Case study — LegacyHive micropatch

Six days from public PoC to a free ZeroPatch micropatch.

ZeroPatch shipped a free micropatch for LegacyHive six days after the public PoC landed — no paid seat, no upgrade cycle, just a binary-level fix teams could drop in over the weekend. The pattern that made that loop possible is the same one we run on our paid cohorts.

Binary-level micropatchShipped 2026-02-XX

Advisory at a glance

CVE id
CVE-2026-XXXXX
Severity
Critical
Affected version
v <ver>
Fixed version
v <ver>+1
Patch release date
2026-02-XX

Timeline

From public PoC to a free patch

Six days between the public advisory and a binary-level drop-in fix. Same loop we run on paid cohorts, applied to LegacyHive as a public service.

  1. 2026-02-XX

    Public advisory

    Proof-of-concept exploit code drops alongside the public advisory. LegacyHive maintainers confirm the issue and start tracking an upstream fix; downstream users with LegacyHive in production have no binary patch to apply yet.

  2. 2026-02-XX

    ZeroPatch micropatch

    ZeroPatch ships a free micropatch — same shape as the eventual upstream fix, scoped to the vulnerable code path, drop-in over the affected binary, no source rebuild required. Released as a public download six days after the public PoC.

Sources

Where the public record lives

The advisory, the attack-surface write-up, and the upstream security notice that framed the disclosure window.

bleepingcomputer.com

Public PoC and advisory coverage

Open source

wiz.io

Cloud attack-surface write-up

Open source

LegacyHive advisory

Upstream vendor security advisory

Open source

Want the same loop running on your dependency graph?

The same AI remediation loop that shipped the LegacyHive micropatch is what runs on a paid cohort seat. Drop on pricing or talk to the team about your graph.