> home / zero-day-timeline

The Zero Day Timeline

Ten vulnerabilities that changed how the industry thinks about attack, disclosure, and defense—from the espionage campaign that made "zero-day" a boardroom word to a deserialization flaw disclosed while it was already being exploited. Each entry is a fact-checked breakdown: what the flaw was, how it worked in plain English, how it was exploited and by whom, its documented impact, and the defensive response. Every claim is grounded in the public record, and every uncertainty is preserved rather than filled in.

10 landmark zero-days · 2010 → 2025 · ordered oldest to newest

January 14, 2010

Operation Aurora

CVE-2010-0249CVSS 3.1: 8.8 High

A use-after-free flaw in Internet Explorer, exploited in a targeted espionage campaign against Google and more than twenty other organizations. Microsoft shipped an out-of-band fix, MS10-002, on January 21, 2010. Researchers linked the campaign to a China-nexus actor, later associated with the Elderwood group.

Browser · Espionage Read the full breakdown →
July 16, 2010

Stuxnet Windows Zero-Day Suite

CVE-2010-2568CVE-2010-2729CVE-2010-2743CVE-2010-2744

The worm that weaponized multiple Windows zero-days at once—an .LNK shortcut flaw, a Print Spooler bug, and win32k privilege-escalation issues—to reach industrial control systems at Natanz. Microsoft's advisory 2286198 appeared July 16, 2010, with MS10-046 following August 2. Widely described as state-sponsored, though the public record attributes it to no specific nation.

Worm · ICS Sabotage Read the full breakdown →
January 3, 2021

Microsoft Exchange ProxyLogon

CVE-2021-26855CVE-2021-26857CVE-2021-26858CVE-2021-27065

A chain of four flaws in on-premises Exchange Server that turned a server-side request forgery into full server takeover. Exploitation was underway by January 3, 2021; Microsoft patched on March 2. Initial activity was attributed to the group Microsoft tracks as HAFNIUM, with roughly 30,000 organizations affected per attributed estimates. Exchange Online was not affected.

Email Server · Mass Exploitation Read the full breakdown →
September 13, 2021

Apple FORCEDENTRY

CVE-2021-30860CoreGraphics · JBIG2

A zero-click iMessage exploit that abused an integer overflow in Apple's CoreGraphics JBIG2 image handling—no tap required from the victim. Apple patched it on September 13, 2021 in iOS 14.8 and related releases. Citizen Lab attributed the exploit, with high confidence, to NSO Group's Pegasus spyware.

Mobile · Zero-Click Spyware Read the full breakdown →
December 1, 2021

Log4Shell

CVE-2021-44228CVSS: 10.0

A maximum-severity flaw in the ubiquitous Log4j logging library: a crafted log string triggered a JNDI/LDAP lookup that could fetch and execute remote code. Evidence of exploitation appeared around December 1, 2021, with public disclosure on December 9. The affected log4j-core versions ran through hundreds of millions of devices—a measure of exposure, not of confirmed compromises.

Library · Ubiquitous RCE Read the full breakdown →
April 7, 2022

Follina (MSDT)

CVE-2022-30190CVSS: 7.8 High

A flaw in the Microsoft Support Diagnostic Tool, invoked through the ms-msdt: URI scheme from an Office document, that could run code with minimal user interaction. Evidence of exploitation dated to April 7, 2022; Microsoft issued a patch on June 14. Reported use included examples associated with actors tracked as TA413 and TA570.

Office · Document Lure Read the full breakdown →
May 27, 2023

MOVEit Transfer and CL0P

CVE-2023-34362CVSS: 9.8

A pre-authentication SQL injection in the MOVEit Transfer file-transfer application, mass-exploited by the CL0P ransomware operation (also tracked as Lace Tempest) to deploy the LEMURLOOT web shell (human2.aspx) and steal data. Exploitation began around May 27, 2023, with a patch on May 31. Attributed estimates put the affected organizations in the thousands.

File Transfer · Mass Data Theft Read the full breakdown →
October 10, 2023

Citrix Bleed

CVE-2023-4966NVD: 7.5 HighCitrix: 9.4 Critical

A buffer over-read in NetScaler ADC and Gateway that leaked process memory—including reusable session tokens—letting attackers hijack sessions and effectively bypass MFA. Patches were disclosed October 10, 2023, though exploitation reportedly began in late August. LockBit 3.0 affiliates were among those who used it. NVD and Citrix scored it differently; both figures are shown.

Edge Appliance · Session Hijack Read the full breakdown →
January 10, 2024

Ivanti Connect Secure Chain

CVE-2023-46805 · 8.2 HighCVE-2024-21887 · 9.1 Critical

An authentication bypass chained with a command injection to produce unauthenticated remote code execution on Ivanti Connect Secure and Policy Secure gateways. Disclosed January 10, 2024 during active exploitation, with the activity detected by Volexity in December 2023 and attributed by Volexity to a likely Chinese nation-state actor tracked as UTA0178. The events made the appliance's own integrity checks impossible to fully trust.

Edge Appliance · Chained RCE Read the full breakdown →
July 19, 2025

Microsoft SharePoint ToolShell

CVE-2025-53770CVSS: 9.8 / 9.3CWE-502

A deserialization-of-untrusted-data flaw in on-premises Microsoft SharePoint Server, disclosed July 19, 2025 while it was already being exploited, enabling unauthenticated remote code execution. Microsoft 365 SharePoint Online was not affected. The public record names no threat actor and gives no victim count—an entry that doubles as a case study in reporting a live zero-day without inventing one.

Server · Unauthenticated RCE Read the full breakdown →

Get the next article first

Weekly updates on AI, DevOps, security, and developer tools. No fluff, no spam.