Hitachi Energy says SOI versions 2.0.0 through 2.2.0 carry CVE-2026-34197, a remote code execution flaw in their bundled Apache ActiveMQ component. CISA's scoring as of 28 September records no exploitation, so operators have time to find SOI hosts and fix them on a planned schedule.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
Reality
- Evidence70
- Adoption40
- Hype gap+10
- Incentives40
- Confidence65
The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence62
The industry is still shipping the defect classes CISA has flagged for years. The case that AI coding assistants will multiply them comes from two named practitioners, not from the agency's own data.
Reality
- Evidence55
- Adoption30
- Hype gap+35
- Incentives75
- Confidence45