Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence50
Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
Two exploited Citrix NetScaler zero-days and a CVSS 9.8 Cisco SD-WAN Manager flaw top a weekly DACH OT risk bulletin. For many operators, both products enforce segmentation into OT, so an attacker who takes one over is standing in front of the control systems.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence45
Attackers chained two self-hosted JFrog Artifactory flaws, both patched more than a month before exploitation, to take admin and install backdoor plugins. Either fix breaks the chain, yet on the published tables only release 7.133.28 closes both.
Reality
- Evidence66
- Adoption70
- Hype gap−6
- Incentives45
- Confidence55
Fortinet says attackers are exploiting a CVSS 9.8 unauthenticated file-write flaw in FortiMail, and no fixed release has shipped yet. Until builds arrive, its two workarounds are the only protection, including for 7.2 users told to move to a 7.4 branch that is still unpatched.
Perspective Coverage
7 publishers
- Builder
- Builder 15%
- Operator
- Operator 82%
- Investor
- Investor 3%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence74
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 62%
- Investor
- Investor 3%
Reality
- Evidence79
- Adoption42
- Hype gap+14
- Incentives67
- Confidence70
DIVD, the Dutch volunteer disclosure group, was breached through two chained zero-days in its own Zammad helpdesk that took an attacker to root in seconds. Zammad claims over 2,000 customers, and DIVD wants every older install upgraded to version 7 or taken offline.
Perspective Coverage
8 publishers
- Builder
- Builder 27%
- Operator
- Operator 64%
- Investor
- Investor 9%
Reality
- Evidence68
- Adoption35
- Hype gap+25
- Incentives40
- Confidence66
TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
CISA added Apple's CoreGraphics zero-day CVE-2026-86950 to its KEV catalog, giving federal agencies until October 2, 2026 to patch. Only federal civilian agencies are bound by that date. Every other Apple fleet sets its own deadline for a bug Apple links to targeted attacks.
Perspective Coverage
9 publishers
- Builder
- Builder 22%
- Operator
- Operator 73%
- Investor
- Investor 5%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+20
- Incentives25
- Confidence70
Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence55
LiteLLM's MCP test endpoints let any valid proxy key run arbitrary commands on the gateway, rated CVSS 8.8. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 8, 2026, confirming exploitation in the wild.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
CISA added Apple's CoreGraphics out-of-bounds write, CVE-2026-86950, to its KEV catalog with an October 2 deadline for federal agencies. Apple's iOS advisory is dated September 28, so agencies have four days to move iPhones, iPads and Macs onto patched builds.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence58
Microsoft's record September release fixed up to 997 CVEs, including two local escalations to SYSTEM that attackers used before the patch shipped. A 7.8 score understates the step that turns a phishing foothold into control of the machine, so both go ahead of the 9.8 remote flaws.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence42
Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 68%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence70
- Adoption55
- Hype gap+25
- Incentives40
- Confidence68
Earlier coverage
- CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive
Security · August 19, 2026 · 2 publishers
- One Gitea Signup Now Buys Shell Access. Patch, Close Registration, Audit Hooks Before August 28.
Build · August 26, 2026 · 1 publisher
- ZoomEye's CVE-2023-49105 count matches its entire ownCloud fingerprint at 152,655 hosts
Build · September 26, 2026 · 1 publisher
- CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass
Security · August 29, 2026 · 4 publishers
- CISA ties federal patch deadlines to four yes-or-no questions about each CVE
Security · September 6, 2026 · 2 publishers
- A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV
Security · September 10, 2026 · 4 publishers
- A hand-debugged Python toolkit turned marimo CVE-2026-39987 into bastion SSH in eight seconds
Security · September 11, 2026 · 3 publishers
- Ransomware gangs move onto the vCenter Syslog bug Broadcom patched on July 29
Security · September 15, 2026 · 2 publishers
- Certification rules slow election-system patching, CISA's 2026 security plan says
Security · September 25, 2026 · 2 publishers
- Attackers are exploiting CVE-2026-93952 in VeloCloud Orchestrators that authenticate Edges by certificate
Security · September 22, 2026 · 4 publishers
- Red Heron-linked actor turned mid-July wp2shell exploits into 18,566 stolen government records
Security · September 22, 2026 · 1 publisher
- Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000
Build · September 21, 2026 · 1 publisher
- Firewalling RouterOS SSH to a management network removes MikroTrick's precondition
Build · September 19, 2026 · 1 publisher
- N-able's fourth hotfix is the one that closes the N-central code injection
Build · September 19, 2026 · 1 publisher
- ZoomEye's SonicWall SMA fingerprint returns 7 records against Shadowserver's several hundred
Build · September 19, 2026 · 1 publisher
- CISA gave federal SonicWall SMA 1000 operators three days to patch a pre-auth SSRF
Build · September 19, 2026 · 1 publisher
- A prohibited leading character in a RouterOS username rewrites the session's policy mask
Build · September 16, 2026 · 1 publisher
- Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass
Build · September 18, 2026 · 1 publisher
- A crafted HTTP request runs commands as root on unpatched Cisco ISE nodes
Build · September 18, 2026 · 1 publisher
- CVE-2026-77179 let sandboxed agent code write anywhere the macOS host account could
Security · September 17, 2026 · 1 publisher
- CISA gives federal agencies three days to fix the ScreenConnect flaw already under attack
Security · September 16, 2026 · 1 publisher
- One slash in a Host header moves the path Starlette's middleware checks
Build · September 16, 2026 · 1 publisher
- A crafted email is already getting root on unpatched Cisco Secure Email Gateways
Security · September 15, 2026 · 1 publisher
- Attackers have been pushing VBScript through live ScreenConnect sessions since August 20
Security · September 14, 2026 · 1 publisher
- A nuclei template hit Langflow's unauthenticated build endpoint 20 hours after disclosure
Security · September 11, 2026 · 1 publisher
- Metasploit packages the SonicWall SMA1000 root chain into one module
Security · September 11, 2026 · 1 publisher
- Fourteen percent of attack actions raised an alert across Picus's 338 million simulations
Security · September 9, 2026 · 1 publisher
- Attackers seized MSP N-central servers through the bypass N-able's incomplete fix left open
Security · September 9, 2026 · 1 publisher
- cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root
Security · September 9, 2026 · 1 publisher
- Attackers chain two PaperCut flaws to lift LDAP and SAM credentials from school print servers
Security · September 5, 2026 · 4 publishers
- Google patches a V8 type confusion already being exploited against Chrome users
Security · September 4, 2026 · 9 publishers
- Unpatched TeamCity server gave attackers AWS IAM credentials from JetBrains' Cadence backup
Security · September 5, 2026 · 1 publisher
- Gitea's unpatched older branches force migration to 1.27.x as CISA flags active exploitation
Leadership · September 5, 2026 · 1 publisher
- CISA asks buyers to make eliminated vulnerability classes a contract condition
Security · September 1, 2026 · 1 publisher
- Two product names and a three-day clock: the case for patching the pipeline first
Security · August 26, 2026 · 1 publisher
- TrueConf's update directory is the delivery route: two KEV bugs, one swapped installer
Build · August 21, 2026 · 1 publisher
- CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN
Security · August 21, 2026 · 1 publisher
- MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list
Build · August 20, 2026 · 1 publisher
- One packet reboots your Cisco VPN box, and Cisco will not say who is firing it
Security · August 19, 2026 · 1 publisher
- SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent
Security · August 14, 2026 · 1 publisher