CISA added Citrix NetScaler flaw CVE-2026-88779 to its exploited-vulnerabilities catalog on 4 October, citing evidence of active exploitation. For anyone running the appliance, confirmed use by attackers puts this fix ahead of work ranked by severity score alone.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence70
Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence55
CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
CVE-2025-62593 carries a CVSS 9.4 and a federal remediation deadline of August 20, 2026. The unauthenticated endpoints behind it are a design decision, not an oversight.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 60%
- Investor
- Investor 6%
Reality
- Evidence68
- Adoption50
- Hype gap+15
- Incentives35
- Confidence66
watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 63%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption55
- Hype gap+20
- Incentives35
- Confidence70
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
Reality
- Evidence70
- Adoption40
- Hype gap+10
- Incentives40
- Confidence65
CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 68%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence70
CVE-2026-21962 reached CISA's exploited-vulnerabilities catalog on August 24 with an August 27 deadline. Honeypots logged attempts in March, and Oracle's fix has been available since January.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Perspective Coverage
7 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption50
- Hype gap−40
- Incentives
- Insufficient
- Confidence74
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.
Perspective Coverage
4 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence66
BOD 26-04 makes remediation urgency a function of exposure, KEV status, exploit automation and technical impact. CISA publishes three of those four answers per CVE; agencies determine the fourth themselves.
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence72
CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.
Perspective Coverage
4 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.
Perspective Coverage
13 publishers
- Builder
- Builder 21%
- Operator
- Operator 76%
- Investor
- Investor 3%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence66
FedRAMP will require daily vulnerability scans at Class D and fixes in as little as 12 hours from December 7, 2026, with a grace period to March 7, 2027. Failures in the detection pipeline now count as vulnerabilities themselves.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives68
- Confidence55
Check Point says a handful of its customers have already been attacked through the Security Management Server, and F5 confirmed exploitation of BIG-IP APM when it disclosed the bug on September 22.
Reality
- Evidence78
- Adoption55
- Hype gap−8
- Incentives62
- Confidence72
The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.
Perspective Coverage
6 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence74
- Adoption68
- Hype gap−8
- Incentives38
- Confidence76
The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.
Perspective Coverage
16 publishers
- Builder
- Builder 18%
- Operator
- Operator 64%
- Investor
- Investor 18%
Reality
- Evidence82
- Adoption58
- Hype gap−8
- Incentives62
- Confidence80
BOD 26-04 revoked the federal CVSS requirement on June 10. The two decision fields CISA promised, automatability and technical impact, go out through Vulnrichment; the KEV feed does not carry them, so every defender does the join.
Reality
- Evidence55
- Adoption30
- Hype gap+12
- Incentives45
- Confidence58
Earlier coverage
- FedRAMP's staffing conditions make federal SaaS revenue a hiring decision
Leadership · September 17, 2026 · 1 publisher
- Confirmed exploitation now lands 40 days sooner after a CVE goes public
Product · September 15, 2026 · 1 publisher
- Attackers have been pushing VBScript through live ScreenConnect sessions since August 20
Security · September 14, 2026 · 1 publisher
- CISA mirrors the KEV catalog on GitHub with a public commit history
Security · September 12, 2026 · 1 publisher
- Attackers have been planting web shells on Magento stores since September 4
Security · September 10, 2026 · 2 publishers
- Gitea's unpatched older branches force migration to 1.27.x as CISA flags active exploitation
Leadership · September 5, 2026 · 1 publisher
- Unauthenticated file exposure puts ownCloud first in CISA's newest KEV batch
Leadership · September 4, 2026 · 1 publisher
- CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines
Product · August 18, 2026 · 1 publisher
- CISA's KEV triage guidance tells agencies to collect RAM before they patch
Security · August 17, 2026 · 1 publisher