Ten vulnerabilities that changed how the industry thinks about attack, disclosure, and defense—from the espionage campaign that made "zero-day" a boardroom word to a deserialization flaw disclosed while it was already being exploited. Each entry is a fact-checked breakdown: what the flaw was, how it worked in plain English, how it was exploited and by whom, its documented impact, and the defensive response. Every claim is grounded in the public record, and every uncertainty is preserved rather than filled in.
10 landmark zero-days · 2010 → 2025 · ordered oldest to newest
A use-after-free flaw in Internet Explorer, exploited in a targeted espionage campaign against Google and more than twenty other organizations. Microsoft shipped an out-of-band fix, MS10-002, on January 21, 2010. Researchers linked the campaign to a China-nexus actor, later associated with the Elderwood group.
The worm that weaponized multiple Windows zero-days at once—an .LNK shortcut flaw, a Print Spooler bug, and win32k privilege-escalation issues—to reach industrial control systems at Natanz. Microsoft's advisory 2286198 appeared July 16, 2010, with MS10-046 following August 2. Widely described as state-sponsored, though the public record attributes it to no specific nation.
A chain of four flaws in on-premises Exchange Server that turned a server-side request forgery into full server takeover. Exploitation was underway by January 3, 2021; Microsoft patched on March 2. Initial activity was attributed to the group Microsoft tracks as HAFNIUM, with roughly 30,000 organizations affected per attributed estimates. Exchange Online was not affected.
A zero-click iMessage exploit that abused an integer overflow in Apple's CoreGraphics JBIG2 image handling—no tap required from the victim. Apple patched it on September 13, 2021 in iOS 14.8 and related releases. Citizen Lab attributed the exploit, with high confidence, to NSO Group's Pegasus spyware.
A maximum-severity flaw in the ubiquitous Log4j logging library: a crafted log string triggered a JNDI/LDAP lookup that could fetch and execute remote code. Evidence of exploitation appeared around December 1, 2021, with public disclosure on December 9. The affected log4j-core versions ran through hundreds of millions of devices—a measure of exposure, not of confirmed compromises.
A flaw in the Microsoft Support Diagnostic Tool, invoked through the ms-msdt: URI scheme from an Office document, that could run code with minimal user interaction. Evidence of exploitation dated to April 7, 2022; Microsoft issued a patch on June 14. Reported use included examples associated with actors tracked as TA413 and TA570.
A pre-authentication SQL injection in the MOVEit Transfer file-transfer application, mass-exploited by the CL0P ransomware operation (also tracked as Lace Tempest) to deploy the LEMURLOOT web shell (human2.aspx) and steal data. Exploitation began around May 27, 2023, with a patch on May 31. Attributed estimates put the affected organizations in the thousands.
A buffer over-read in NetScaler ADC and Gateway that leaked process memory—including reusable session tokens—letting attackers hijack sessions and effectively bypass MFA. Patches were disclosed October 10, 2023, though exploitation reportedly began in late August. LockBit 3.0 affiliates were among those who used it. NVD and Citrix scored it differently; both figures are shown.
An authentication bypass chained with a command injection to produce unauthenticated remote code execution on Ivanti Connect Secure and Policy Secure gateways. Disclosed January 10, 2024 during active exploitation, with the activity detected by Volexity in December 2023 and attributed by Volexity to a likely Chinese nation-state actor tracked as UTA0178. The events made the appliance's own integrity checks impossible to fully trust.
A deserialization-of-untrusted-data flaw in on-premises Microsoft SharePoint Server, disclosed July 19, 2025 while it was already being exploited, enabling unauthenticated remote code execution. Microsoft 365 SharePoint Online was not affected. The public record names no threat actor and gives no victim count—an entry that doubles as a case study in reporting a live zero-day without inventing one.
Weekly updates on AI, DevOps, security, and developer tools. No fluff, no spam.