# Preserve the link between a temporary zero-day name and its later CVE identifier

> How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:13+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

How should a vulnerability case remain traceable when Defender replaces its temporary TVM name with a CVE?

## Potentially affected

Defender Vulnerability Management records for known zero-day vulnerabilities that initially lack an assigned CVE identifier.

## DSE recommendation

Keep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available.

## Article

## Source facts

Defender Vulnerability Management can display a zero-day without a CVE under a temporary TVM-XXXX-XXXX name. It replaces that name when a CVE is assigned, while keeping the earlier name searchable in the side panel. When a patch becomes available, the recommendation changes to Update and the zero-day tag is removed. The service displays only zero-days about which it has information. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities).

## Applicability

Use this continuity check for an already tracked vulnerability whose displayed identifier or label changes. A naming transition and patch availability are lifecycle information; neither is evidence that the organization’s affected installations were repaired.

## DSE recommendation

Keep the temporary identifier as an alias in the existing vulnerability case when the official CVE becomes available. Ask the case owner to connect earlier mitigation decisions, affected-software evidence and subsequent update work to that same record. Avoid closing the case merely because its old display label disappears, and investigate a possible duplicate before creating another independently tracked item.

## Verification

Search for the retained temporary name and compare the resulting record with the assigned CVE and software scope. Record the identifier transition separately from the patch-deployment decision. If an update is now recommended, confirm which affected installations have actually received the approved remediation and which remain exceptions. Keep unverified installations open; the acceptance result is a reconciled case history and observed remediation state, not simply a cleaner zero-day filter.

## Official references

[Microsoft Learn: Zero-day vulnerability handling](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities). Source reviewed September 9, 2026.

## Primary reference

- Name: Mitigate zero-day vulnerabilities - Microsoft Defender Vulnerability Management | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-zero-day-vulnerabilities
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve the link between a temporary zero-day name and its later CVE identifier,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-463-preserve-the-link-between-a-temporary-zero-day-name-and-its-later-cve-identifier/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
