Kiteworks fixed CVE-2026-54154, a CVSS 10.0 flaw letting unauthenticated attackers run code on its Email Protection Gateway, in version 9.4.1. Other EPG flaws disclosed the same day are fixed only in 9.5.1, so internet-facing gateways should go straight to that release.
Reality
- Evidence72
- Adoption35
- Hype gap+5
- Incentives
- Insufficient
- Confidence68
Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 60%
- Investor
- Investor 17%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence60
CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence70
- Adoption55
- Hype gap+25
- Incentives40
- Confidence68
A third party published CVE-2026-63520 before the planned date, and two public gadget chains now reach the same flaw by different routes. One signature will not cover both.
Reality
- Evidence72
- Adoption40
- Hype gap+5
- Incentives45
- Confidence70
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Perspective Coverage
7 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption50
- Hype gap−40
- Incentives
- Insufficient
- Confidence74
CISA now flags CVE-2025-14733 as used in ransomware attacks, nine months after WatchGuard shipped the fix. Shadowserver's scans show the exposed population fell from more than 115,000 to nearly 9,000, and that remainder is the target set.
Reality
- Evidence70
- Adoption85
- Hype gap+5
- Incentives30
- Confidence72
CVE-2026-59310 gave a suspected APT crew persistence on vCenter systems in August. CISA has now flagged the same directory traversal as abused by ransomware operators. Broadcom patched it on July 29.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence65
CISA said Sept. 23 that ransomware crews are exploiting CVE-2026-63077, an unauthenticated 9.8 RCE in JetBrains TeamCity patched July 25. Any build server patched late has to be handled as breached, including the credentials and signing keys it held.
Reality
- Evidence70
- Adoption75
- Hype gap+15
- Incentives35
- Confidence72
F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.
Perspective Coverage
6 publishers
- Builder
- Builder 19%
- Operator
- Operator 64%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption40
- Hype gap+10
- Incentives30
- Confidence75
Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.
Reality
- Evidence55
- Adoption60
- Hype gap+25
- Incentives78
- Confidence55
ConnectWise's stopgap is to switch off file transfers in ScreenConnect, and with CISA's exploited-flaw listing now carrying a three-day federal deadline, more than 1,000 exposed servers still run the unpatched build.
Reality
- Evidence62
- Adoption70
- Hype gap+12
- Incentives45
- Confidence60
Two unauthenticated Check Point RCEs, a CVSS 10.0 GitLab path traversal and an already-exploited N-able flaw all came due on September 11. How fast each one closes depends on the release you happen to be running.
Reality
- Evidence35
- Adoption40
- Hype gap+30
- Incentives30
- Confidence40
VulnCheck logged 884 vulnerabilities with first-time exploitation evidence in 2025, and 28.96% of them were already being exploited by the day their CVE appeared, up from 23.6% a year earlier. The same report calls the year's timing highly consistent with 2024.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+18
- Incentives78
- Confidence48
ConnectWise says the fix arrives later this week. Until it does, the only step it offers is a hand-edited per-role permission change that turns off file transfer inside support sessions, on cloud and on-premises alike.
Reality
- Evidence42
- Adoption34
- Hype gap+12
- Incentives66
- Confidence52
The mid-August Citrix advisory that many teams parked behind lower-risk work now has attack traffic behind it, and the appliances in scope are the ones fronting remote access. Role and firmware decide scope, not appliance count.
Reality
- Evidence60
- Adoption34
- Hype gap+15
- Incentives58
- Confidence58
PaperCut shipped emergency fixes for CVE-2026-81578 and CVE-2026-82078 on Thursday and Friday, and by the weekend Defused was watching honeypot intruders bypass authentication and read database tables instead of running code.
Reality
- Evidence62
- Adoption58
- Hype gap+18
- Incentives58
- Confidence60
CISA says attackers reached programmable logic controllers over the internet during July 2026, changed IP addresses and passwords, and left some utilities unable to monitor their own equipment. No actor has been named.
Reality
- Evidence58
- Adoption55
- Hype gap+6
- Incentives38
- Confidence52
Attackers are forging tokens SharePoint accepts, then enumerating management APIs and probing Business Connectivity Services for the execution sink. BleepingComputer reports nobody has seen that last step land.
Reality
- Evidence55
- Adoption42
- Hype gap+18
- Incentives30
- Confidence48
CVE-2026-58231 chains a default auth client with missing input validation in SAP's Data Hub Adapter. The fix needs a rebuild and redeploy; the attackers needed 72 hours.
Reality
- Evidence42
- Adoption28
- Hype gap+12
- Incentives38
- Confidence44