Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
Reality
- Evidence70
- Adoption40
- Hype gap+10
- Incentives40
- Confidence65
CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 68%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence70
The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.
Perspective Coverage
4 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence66
BOD 26-04 makes remediation urgency a function of exposure, KEV status, exploit automation and technical impact. CISA publishes three of those four answers per CVE; agencies determine the fourth themselves.
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence72
CISA now flags CVE-2025-14733 as used in ransomware attacks, nine months after WatchGuard shipped the fix. Shadowserver's scans show the exposed population fell from more than 115,000 to nearly 9,000, and that remainder is the target set.
Reality
- Evidence70
- Adoption85
- Hype gap+5
- Incentives30
- Confidence72
CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.
Perspective Coverage
4 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
Check Point says a handful of its customers have already been attacked through the Security Management Server, and F5 confirmed exploitation of BIG-IP APM when it disclosed the bug on September 22.
Reality
- Evidence78
- Adoption55
- Hype gap−8
- Incentives62
- Confidence72
The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.
Perspective Coverage
6 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence74
- Adoption68
- Hype gap−8
- Incentives38
- Confidence76
The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
BOD 26-04 revoked the federal CVSS requirement on June 10. The two decision fields CISA promised, automatability and technical impact, go out through Vulnrichment; the KEV feed does not carry them, so every defender does the join.
Reality
- Evidence55
- Adoption30
- Hype gap+12
- Incentives45
- Confidence58
CISA has added StyleSmuggler, CVE-2026-75650, to its exploited-vulnerability catalog with a September 11 federal due date. Sansec dates the first exploitation to September 4, which makes the patch and the compromise check one job.
Reality
- Evidence74
- Adoption68
- Hype gap+5
- Incentives32
- Confidence72
CVE-2025-62593 is a code-injection flaw in Ray that CISA says is already being exploited, and its own entry says the bug can be reached through a browser. The fix is version 2.52.0.
Reality
- Evidence58
- Adoption46
- Hype gap+14
- Incentives34
- Confidence55