Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence50
Brevo says an intruder reached 120 customer accounts and used them to mail phishing from those customers' own domains. Three crypto companies confirmed their newsletter lists were hit. Only one named the provider.
Perspective Coverage
4 publishers
- Builder
- Builder 15%
- Operator
- Operator 69%
- Investor
- Investor 16%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−20
- Incentives40
- Confidence70
SAML's security rests on XML signature validation, and most fielded implementations hand that job to libxmlsec. Trail of Bits says that dependency is the reason to deprecate the protocol and move SSO to OpenID Connect.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence55
GitHub Enterprise Cloud lets an admin clear SSO authorizations for personal access tokens, SSH keys and app user tokens across every organization at once, while deleting the credentials themselves stays limited to Enterprise Managed Users.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence66
Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.
Perspective Coverage
3 publishers
- Builder
- Builder 34%
- Operator
- Operator 48%
- Investor
- Investor 18%
Reality
- Evidence78
- Adoption60
- Hype gap+20
- Incentives58
- Confidence72
The two September 15 disclosures describe a padding oracle and a SAML assertion wrapping bypass in Secret Server's pre-login code path, both reachable without credentials and both already closed in the August build.
Reality
- Evidence55
- Adoption28
- Hype gap+35
- Incentives55
- Confidence47
Delinea scored CVE-2026-15640 at 9.5 on CVSS v4 for on-prem Secret Server 10.5.0 through 12.1.3, and 12.2.7 is the only listed build that also clears the padding oracle and the FIDO2 registration bug.
Publishers:delinea.com
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−8
- Incentives74
- Confidence70
Fortinet switched off FortiCloud SSO worldwide on January 26 and turned it back on the next day with server-side changes. Devices already fully patched against the two 2025 SAML bypasses were compromised anyway.
Reality
- Evidence70
- Adoption66
- Hype gap−8
- Incentives40
- Confidence65
For virtual appliances where exploitation is suspected, Cisco's advisory lists five actions before the box can be trusted again, one of which is installing fixed software. Owners of physical appliances are told to call TAC.
Publishers:cisco.com
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+6
- Incentives70
- Confidence62
CVE-2026-80465 lets an unauthenticated remote attacker hijack an account in some single sign-on setups. The fix is a Mendix Marketplace module update. It has to be taken app by app across three version trains.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−15
- Incentives55
- Confidence68
Brevo closed the SAML vector and reset active sessions by about 8:30 UTC on 10 September. Six of the 138 breached accounts sent phishing mail, and Trezor counted roughly 347,000 recipients in a single day.
Reality
- Evidence48
- Adoption62
- Hype gap+12
- Incentives55
- Confidence45
A dev.to post from 2SD Technologies argues test estates accrete production snapshots because generators only satisfy the schema, and that the tool you point at the fixture becomes a second copy of it in a store with no retention policy.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+14
- Incentives58
- Confidence45
Citrix shipped fixes on 19 August 2026 for a memory overflow and an authentication bypass in NetScaler ADC and Gateway, but each one needs particular features turned on, so the inventory has to come before the change window.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+12
- Incentives35
- Confidence55
The overflow in CVE-2026-8452 sits in PrefixList canonicalization, which NetScaler performs before it validates the SAML signature, so an attacker needs no trust with your IdP and only a reachable virtual server with SAML turned on.
Reality
- Evidence56
- Adoption63
- Hype gap−8
- Incentives44
- Confidence55
The plugin honoured HMAC-SHA1 chosen by the attacker and used the IdP's public RSA key as the shared secret. Free is fixed at 5.4.5, Standard at 17.0.6, under the same slug.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives50
- Confidence48
Red Hat's pitch for SPIFFE and SPIRE on OpenShift is an argument about exposure windows: a leaked Secret stays valid until someone notices it. Agents sharing the analysts' database worsen the arithmetic.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+22
- Incentives82
- Confidence42
Part two of the AWS multi-agent series abstracts model providers with a code sample, then leaves session storage where each framework put it. That is where the switching cost actually sits.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+38
- Incentives58
- Confidence40
Origin keeps GitHub as the source of truth. That is both the reason engineering orgs can try it this quarter and the reason it is not yet an exit.
Reality
- Evidence38
- Adoption22
- Hype gap+32
- Incentives68
- Confidence34
AWS has published a pattern for bridging Bedrock AgentCore agents to Basic Auth backends by building the header inside a Lambda interceptor, with the credential pulled from Secrets Manager at call time.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−8
- Incentives68
- Confidence58