Six days from public PoC to a free ZeroPatch micropatch.
ZeroPatch shipped a free micropatch for LegacyHive six days after the public PoC landed — no paid seat, no upgrade cycle, just a binary-level fix teams could drop in over the weekend. The pattern that made that loop possible is the same one we run on our paid cohorts.
Advisory at a glance
- CVE id
- CVE-2026-XXXXX
- Severity
- Critical
- Affected version
- v <ver>
- Fixed version
- v <ver>+1
- Patch release date
- 2026-02-XX
Timeline
From public PoC to a free patch
Six days between the public advisory and a binary-level drop-in fix. Same loop we run on paid cohorts, applied to LegacyHive as a public service.
- 2026-02-XX
Public advisory
Proof-of-concept exploit code drops alongside the public advisory. LegacyHive maintainers confirm the issue and start tracking an upstream fix; downstream users with LegacyHive in production have no binary patch to apply yet.
- 2026-02-XX
ZeroPatch micropatch
ZeroPatch ships a free micropatch — same shape as the eventual upstream fix, scoped to the vulnerable code path, drop-in over the affected binary, no source rebuild required. Released as a public download six days after the public PoC.
Sources
Where the public record lives
The advisory, the attack-surface write-up, and the upstream security notice that framed the disclosure window.
Want the same loop running on your dependency graph?
The same AI remediation loop that shipped the LegacyHive micropatch is what runs on a paid cohort seat. Drop on pricing or talk to the team about your graph.