CISA's Malcolm before v26.06.0 lets an attacker with no account run script in an analyst's session through one crafted link. Four other flaws in the same advisory need a login, and CISA's fix for all five is the September 2026 release.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives30
- Confidence60
Schneider Electric's NetBotz 5 750 and 755 environmental monitors execute operating system commands from a maliciously modified backup file, and firmware 5.6.0 closes that hole along with an authenticated SQL injection.
Reality
- Evidence68
- Adoption20
- Hype gap+15
- Incentives60
- Confidence65
CVE-2026-16812 scores 10.0 on both CVSS scales because the scope metrics say a compromise of the orchestrator host does not stay inside the orchestrator, and on-prem operators are the ones who have to schedule the fix.
Publishers:arista.com
Reality
- Evidence62
- Adoption35
- Hype gap−12
- Incentives70
- Confidence58
The goPhone value is escaped for SQL, then dropped into an exec() string that PHP runs through /bin/sh. Any active agent can trigger the logout call, and on a production box the injected command runs under sudo.
Reality
- Evidence60
- Adoption28
- Hype gap+14
- Incentives58
- Confidence55
CISA's August 27 advisory lists three flaws in the LK100W below firmware 2.1.240, and one of them hands an attacker the authenticated position another one requires. The firmware is the only device-specific fix.
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+12
- Incentives22
- Confidence70
An AI editor's remediation for a CWE-78 bug was a shell metacharacter blocklist. The payload git clone ext::sh -c whoami carries none of those characters and runs code anyway.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives32
- Confidence56