Security researchers are warning that the gap between a software flaw becoming public and attackers actively exploiting it has shrunk to just days, sometimes hours. Several high-profile examples have surfaced this week.
- What it is: A critical SAP Commerce Cloud flaw (CVE-2026-58231) was under active attack within 72 hours of being disclosed. A separate VMware vCenter vulnerability is already being used by an China-linked group to deploy ransomware, and a Zimbra Collaboration flaw (CVE-2026-73570) is also being actively exploited.
- Who is affected: Any business running SAP Commerce Cloud, VMware virtual infrastructure, or Zimbra email. More broadly, any organisation that delays applying vendor security patches.
- What the risk is: Full system compromise, data theft, and ransomware deployment, often with little to no warning before exploitation begins.
- What to do: Apply vendor security patches as soon as they are released rather than waiting for a scheduled maintenance window. If you run any of the platforms above, check patch status today.
We recommend treating critical security patches as same-day priorities, not routine maintenance items.
Source: SecurityWeek