DIVD says an attacker chained two unpublished Zammad bugs from an unauthenticated web session to root on its helpdesk host. Its claim that an autonomous AI agent did it is still a first-party assessment with no independent confirmation yet.
Reality
- Evidence55
- Adoption35
- Hype gap+30
- Incentives55
- Confidence55
Attackers using two NetScaler zero-days since early September left webshells that patching to 14.1-73.37 or 13.1-64.23 does not remove. Operators have to search every appliance for those traces, patched or not, and move OT remote access onto a jump host of its own.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
DIVD, the Dutch volunteer disclosure group, was breached through two chained zero-days in its own Zammad helpdesk that took an attacker to root in seconds. Zammad claims over 2,000 customers, and DIVD wants every older install upgraded to version 7 or taken offline.
Perspective Coverage
8 publishers
- Builder
- Builder 27%
- Operator
- Operator 64%
- Investor
- Investor 9%
Reality
- Evidence68
- Adoption35
- Hype gap+25
- Incentives40
- Confidence66
LevelBlue says attackers are exploiting NetScaler flaw CVE-2026-88771, rated 9.5, to create a hidden superuser account and plant web shells. The patch closes the injection but removes neither, so already-exposed appliances need a compromise check.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
Publishers:dev.to · thestack.technology · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 73%
- Investor
- Investor 12%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence60
Adobe's Connect 12.12 fixes CVE-2026-75682, a 9.9 SQL injection that reaches code execution from any low-privileged account. Connect deployments typically hand those accounts to students, contractors and partners, so the login barrier stops few attackers.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
Adobe's September Connect patch fixes a CVSS 9.9 SQL injection that lets a low-privileged user run arbitrary code. Connect gives accounts to outside students and partners, so that bar is low enough to justify a separate 12.12 window even with no exploitation reported.
Reality
- Evidence55
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 70%
- Investor
- Investor 8%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence68
The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.
Perspective Coverage
6 publishers
- Builder
- Builder 22%
- Operator
- Operator 72%
- Investor
- Investor 6%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence62
The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.
Perspective Coverage
6 publishers
- Builder
- Builder 21%
- Operator
- Operator 70%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence70
Check Point says a handful of its customers have already been attacked through the Security Management Server, and F5 confirmed exploitation of BIG-IP APM when it disclosed the bug on September 22.
Reality
- Evidence78
- Adoption55
- Hype gap−8
- Incentives62
- Confidence72
Two unauthenticated Check Point RCEs, a CVSS 10.0 GitLab path traversal and an already-exploited N-able flaw all came due on September 11. How fast each one closes depends on the release you happen to be running.
Reality
- Evidence35
- Adoption40
- Hype gap+30
- Incentives30
- Confidence40
The new Foundations for OT Cybersecurity guidance treats an asset inventory plus a taxonomy as the precondition for everything else in a defensible architecture. It sets no deadline and names no auditor.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence70
The nine flaws Microsoft fixed in Entra ID, Cosmos DB and six other services never reached a patch queue. The week's real remediation cost sat instead with 21,000 exposed Exchange servers and one Minnesota county.
Reality
- Evidence45
- Adoption55
- Hype gap−10
- Incentives60
- Confidence50
Microsoft patched the Exchange authentication bypass on August 11. Shadowserver's September 1 scan still counts 21,899 internet-facing servers unpatched, and NCSC-NL says working exploit code for full mailbox takeover is circulating.
Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence72
- Adoption30
- Hype gap+18
- Incentives70
- Confidence68
Nine agencies across four countries refreshed the #StopRansomware Akira advisory on Nov. 13 with indicators current to November 2025 and a three-item action list.
Reality
- Evidence79
- Adoption66
- Hype gap+4
- Incentives24
- Confidence71
An authentication state flaw lets anyone who reaches TCP/5900 skip credentials entirely. Multiple cases reported to NCSC-NL ended in root and a Monero miner.
Reality
- Evidence34
- Adoption31
- Hype gap+18
- Incentives24
- Confidence41