Four September 2026 CVEs in Codex CLI, Roo-Code, OpenClaw and Ollama came from approval gates that read commands differently from the shell. Ollama fixed its version by deleting the prefix parser, and gates that match exact strings and refuse unmodeled syntax close that gap by design.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence50
Fortinet confirmed a 9.8-rated, unauthenticated file-write zero-day in FortiMail that attackers are using to drop a reboot-surviving ld.so.preload rootkit. Patching closes the hole but leaves any implant already on the appliance in place.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Attackers chained two self-hosted JFrog Artifactory flaws, both patched more than a month before exploitation, to take admin and install backdoor plugins. Either fix breaks the chain, yet on the published tables only release 7.133.28 closes both.
Reality
- Evidence66
- Adoption70
- Hype gap−6
- Incentives45
- Confidence55
MITRE rated CrewAI's nine-name code-sandbox blocklist a CVSS 8.1 flaw, bypassed by a call that executes no import. The fix removed the feature, so teams running agent-written code need isolation at the OS or process level.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58
MaxKB's v2.10.5-lts fix for a CVSS 10.0 agent flaw repairs shell quoting but leaves the execute tool off the approval list. According to one developer's trace of the release tag, a prompt planted in ingested documents can still trigger shell commands with no human sign-off.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives30
- Confidence40
Five of nine FreeSWITCH CVEs from June 2026 sit in mod_verto, including an unauthenticated 9.8 heap overflow that unloading the module closes without a patch. The second critical, a 9.1 in the Event Socket Library, stays loaded and reaches any binary linked against libesl.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence55
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
Reality
- Evidence70
- Adoption40
- Hype gap+10
- Incentives40
- Confidence65
Linux distributions backport security fixes without moving the version number, so an unauthenticated scan can only report that a host might be vulnerable. The figures in one dev.to post put the median time to patch at 32 days.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives30
- Confidence55
The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
Adobe scored CVE-2026-75650 at 10.0 and shipped hotfix VULN-39341 three days after Sansec first saw it exploited. The first confirmed victim was running 2.4.6-p15, the newest release, and it had passed a security status check.
Reality
- Evidence58
- Adoption52
- Hype gap+6
- Incentives60
- Confidence55
Two RouterOS flaws published to NVD on 2026-09-05 both sit in code that runs before a session has proven who it is. An upgrade closes them. Which management services answer from the internet is still an open question.
Reality
- Evidence64
- Adoption72
- Hype gap−16
- Incentives34
- Confidence66
NLnet Labs shipped Unbound 1.26.1 on Wednesday with nine CVEs fixed, among them a DNSSEC validator overflow an attacker reaches with one query into a zone he controls. Debian's stable branches are still waiting.
Reality
- Evidence74
- Adoption32
- Hype gap+12
- Incentives42
- Confidence66
Root Evidence rebuilt the exploitation clock on vendor advisory dates rather than NVD publication, and Jeremiah Grossman's team reads the resulting four-month median as a measure of inventory that stopped being maintained.
Publishers:cyrilsimonnet.substack.com
Reality
- Evidence62
- Adoption20
- Hype gap+12
- Incentives58
- Confidence55
Three exploited CVEs arrived together with three different entry requirements. Only the ownCloud flaw needs no credentials, and that is what decides where the first hour of remediation goes.
Publishers:windowsforum.com
Reality
- Evidence70
- Adoption45
- Hype gap−10
- Incentives40
- Confidence62
Insikt Group counted 215 actively exploited CVEs in six months, up 34% year on year, and describes attackers running them through remote access utilities, package registries and payment flows defenders already permit.
Reality
- Evidence61
- Adoption63
- Hype gap−7
- Incentives71
- Confidence57
Half of those rejections say the same thing, that the proposing model pushed severity past the CVSS evidence it had just cited. That is a real finding about the proposer, and it still says nothing about whether a same-family reviewer would have caught it.
Reality
- Evidence44
- Adoption8
- Hype gap+12
- Incentives48
- Confidence38
The bypass needs HTTP transport and SAML mode, so it misses the Kerberos default, but Apache published no CVSS vector and NVD has no score, which leaves triage to whoever actually reads hive-site.xml, and the 4.2.1 fix carries two more security bugs with it.
Reality
- Evidence62
- Adoption20
- Hype gap−8
- Incentives42
- Confidence58
Earlier coverage
- NVD stops scheduling enrichment for roughly 30,000 pre-March-2026 CVEs
Security · August 28, 2026 · 1 publisher
- Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor
Security · August 26, 2026 · 1 publisher
- Vulnerability disclosures bent upward in 2026. Algorithm records did not.
Security · August 25, 2026 · 1 publisher
- Calix gateway takes UPnP orders from the internet, and there is no patch to install
Build · August 24, 2026 · 1 publisher
- Firmware CVE intake: the finding is almost never a zero-day, it is a five-year-old BusyBox
Build · August 22, 2026 · 1 publisher
- Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code
Build · August 22, 2026 · 1 publisher
- Open REST route in WildApricotPress Member Directory hands out members-only emails and phones
Build · August 22, 2026 · 1 publisher