Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence50
CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 66%
- Investor
- Investor 7%
Reality
- Evidence64
- Adoption70
- Hype gap+8
- Incentives
- Insufficient
- Confidence62
Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
CISA added Citrix NetScaler flaw CVE-2026-88779 to its exploited-vulnerabilities catalog on 4 October, citing evidence of active exploitation. For anyone running the appliance, confirmed use by attackers puts this fix ahead of work ranked by severity score alone.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence70
Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.
Perspective Coverage
5 publishers
- Builder
- Builder 36%
- Operator
- Operator 50%
- Investor
- Investor 14%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence72
DIVD says an attacker chained two unpublished Zammad bugs from an unauthenticated web session to root on its helpdesk host. Its claim that an autonomous AI agent did it is still a first-party assessment with no independent confirmation yet.
Reality
- Evidence55
- Adoption35
- Hype gap+30
- Incentives55
- Confidence55
Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.
Perspective Coverage
8 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence66
- Adoption35
- Hype gap+18
- Incentives35
- Confidence70
Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.
Perspective Coverage
4 publishers
- Builder
- Builder 21%
- Operator
- Operator 68%
- Investor
- Investor 11%
Reality
- Evidence80
- Adoption40
- Hype gap+5
- Incentives
- Insufficient
- Confidence75
Cisco confirmed attackers are exploiting CVE-2026-76460, a CVSS 10.0 flaw giving unauthenticated root on Identity Services Engine. ISE decides which devices join the network, so a rooted node hands over every access decision and the device credentials it stores.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 59%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence68
Fortinet confirmed a 9.8-rated, unauthenticated file-write zero-day in FortiMail that attackers are using to drop a reboot-surviving ld.so.preload rootkit. Patching closes the hole but leaves any implant already on the appliance in place.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Two exploited Citrix NetScaler zero-days and a CVSS 9.8 Cisco SD-WAN Manager flaw top a weekly DACH OT risk bulletin. For many operators, both products enforce segmentation into OT, so an attacker who takes one over is standing in front of the control systems.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence45
NLnet Labs' Unbound 1.26.1 fixes CVE-2026-81642, a DNSSEC heap overflow its vendor says could allow remote code execution. A related CoreDNS flaw in its newer transport listeners gives resolver operators a second check, this one in their configuration.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Attackers chained two self-hosted JFrog Artifactory flaws, both patched more than a month before exploitation, to take admin and install backdoor plugins. Either fix breaks the chain, yet on the published tables only release 7.133.28 closes both.
Reality
- Evidence66
- Adoption70
- Hype gap−6
- Incentives45
- Confidence55
NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58
Fortinet says attackers are exploiting a CVSS 9.8 unauthenticated file-write flaw in FortiMail, and no fixed release has shipped yet. Until builds arrive, its two workarounds are the only protection, including for 7.2 users told to move to a 7.4 branch that is still unpatched.
