Zero-day blitz pushes defenders past patch speed

The gist
Attackers are outpacing defenders in 2026, weaponizing zero-days and exploiting trusted systems faster than organizations can patch or even detect threats.
What to know
- Zero-day exploits have surged across major platforms like Cisco SD-WAN (seven zero-days in six months), Oracle E-Business Suite, and Chrome, overwhelming security teams.
- Attackers now breach entire networks in hours using multi-stage chains and rapid lateral movement—Check Point VPN intrusions compromised domain controllers in under four hours.
- Unpatchable vulnerabilities and attacks abusing implicit trust in OAuth tokens and SaaS integrations leave organizations exposed, with recent breaches like Klue and Tata Electronics showing that trust, not just tech, is the weakest link.
Zero-Days Go Mainstream
Attackers are relentlessly chaining zero-day exploits across trusted platforms like Cisco SD-WAN and Oracle, using advanced tactics to seize entire networks in hours and exposing the growing gap between attacker speed and defender readiness.
By mid-2026, zero-day exploits have surged across critical enterprise platforms like Oracle PeopleSoft, Oracle E-Business Suite, Chrome, and Cisco SD-WAN, reflecting an unprecedented operational tempo among attackers. For instance, Cisco SD-WAN recorded seven zero-days in just six months, with Mandiant labeling this a 'structural failure,' while Google addressed five actively exploited Chrome zero-days including the high-severity CVE-2026-11645. Oracle’s ecosystem has been particularly hard hit, with over 900 internet-facing E-Business Suite instances actively targeted despite available patches, underscoring attackers’ persistence and the widening attack surface impacting universities, government bodies, and major enterprises alike.
Attackers are not only accelerating the pace of zero-day exploitation but also increasing the complexity of their tactics through multi-stage attack chains and rapid lateral movement. Mandiant’s forensic analysis of Cisco SD-WAN revealed sophisticated chains combining authentication bypass, command injection, and hidden root account creation to gain full network control, while Check Point VPN intrusions demonstrated a frightening velocity—compromising domain controllers in under four hours. This rapid progression from initial access to full control highlights a shift where attacker velocity is now measured in hours, not days, challenging defenders to rethink detection and response strategies.
Compounding the threat landscape, attackers exploit implicit trust within enterprise systems and legacy authentication flows, leveraging these assumptions to bypass defenses without relying solely on sophisticated malware. For example, attackers abused Azure’s Resource Owner Password Credential (ROPC) OAuth flow, a legacy mechanism lacking modern MFA protections, to compromise accounts despite MFA being enabled. Similarly, the ShinyHunters gang exploited an unpatched Oracle PeopleSoft zero-day to conduct unauthenticated takeovers, primarily targeting higher education institutions, illustrating how trusted platforms and authentication flows have become prime vectors in zero-day campaigns.
The rapid emergence of zero-days in abandoned or deprecated software components further complicates defenders’ patching efforts, as attackers weaponize these overlooked assets to deploy rootkits and stealers at scale. Notably, hundreds of legitimate-but-abandoned Arch Linux packages were compromised, with affected packages ballooning from 400 to over 1,500, demonstrating how attackers exploit gaps in software lifecycle management. This trend, coupled with continuous exploitation of patched vulnerabilities—such as Oracle E-Business Suite instances remaining exposed post-patch—underscores the urgent need for accelerated patch management, restricted internet exposure, and continuous monitoring of all enterprise assets.
Patch Fatigue and Unfixable Flaws
With unpatchable vulnerabilities and sluggish remediation cycles, organizations are forced into a losing game of mitigations, leaving even fully updated systems wide open to rapid exploitation and persistent malware.
Unpatchable vulnerabilities have emerged as a critical operational challenge in 2026, forcing organizations to rely heavily on mitigations rather than definitive fixes. For instance, Cisco SD-WAN experienced its seventh zero-day this year with no remediation path, while Arista’s EOS tunnel bypass vulnerability was addressed solely through access control lists since no patch is planned. This trend underscores a growing reliance on workaround strategies that leave systems inherently exposed and complicate long-term security postures.
