NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
OpenAI has fixed a Critical Codex flaw in which a semicolon in a branch name leaked the agent's GitHub OAuth token on all four Codex surfaces. How far one leaked token could reach was set by its scope, which is chosen by whoever provisions the agent.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence60
GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 59%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence74
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
Bitbucket Cloud's API tokens, which replace app passwords removed on 28 July 2026, expire after one year with no extension, a dev.to migration guide says. Teams that switch in July 2026 have set their next credential failure for July 2027 unless someone owns token rotation.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
OpenAI's Codex now builds a project's environment once and starts each cloud task from it, with task state recoverable for up to seven days. For a team rolling it out, the new job is deciding who may edit the shared setup and what it can reach.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives45
- Confidence65
Kaniko's community fork, with cross-stage cache lookahead, ran 1.6x slower than BuildKit on GitLab.com runners in a dev.to benchmark. The 15x gap still quoted against kaniko dates from 2018, so teams choosing an in-cluster builder need figures from their own Dockerfiles.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence35
GitLab's v19.5 docs send AI reviews started by Duo Enterprise seat holders to the single-pass reviewer that reads only the merge request and its diffs. To check cross-file rules on every review, a group Owner has to move seat holders onto the credit-billed Code Review Flow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Aikido found a dozen live GitLab 'email work item' addresses in public docs, each carrying a long-lived token that lets any mailbox act as its owner. GitLab calls it intended behavior, so maintainers must pull the address and reset the token.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 52%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption28
- Hype gap+10
- Incentives52
- Confidence60
WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.
Perspective Coverage
7 publishers
- Builder
- Builder 29%
- Operator
- Operator 62%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence70
Five US agencies report attackers scanning for exposed S7 PLCs and using a public library to read and write data blocks. The mitigation list reads like a commissioning checklist.
Publishers:sans.org · scworld.com Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+40
- Incentives
- Insufficient
- Confidence60
Rapid7 published a Metasploit module for CVE-2026-85706, an unauthenticated file read it says is already exploited against self-hosted GitLab. Every CE and EE build from 18.7 stays exposed until 19.1.8, 19.2.6 or 19.3.2.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence55
The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.
Publishers:dev.to · docs.gitlab.com · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 73%
- Investor
- Investor 5%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence74
Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.
Perspective Coverage
13 publishers
- Builder
- Builder 21%
- Operator
- Operator 76%
- Investor
- Investor 3%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence66
Black Lotus Labs counted about a dozen compromised enterprises, mostly in Asia and South America, on a framework that has been publishing operator commands to infected hosts through IoT message brokers since 2024.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 62%
- Investor
- Investor 11%
Reality
- Evidence66
- Adoption18
- Hype gap+20
- Incentives
- Insufficient
- Confidence64
GitLab raised its FY27 revenue guide by $16 million at the midpoint after 24% billings growth, leaving out a Flex shift worth up to $13 million. Fast conversion would leave cash intact and push reported revenue back toward the old range.
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives40
- Confidence50
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
The fix for CVE-2026-85706 shipped on 10 September in 19.3.2, 19.2.6 and 19.1.8, and CISA listed the flaw as exploited the next day. A ZoomEye fingerprint count of 1,262,273 hosts does not report versions; it shows where to look.
Reality
- Evidence62
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
Microsoft's Defender Experts date the Contagious Interview campaign to December 2022. Its payload lands at the one hiring stage where a candidate is expected to clone and run a stranger's code. The same team tells employers to give staff a non-persistent VM for coding tests.
Reality
- Evidence64
- Adoption35
- Hype gap+8
- Incentives58
- Confidence62
AWS's walkthrough for the pattern wires GitHub and GitLab activity feeds through Step Functions into QuickSight on a schedule you set in CloudFormation, with a detector Lambda that skips the whole cycle when nothing has changed.
Reality
- Evidence46
- Adoption
- Insufficient
- Hype gap+22
- Incentives82
- Confidence56
Earlier coverage
- The SaaSpocalypse thesis still has to get past the customer's pen-testers
Leadership · September 16, 2026 · 1 publisher
- SaaStr's counterfactual Slack works out to 6 to 8 times a triangulated revenue base
Invest · September 15, 2026 · 1 publisher
- Claude's Salesforce beta proposes changes like close-date updates for sellers to approve
Build · September 15, 2026 · 1 publisher
- Origin inherits GitHub's read list for every repo a developer syncs into Cursor
Build · September 14, 2026 · 1 publisher
- Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest
Build · September 14, 2026 · 1 publisher
- East River rewrites the storage under Git without asking anyone to migrate
Build · September 11, 2026 · 1 publisher
- OpenAI opened its first incident 57 days after agents found write access on Artifactory
Build · September 10, 2026 · 2 publishers
- Testing teams adopted AI for writing tests 3.5 times as often as for judging risk
Product · September 9, 2026 · 1 publisher
- Adding Git replicas made Datadog's CI fetches slower because every write went to all of them
Build · September 6, 2026 · 1 publisher
- Opting into native Git in SageMaker Unified Studio turns every save into a staging decision
Build · September 1, 2026 · 1 publisher
- An approving LLM comment sent an unguarded array index into a payment reconciliation job
Build · August 29, 2026 · 1 publisher
- Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020
Security · August 28, 2026 · 1 publisher
- Harness gives the coding agent its own permissions and its own audit trail
Product · August 27, 2026 · 1 publisher
- Gogs checks the path, then follows the symlink out of the repository
Build · August 27, 2026 · 1 publisher
- A repo compromise found in week four outlives GitHub's seven-day Git event log
Security · August 27, 2026 · 1 publisher
- GitLab ships five security fixes and keeps the details sealed until October
Build · August 23, 2026 · 1 publisher
- Partition, not consolidation: what a 43-minute Jenkins queue actually cost
Build · August 21, 2026 · 1 publisher
- 678,000 French filers and one 9.4: the week's patch-and-notify work, with numbers attached
Security · August 21, 2026 · 1 publisher
- The stability step is a branch, not a pipeline: inside one team's release-candidate discipline
Build · August 21, 2026 · 1 publisher
- GitLab 19.3 puts agent runtime, inference models and secrets under one permission model
Security · August 21, 2026 · 1 publisher
- Two hardware tokens, one wrong guess: why SSH keeps asking for your PIN twice
Build · August 20, 2026 · 1 publisher
- GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim
Build · August 18, 2026 · 1 publisher
- Optus's RHEL factory treats image sprawl as a pipeline defect, not an engineer's lapse
Product · August 17, 2026 · 1 publisher
- Thirty MCP tools become three: the reliability bug is in your schema, not the model
Build · August 15, 2026 · 1 publisher