Some IPs probe a CVE's exact exploit path weeks before it's public, and if you're recording, you can see it. On April 11 one of our honeypots logged 16 requests for the cPanel WHM login path on port 2087 from 85[.]122[.]114[.]177, an address that has never touched us otherwise, before or since. 17 days later cPanel disclosed CVE-2026-41940, a 9.8 auth bypass in exactly that flow. Method, formulas, and the live table: https://honeylabs.net/blog/probe-17-days-before-the-cve #ThreatIntel #ThreatHunting #Honeypots #CVE #InfoSec #DFIR