Perspective Coverage
7 publishers
- Builder
- Builder 15%
- Operator
- Operator 82%
- Investor
- Investor 3%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence74
GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 59%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence74
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
Earlier coverage
- Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array
Security · October 2, 2026 · 3 publishers
- Gunra enters through the same VPN appliances the advisory says should front RDP
Build · October 2, 2026 · 1 publisher
- DIVD traces its breach to two chained zero-days in its own Zammad helpdesk
Security · October 1, 2026 · 8 publishers
- FBI and EPA pin the water-sector PLC attacks on controllers reachable from the open internet
Build · October 2, 2026 · 1 publisher
- Two known-exploited Chromium V8 bugs lead September's 36 device CVEs beyond the kernel
Build · October 1, 2026 · 1 publisher
- CISA says every version of Monta's charging platform lets attackers pose as EV chargers
Security · October 1, 2026 · 1 publisher
- Crafted links could run script in users' sessions on CISA Malcolm before v26.06.0
Security · October 1, 2026 · 1 publisher
- Armatura One's access-control software leaves a 2023 ActiveMQ flaw open to unauthenticated code execution
Security · October 1, 2026 · 1 publisher
- ABB's PCM600 Scheduler Service gives standard users a route to LocalSystem control
Security · October 1, 2026 · 1 publisher
- Johnson Controls EasyIO Neo controllers send building-system logins over plain HTTP
Security · October 1, 2026 · 1 publisher
- CISA gives federal agencies until October 2 to patch Apple's exploited CoreGraphics flaw
Security · September 30, 2026 · 9 publishers
- NetScaler compromise response has to unwind the controls the gateway concentrated
Build · October 1, 2026 · 1 publisher
- How Gunra actors got into a network through a default SSL VPN admin password
Build · October 1, 2026 · 1 publisher
- Triage and tuning decided which SOC caught CISA's red team
Leadership · October 1, 2026 · 1 publisher
- Google traces most of 2026's exploitation growth to fast n-day weaponization
Security · September 30, 2026 · 4 publishers
- OpenSSL patches a DTLS flaw that sends heap memory to unauthenticated peers
Security · September 30, 2026 · 4 publishers
- NetScaler attackers tunnel into internal networks with a new Python proxy
Security · September 30, 2026 · 21 publishers
- Attackers chain three JFrog Artifactory flaws to mint their own admin tokens
Build · September 30, 2026 · 2 publishers
- A low-privilege LiteLLM key could run system commands through its MCP test endpoints
Build · September 30, 2026 · 1 publisher
- WaterISAC speeds threat sharing for water utilities still running exposed, pre-cyber PLCs
Security · September 30, 2026 · 1 publisher
- CISA gives federal agencies until October 2 to patch Apple's CoreGraphics flaw
Build · September 29, 2026 · 1 publisher
- Two exploited Windows privilege escalations should go first in September's record Patch Tuesday
Build · September 29, 2026 · 1 publisher
- Viidure dashcam platform exposes live footage and firmware through a publicly readable bucket
Security · September 29, 2026 · 1 publisher
- Lantronix cellular gateway turns tampered update metadata into root code, CISA says
Security · September 29, 2026 · 1 publisher
- CVE-2026-22755 opens 37 VIVOTEK camera models to remote command execution
Security · September 29, 2026 · 1 publisher
- CISA publishes nine Anjvision YSSD-RTMP-H5 flaws with no fix planned
Security · September 29, 2026 · 1 publisher
- Toptech TMS7 and TopHAT 7.6.3 let unauthenticated attackers export any database table
Security · September 29, 2026 · 1 publisher
- Two NetScaler zero-days under active attack justify an outage outside the patch cycle
Leadership · September 29, 2026 · 2 publishers
- Nvidia's Huang defends AI distillation as competition despite Treasury's July sanctions threat
Invest · September 28, 2026 · 2 publishers
- Build number and SAML settings decide exposure to exploited NetScaler flaw CVE-2026-19490
Security · September 28, 2026 · 1 publisher
- CISA wants NetScaler owners to check for intruders before installing Citrix's zero-day fixes
Product · September 28, 2026 · 2 publishers
- Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs
Build · September 28, 2026 · 3 publishers
- Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection
Security · September 25, 2026 · 4 publishers
- Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says
Security · September 27, 2026 · 3 publishers
- Meta ads steer Android users to fake Google Play pages carrying the RemControl banking trojan
Security · September 25, 2026 · 4 publishers
- SharePoint flaw CVE-2026-65660 came under attack within days of Viettel's technical write-up
Security · September 27, 2026 · 5 publishers
- Kiteworks asks customers to power down for nine hours to guard against zero-day attacks
Invest · September 27, 2026 · 3 publishers
- Cisco email gateway flaw runs attacker SQL as root the moment it parses a message
Build · September 27, 2026 · 1 publisher
- Putting KEV and EPSS ahead of CVSS lifts a 6.5 finding above a 9.1
Build · September 26, 2026 · 1 publisher
- CISA's exploitation listing moves kernel flaw CVE-2026-53266 ahead of the monthly patch cycle
Build · September 26, 2026 · 1 publisher