Trusted by teams that can't afford to wait for upstream patches.
Customer remediation logs as we publish them — how teams running ZeroPatch got a CVE closed before the upstream vendor shipped one. We start with LegacyHive and CVE-2025-21756, and CVE-2025-29927. More remediation logs will follow as editorial sign-off wraps.
What's inside
- Three live case studies you can read end to end — LegacyHive, CVE-2025-21756, and CVE-2025-29927.
- One upcoming case study remains queued for editorial sign-off.
- A clear invite: be the next referenceable team on this page.
Case studies
Read the remediation logs as we publish them.
Three published, one in editorial review. Each case study is a single timeline from public disclosure to shipped fix — proof-first, no marketing-led reordering.
Six days from a public PoC to a free ZeroPatch micropatch — no paid seat, no upgrade cycle.
Free micropatch shipped 6 days after public PoC for CVE-2025-21756
Linux kernel vsock use-after-free — fix merged 11 hours before disclosure, exploit chain blocked on every patched host before the PoC dropped.
Fix auto-merged 11 hours before public disclosure — no customer interrupt.
Next.js middleware authorization bypass — the affected release lines, fixed versions, and audit-backed merge are all visible in one remediation log.
Critical remediation recorded as merged on 2026-09-02.
Coming soon — SaaS platform
A multi-tenant SaaS team that wanted pre-disclosure remediation on its core framework dependency without touching the source.
Will cover the design-partner loop, the false-positive filter shape, and how the agent opened PRs against the real production graph.
3 live case studies, 1 in editorial review.
Be the next case study on this page.
If your team is running a production dependency graph and a remediation SLA measured in hours, talk to us about running the AI patch loop on your real repos. Pilot partners who convert get the full case-study write-up here.