CISA added Citrix NetScaler flaw CVE-2026-88779 to its exploited-vulnerabilities catalog on 4 October, citing evidence of active exploitation. For anyone running the appliance, confirmed use by attackers puts this fix ahead of work ranked by severity score alone.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence70
CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 68%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence70
Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.
Perspective Coverage
13 publishers
- Builder
- Builder 21%
- Operator
- Operator 76%
- Investor
- Investor 3%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence66
CERT Polska's breakdown of the September RouterOS compromises names two bugs, CVE-2026-67279 and CVE-2026-86060, and the forum logs that match the chain start on September 2, a day before MikroTik shipped fixes.
Reality
- Evidence74
- Adoption52
- Hype gap−8
- Incentives35
- Confidence70
Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.
Reality
- Evidence55
- Adoption60
- Hype gap+25
- Incentives78
- Confidence55
Check Point says a handful of its customers have already been attacked through the Security Management Server, and F5 confirmed exploitation of BIG-IP APM when it disclosed the bug on September 22.
Reality
- Evidence78
- Adoption55
- Hype gap−8
- Incentives62
- Confidence72
Eclypsium tracked 158 infrastructure advisories between August 25 and September 17. The exploited maximum-severity flaws it highlights are authentication bypasses in Cisco's Firewall Management Center and Identity Services Engine.
Reality
- Evidence62
- Adoption72
- Hype gap+14
- Incentives65
- Confidence58
CISA has confirmed exploitation of three Linux kernel flaws without publishing how, and the three entries do not triage the same way, because Red Hat's interim advice covers kTLS and ebtables but not the AF_ALG race.
Reality
- Evidence58
- Adoption35
- Hype gap+12
- Incentives45
- Confidence52
CISA's exploited-vulnerability catalog now holds entries for LiteLLM, Kestra and Starlette, according to a dev.to writeup, and the quickstart docs for those tools still keep provider API keys in the process environment an attacker reads first.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives32
- Confidence34
Cisco Talos says three separate clusters, one sharing tooling with Sandworm, worked the same CVSS 10.0 bypass in Secure Firewall Management Center. The scope change in that vector reaches every firewall the console manages.
Reality
- Evidence72
- Adoption61
- Hype gap+8
- Incentives38
- Confidence68
The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
The fix for CVE-2026-85706 shipped on 10 September in 19.3.2, 19.2.6 and 19.1.8, and CISA listed the flaw as exploited the next day. A ZoomEye fingerprint count of 1,262,273 hosts does not report versions; it shows where to look.
Reality
- Evidence62
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.
Perspective Coverage
16 publishers
- Builder
- Builder 18%
- Operator
- Operator 64%
- Investor
- Investor 18%
Reality
- Evidence82
- Adoption58
- Hype gap−8
- Incentives62
- Confidence80
BOD 26-04 revoked the federal CVSS requirement on June 10. The two decision fields CISA promised, automatability and technical impact, go out through Vulnrichment; the KEV feed does not carry them, so every defender does the join.
Reality
- Evidence55
- Adoption30
- Hype gap+12
- Incentives45
- Confidence58
Fortinet switched off FortiCloud SSO worldwide on January 26 and turned it back on the next day with server-side changes. Devices already fully patched against the two 2025 SAML bypasses were compromised anyway.
Reality
- Evidence70
- Adoption66
- Hype gap−8
- Incentives40
- Confidence65
The bug lets files be pushed and executed through a remote session the host already approved, and CISA says attackers are doing it now. It is ScreenConnect's fourth entry on the KEV catalog since 2024.
Reality
- Evidence62
- Adoption42
- Hype gap+18
- Incentives68
- Confidence58
CVE-2026-76461 was in use before Monday's advisory and Cisco says multiple customers were likely compromised first, so a gateway patched this week still needs a hunt against indicators that root access can erase.
Reality
- Evidence72
- Adoption58
- Hype gap0
- Incentives55
- Confidence66
The industry is still shipping the defect classes CISA has flagged for years. The case that AI coding assistants will multiply them comes from two named practitioners, not from the agency's own data.
Reality
- Evidence55
- Adoption30
- Hype gap+35
- Incentives75
- Confidence45
An authentication bypass in Cisco's firewall management console was fixed in March 2026 and exploited in the wild by August. Cisco Talos attributes the activity to three separate clusters with three different objectives.
Reality
- Evidence58
- Adoption55
- Hype gap+14
- Incentives45
- Confidence55
The KEV catalog's CSV and JSON files now sit in a CC0 GitHub repo that CISA says stays within minutes of cisa.gov. For vulnerability teams, the git log supplies a change history the catalog page itself does not keep.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives40
- Confidence62