Fortinet confirmed a 9.8-rated, unauthenticated file-write zero-day in FortiMail that attackers are using to drop a reboot-surviving ld.so.preload rootkit. Patching closes the hole but leaves any implant already on the appliance in place.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
MITRE rated CrewAI's nine-name code-sandbox blocklist a CVSS 8.1 flaw, bypassed by a call that executes no import. The fix removed the feature, so teams running agent-written code need isolation at the OS or process level.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58
CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 62%
- Investor
- Investor 3%
Reality
- Evidence79
- Adoption42
- Hype gap+14
- Incentives67
- Confidence70
TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
OpenSSL patched 14 flaws, led by CVE-2026-84782, a CVSS 8.2 DTLS handshake bug that lets an unauthenticated remote peer pull fragments of heap memory. Only software that speaks DTLS is exposed, so VPN, VoIP and IoT products go first in the patch queue.
Perspective Coverage
4 publishers
- Builder
- Builder 40%
- Operator
- Operator 54%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption40
- Hype gap+25
- Incentives30
- Confidence70
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Ranking by KEV, then EPSS, then CVSS puts a 6.5 with 0.61 exploit odds ahead of a 9.1 at 0.02 in a Dev.to triage guide's worked example. The order is sound, though the backlog savings it promises rest on five hypothetical findings and CVE-wide statistics the post does not source.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence50
Unauthenticated attackers can drop PHP onto WordPress sites running Forminator 1.56.1 or earlier. The install base is 600,000; the exposed subset depends on how the forms were built.
Reality
- Evidence72
- Adoption45
- Hype gap+30
- Incentives
- Insufficient
- Confidence68
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
Three of the Crosswork flaws score a flat 10.0, and Cisco says each CVE bundles several underlying defects. No exploitation reported in the wild so far.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 55%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption60
- Hype gap+10
- Incentives30
- Confidence74
Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.
Perspective Coverage
5 publishers
- Builder
- Builder 20%
- Operator
- Operator 65%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+40
- Incentives55
- Confidence55
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.
Perspective Coverage
5 publishers
- Builder
- Builder 15%
- Operator
- Operator 74%
- Investor
- Investor 11%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence62
ExPatch says Telegram Desktop wrote bot button text into HTML chat exports without escaping it from March 2024 until a July fix, and updating the app leaves every file the earlier builds wrote unchanged on disk.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence72
WSO2 published the fix in May. watchTowr saw forged tokens arrive at its honeypot in September. Its own replay against a correctly targeted deployment came back with the credentials the gateway holds.
Publishers:dev.to · security.docs.wso2.com Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
SolarWinds fixed two pre-authentication RCEs in Observability Self-Hosted 2026.2.3, rated CVSS 9.8 and 8.8. Operators have no public detail to check either flaw's precondition against, so for most teams upgrading is the quickest way to know where a monitoring server stands.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Earlier coverage
- Attackers are exploiting CVE-2026-93952 in VeloCloud Orchestrators that authenticate Edges by certificate
Security · September 22, 2026 · 4 publishers
- SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure
Security · September 24, 2026 · 1 publisher
- Eclypsium finds the month's exploited infrastructure flaws again in the management consoles
Security · September 23, 2026 · 1 publisher
- An agent now picks the packages the person prompting it will never see
Build · September 23, 2026 · 1 publisher
- Admin credentials are the only gate on D-Link's unfixed R95 command injection
Security · September 23, 2026 · 1 publisher
- Unauthenticated requests to TCP/19009 run scripts on Check Point management servers
Build · September 22, 2026 · 1 publisher
- Signed int arithmetic in libde265 shrinks a 4 GB plane allocation to 1,040 bytes before the fill
Security · September 22, 2026 · 1 publisher
- Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server
Build · September 22, 2026 · 1 publisher
- A banner-grabbing scanner flags patched OpenSSL 3.0.2 on RHEL 9 as potentially vulnerable
Build · September 22, 2026 · 1 publisher
- Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000
Build · September 21, 2026 · 1 publisher
- A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy
Build · September 20, 2026 · 1 publisher
- A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem
Build · September 19, 2026 · 1 publisher
- N-able's fourth hotfix is the one that closes the N-central code injection
Build · September 19, 2026 · 1 publisher
- A crafted request to one Cisco ISE API endpoint reaches root without a credential
Build · September 19, 2026 · 2 publishers
- GitLab's commits API returns arbitrary files to an unauthenticated caller at CVSS 10.0
Build · September 19, 2026 · 1 publisher
- Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE
Security · September 19, 2026 · 1 publisher
- A prohibited leading character in a RouterOS username rewrites the session's policy mask
Build · September 16, 2026 · 1 publisher
- Operators rebuilding CISA's post-CVSS patch sort must merge KEV with Vulnrichment themselves
Security · September 18, 2026 · 1 publisher
- WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme
Security · September 18, 2026 · 1 publisher
- A crafted HTTP request runs commands as root on unpatched Cisco ISE nodes
Build · September 18, 2026 · 1 publisher
- Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0
Security · September 18, 2026 · 1 publisher
- A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API
Build · September 17, 2026 · 1 publisher
- Delinea fixed two unauthenticated critical flaws in its credential vault 18 days before disclosing them
Science · September 18, 2026 · 1 publisher
- CVE-2026-77179 let sandboxed agent code write anywhere the macOS host account could
Security · September 17, 2026 · 1 publisher
- An empty string in Artifactory's default join keys mints a platform admin token
Build · September 17, 2026 · 1 publisher
- Delinea's 2 September hotfixes all land inside the new SAML impersonation range
Build · September 17, 2026 · 1 publisher
- A crafted DNSKEY overflows the heap in every Unbound release before 1.26.1
Security · September 17, 2026 · 1 publisher
- Microsoft expects 58 of September's 973 CVEs to be exploited within 30 days
Security · September 17, 2026 · 1 publisher
- CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session
Security · September 16, 2026 · 1 publisher
- Acronis bases its CVE-2026-87886 exploitation warning on one customer report
Security · September 16, 2026 · 4 publishers
- One slash in a Host header moves the path Starlette's middleware checks
Build · September 16, 2026 · 1 publisher
- Any Kestra API path ending in /configs skipped Basic Authentication
Build · September 15, 2026 · 1 publisher
- CISA ties 40% of 2024's exploited flaws to a handful of long-known weakness classes
Security · September 15, 2026 · 1 publisher
- Exploitation catalogues logged 495 of the 35,853 CVEs published in the first half of 2026
Security · September 15, 2026 · 1 publisher
- Attackers have been pushing VBScript through live ScreenConnect sessions since August 20
Security · September 14, 2026 · 1 publisher
- CVE-2026-89049 converts a port-forwarding permission into instance-role credentials
Build · September 12, 2026 · 1 publisher
- Prompt injection embedded in malware turns an LLM scanner's refusal into a free pass
Security · September 11, 2026 · 1 publisher
- A wiki that accepted GET as an edit gave read-only agents 18,000 writes
Build · September 11, 2026 · 1 publisher
- Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year
Security · September 10, 2026 · 1 publisher
- cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root
Security · September 9, 2026 · 1 publisher