Slow and incomplete patch management continues to exacerbate persistent vulnerabilities, allowing attackers to exploit even fully patched environments through overlooked flaws. Rogue Planet’s ability to achieve SYSTEM privileges on a fully patched Windows system via an unaddressed race condition exemplifies this risk. Despite longstanding awareness, many organizations patch at an average pace of 69 days, a window that attackers now exploit aggressively, with weaponization timelines shrinking to less than 24 hours and multiple threat actors occupying compromised machines within weeks.
Credential hygiene and firmware update delays significantly contribute to the persistence of malware and exploitation risks, as attackers increasingly target legacy authentication flows and unpatched infrastructure. The FortiBleed campaign, which leveraged unpatched enterprise firewalls to capture credentials and facilitate ransomware attacks, highlights how outdated systems remain a favored entry point. Additionally, Azure’s legacy Resource Owner Password Credential flow allowed 81 million password spray attempts bypassing MFA, illustrating how poor credential management amplifies exposure across critical enterprise platforms.
The expanding trust boundaries in modern enterprise environments—encompassing every authentication flow, AI agent, and software dependency—have complicated vulnerability management and patching efforts. This erosion of the traditional perimeter means that organizations must defend a vastly broader attack surface, where slow adaptation and governance failures, such as leaving credentials active for years or neglecting OAuth token reviews, create persistent security gaps. As one analyst warns, 'If you have not built shields, you’re in a lot of trouble,' emphasizing that operational discipline in patching and access governance is now a critical survival requirement amid AI-driven attack acceleration.
Trust: The New Attack Surface
Attackers now weaponize implicit trust in SaaS, cloud, and supplier relationships—turning OAuth tokens, legacy credentials, and unchecked integrations into high-value entry points that bypass traditional defenses and fuel cascading breaches.
By 2026, implicit trust within enterprise systems has emerged as a critical vulnerability, with attackers increasingly exploiting trusted infrastructure such as VPNs, SD-WAN controllers like Palo Alto GlobalProtect and Cisco SD-WAN, and supply chains to gain persistent access and intelligence. Rather than focusing solely on technical vulnerabilities, adversaries prioritize systems that organizations inherently trust, turning OAuth tokens, SaaS integrations, and supplier networks into lucrative attack vectors. The Klue breach exemplifies this trend, where attackers leveraged compromised legacy credentials to harvest OAuth tokens and infiltrate Salesforce environments across nearly 200 organizations without deploying malware, underscoring trust as the central cybersecurity challenge.
The expanding scope of enterprise trust relationships now encompasses SaaS integrations, cloud identity platforms, manufacturing ecosystems, and developer tools, all of which require governance equivalent to traditional infrastructure. As security expert Jack Hirsch emphasizes, “Every vendor relationship, every software dependency, every developer plugin, and every cloud integration now deserves the same governance once reserved only for traditional infrastructure.” This broadening attack surface demands enhanced visibility and continuous validation of trust, moving beyond patching to include governance and trust validation as core defensive strategies.
The dissolution of the traditional network perimeter has transformed every authentication flow, AI agent, and trusted software dependency into a potential attack surface, forcing organizations to rethink their security postures. Incidents like the Tata Electronics breach reveal how a single compromised access account can cascade across multiple international firms, exposing sensitive data in semiconductor, automotive, and electronics sectors. Without continuous verification, organizations risk reactive defenses as attackers exploit assumptions about previously approved access, making trust without verification “one of cybersecurity’s greatest liabilities,” as noted in recent analyses.
Attackers exploit implicit trust not through sophisticated malware but by abusing legitimate credentials, OAuth tokens, and approved integrations, often requiring minimal operational security lapses. The Klue incident, where a simple automated Python script querying Salesforce’s REST API sufficed to breach sensitive data, highlights how attackers leverage trust relationships to bypass direct defenses. This shift underscores the urgent need for defense-in-depth controls and detection rules that monitor trusted integration paths, as failing to do so leaves enterprises vulnerable to lateral movement and data exfiltration via trusted channels.

