DIVD says an attacker chained two unpublished Zammad bugs from an unauthenticated web session to root on its helpdesk host. Its claim that an autonomous AI agent did it is still a first-party assessment with no independent confirmation yet.
Reality
- Evidence55
- Adoption35
- Hype gap+30
- Incentives55
- Confidence55
Cisco confirmed attackers are exploiting CVE-2026-76460, a CVSS 10.0 flaw giving unauthenticated root on Identity Services Engine. ISE decides which devices join the network, so a rooted node hands over every access decision and the device credentials it stores.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Fortinet confirmed a 9.8-rated, unauthenticated file-write zero-day in FortiMail that attackers are using to drop a reboot-surviving ld.so.preload rootkit. Patching closes the hole but leaves any implant already on the appliance in place.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Horizon3 used Anthropic's Mythos model to find CVE-2026-61500, a chain that forges Rejetto HFS admin sessions and reaches remote code execution. The firm expects frontier models to make deeper, less reliable bug classes worth weaponizing at scale.
Reality
- Evidence55
- Adoption15
- Hype gap+30
- Incentives70
- Confidence50
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
Publishers:dev.to · thestack.technology · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 73%
- Investor
- Investor 12%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence60
The kernel fixed CVE-2026-80521 on August 6. Ubuntu has shipped nothing for 22.04, 24.04 or 26.04, including its AWS, Azure and GCP kernels, and DepthFirst's exploit for 26.04 went public on September 22.
Publishers:linuxjournal.com · thehackernews.com Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence68
Ranking by KEV, then EPSS, then CVSS puts a 6.5 with 0.61 exploit odds ahead of a 9.1 at 0.02 in a Dev.to triage guide's worked example. The order is sound, though the backlog savings it promises rest on five hypothetical findings and CVE-wide statistics the post does not source.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence50
A researcher published a GeoServer SQL injection on 12 August 2026 and watchTowr says probing started within hours. With no fix shipped, access control is the only lever available.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Hunt.io says one operator brute-forced its way through more than 14,000 internet-exposed cameras in five weeks. The tooling was borrowed; the exposure did the work.
Perspective Coverage
6 publishers
- Builder
- Builder 34%
- Operator
- Operator 61%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence64
CVE-2026-82329 is reported as a pre-auth authentication bypass in JFrog Artifactory's Access microservice, and it reaches every dependency your builds pull from the platform. One publisher, no vendor advisory.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 63%
- Investor
- Investor 9%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence64
CVE-2026-6471 has sat in every PostgreSQL release since 9.4 shipped in 2014. Cyera says the plugin name in a replication slot request reaches dlopen() unvalidated, which makes the fix a privilege audit as much as a patch.
Perspective Coverage
4 publishers
- Builder
- Builder 32%
- Operator
- Operator 59%
- Investor
- Investor 9%
Reality
- Evidence74
- Adoption55
- Hype gap+24
- Incentives58
- Confidence72
CVE-2026-81963 in the Update Stack and CVE-2026-85880 in ALPC each take a low-privilege foothold to SYSTEM, and the remediation guidance asks for verified restarts, which is a harder number to report than install counts.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.
Perspective Coverage
5 publishers
- Builder
- Builder 15%
- Operator
- Operator 74%
- Investor
- Investor 11%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence62
cPanel's September 14 advisory covers every LiteSpeed Web Server Enterprise build before 6.3.7. The fix shipped on September 11; because auto-update may lag, administrators have to force it onto servers by hand.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence60
CVE-2026-86218 lets an unauthenticated attacker run code on an N-central server with no user interaction. N-able fixed it in build 2026.3.1.14 and has already patched its own hosted instances.
Publishers:horizon3.ai · n-able.com Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence70
CISA said Sept. 23 that ransomware crews are exploiting CVE-2026-63077, an unauthenticated 9.8 RCE in JetBrains TeamCity patched July 25. Any build server patched late has to be handled as breached, including the credentials and signing keys it held.
