A vulnerability identified as CVE-2015-20122 was reportedly exploited on the same day it was publicly disclosed, September 29, 2026. This rapid exploitation timeframe was measured from the CVE publication date to its initial listing in a known exploited vulnerabilities (KEV) catalog.
The vulnerability's lifecycle began with its reservation on September 29, 2026, followed by its publication and first KEV listing on the very same day. All reported sightings of exploitation also occurred on September 29, 2026.
While the claim of exploitation on the day of disclosure is noted, it currently rests on a single commercial research catalog, VulnCheck KEV, which listed it on September 29, 2026. Neither the CISA KEV, maintained by the US federal government, nor the EUVD from ENISA, the European Union's cybersecurity agency, currently list CVE-2015-20122 as actively exploited. CIRCL, a cybersecurity aggregator, mirrors information from other sources but does not independently corroborate the exploitation claim in this instance.
Public evidence of exploitation was reported on September 29, 2026, with one public report collected from VulnCheck and CIRCL, linking to an original source. However, the verification of these original sources has not been confirmed. The CVE record itself provides a description and references for further information.






