
4.6% of confirmed findings
Download Full Q2 2026 Report (PDF, 418 KB)
Why CVE Feeds Are Not Enough

The Numbers Behind the Blind Spot

80%

Exploits precede CVE publication

80% of exploits are published before the corresponding CVE is officially released, with an average lead of 23 days (Unit 42, State of Exploit Development, 2024).

23.6%

Already weaponized at disclosure

CVEs added to CISA's Known Exploited Vulnerabilities catalog were already being weaponized on or before the day the CVE was publicly disclosed (VulnCheck, 2024).

36%

Confirmed findings have no CVE at all

Roughly 36% of VulNow's Q2 2026 confirmed findings resolved to a GitHub Security Advisory with no CVE record. For a CVE-keyed scanner, these vulnerabilities don't just arrive late — they don't exist.

EU Cyber Resilience Act
✓ CRA-Ready Intelligence

PreCVE Intelligence Meets EU Regulatory Reality

The EU Cyber Resilience Act mandates that manufacturers of products with digital elements actively identify, document, and address vulnerabilities, including those not yet publicly disclosed. CVE-based tooling alone cannot satisfy this requirement.

VulNow's PreCVE intelligence directly addresses the CRA's requirements for proactive vulnerability handling, giving EU-regulated organizations a defensible, documented advantage over the silent fix window.

With hard deadlines in September 2026 and December 2027, organizations that have not established proactive vulnerability intelligence programs are already behind.

Proactive Vulnerability Identification

CRA Article 13 requires manufacturers to identify and document vulnerabilities including those discovered before public disclosure. PreCVEs satisfy this before the CVE exists.

SBOM Hypercare

CRA mandates software bill of materials transparency. VulNow enriches your SBOM data with real-time PreCVE risk signals your components carry before any CVE exists.

Distribution-Weighted Severity for Regulated Environments

Standard CVE scoring underweights distribution scale. VulNow's severity is refined against real-world download and deployment data (Tier 2 plan), providing defensible risk classification for regulated product portfolios.

Two Ways to Use VulNow

Defend Your Stack, or Embed PreCVE in Your Product

Whether you're protecting your own software supply chain or shipping next-generation security tooling, PreCVE intelligence opens new categories of detection.

For CISOs, AppSec leads & product security teams

Defend Your Software Supply Chain

  • PreCVE alerts for your active dependencies before public disclosure
  • Prioritize remediation before CVE noise and alert fatigue begins
  • Reduce exposure window on foundational packages like react, axios, django
  • Severity calibrated to your real download exposure, not generic CVSS
  • Shift from reactive triage to proactive patching with a measurable lead time advantage
Start Predictive Pilot Program
See intelligence tiers →
Intelligence & Research

From the VulNow Team

Original research on software supply chain risk, PreCVE intelligence, and the data behind modern vulnerability management.

Team

Built by People Who've Lived This Problem

Cassie Crossley

Cassie Crossley

CEO & Co-Founder

Author of Software Supply Chain Security (O'Reilly). Former VP of Supply Chain Security at Schneider Electric (a €38B global enterprise), where she led product security and cyber resilience programs across complex international supply chains. Internationally recognized speaker and authority on vulnerability management, product risk, and EU regulatory compliance. Board director at Cybeats.

O'Reilly Author30+ years security leadershipSchneider Electric VPEU CRA expertiseQTE designation
Valerio Mulas

Valerio Mulas

CTO & Co-Founder

20+ years in security, cloud architecture, DevOps, and resilient infrastructure across regulated and mission-critical environments. Built and secured large-scale production systems in Banking and Fintech using AWS, Kubernetes, IaC, and CI/CD automation. Leads VulNow's technical platform, translating deep engineering expertise into scalable predictive vulnerability intelligence.

20+ years security engineeringCloud architectureDevSecOpsBanking & Fintech
Predictive Pilot Program

Don't Wait for the CVE.
Get the Signal First.

Join VulNow's Predictive Pilot Program. Receive live PreCVE detections for your dependency stack, or integrate our intelligence feed into your security platform.

Contact: info@vul.now · Netherlands-based · Serving most global markets