Reality
- Evidence70
- Adoption75
- Hype gap+15
- Incentives35
- Confidence72
A default self-hosted Artifactory install trusted an empty string as a join key. Because JFrog supports non-expiring tokens, an upgrade can leave a forged administrator token valid.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Earlier coverage
- ToolShell's author publishes a working code-execution exploit for SharePoint's CVE-2026-65660
Security · September 22, 2026 · 2 publishers
- Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers
Security · September 23, 2026 · 6 publishers
- GreyNoise ties 18,566 stolen government records and 996 harvested Zyxel switches to one actor
Build · September 22, 2026 · 1 publisher
- A banner-grabbing scanner flags patched OpenSSL 3.0.2 on RHEL 9 as potentially vulnerable
Build · September 22, 2026 · 1 publisher
- Delinea fixed two unauthenticated critical flaws in its credential vault 18 days before disclosing them
Science · September 18, 2026 · 1 publisher
- Verizon's 43-day median patch time, against a five-day weaponization clock
Security · September 17, 2026 · 1 publisher
- A published ProFTPD mod_sql exploit needs a login and a privileged PostgreSQL role
Build · September 16, 2026 · 1 publisher
- A query string walks past server.fs.deny on Vite dev servers left on a public port
Build · September 15, 2026 · 2 publishers
- Exploitation beat CVE publication for about 256 vulnerabilities last year
Build · September 11, 2026 · 1 publisher
- Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year
Security · September 10, 2026 · 1 publisher
- Two agent sandboxes ship an unauthenticated shell endpoint on every interface
Build · September 6, 2026 · 1 publisher
- Guest admin is enough to break out of VMware Workstation onto the host
Security · September 5, 2026 · 3 publishers
- Counting from the vendor advisory stretches the exploitation window to 116 days
Build · September 5, 2026 · 1 publisher
- August's 398-CVE Patch Tuesday moves the bottleneck to the test bench
Security · September 4, 2026 · 1 publisher
- A dropped authorization check exposes GeoNetwork geoportal backends to unauthenticated RCE
Security · September 2, 2026 · 1 publisher
- Cohesity's field CISO ranks KEV above EPSS above CVSS in a tiebreaker she would hand an analyst
Security · August 31, 2026 · 1 publisher
- Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain
Build · August 31, 2026 · 1 publisher
- Three AI scanners disagreed on 95 percent of one codebase's findings in Contrast's test
Security · August 31, 2026 · 1 publisher
- Hive's SAML validator hands out a session to any Bearer token you forge
Build · August 30, 2026 · 1 publisher
- Exposed AI tooling now outnumbers exposed ICS hosts by more than two to one
Security · August 28, 2026 · 1 publisher
- One shared-hosting customer can take root on a whole cPanel server through parked domains
Security · August 28, 2026 · 1 publisher
- Someone enumerated LiteLLM's key tables 36 hours after the advisory hit defender feeds
Security · August 28, 2026 · 1 publisher
- Self-hosted ServiceNow operators inherit three unauthenticated CVSS 10.0 flaws to patch themselves
Security · August 28, 2026 · 2 publishers
- Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success
Security · August 27, 2026 · 1 publisher
- Frontier AI can find the bugs faster. The patch queue is the number nobody published.
Security · August 26, 2026 · 1 publisher
- Two datasets, one vendor list: edge risk is a procurement problem, not a CVE queue
Security · August 26, 2026 · 1 publisher
- Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor
Security · August 26, 2026 · 1 publisher
- Vulnerability disclosures bent upward in 2026. Algorithm records did not.
Security · August 25, 2026 · 1 publisher
- 8,900 hostile requests, none of them dangerous: reading a Next.js site's own edge log
Build · August 17, 2026 · 1 publisher
- Three Zoom annotation bugs made every screen share a two-way takeover path
Security · August 15, 2026 · 2 publishers