Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.
Reality
- Evidence70
- Adoption72
- Hype gap0
- Incentives50
- Confidence65
vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58
TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
VulnCheck counts Chrome CVEs up 563% and GitHub-issued CVEs up 476% this year, a rise it calls consistent with AI-assisted bug finding. Whether the volume lasts is unknown, so exploitation data still sets patch order.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives55
- Confidence50
watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 63%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption55
- Hype gap+20
- Incentives35
- Confidence70
A flaw in NASA's open-source AIT-GUI lets unauthenticated requests reach spacecraft command routes, and Cycode says a malicious web page can deliver them through an operator's browser.
Perspective Coverage
4 publishers
- Builder
- Builder 43%
- Operator
- Operator 50%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+30
- Incentives45
- Confidence65
A third party published CVE-2026-63520 before the planned date, and two public gadget chains now reach the same flaw by different routes. One signature will not cover both.
Reality
- Evidence72
- Adoption40
- Hype gap+5
- Incentives45
- Confidence70
The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.
Perspective Coverage
4 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption40
- Hype gap+15
- Incentives65
- Confidence60
Manifold Security reported eight instances across seven command-line agents. The command runs as the user, outside the sandbox, with no approval prompt, and four were still firing when the researchers retested on September 1.
Publishers:manifold.security · thehackernews.com Reality
- Evidence72
- Adoption60
- Hype gap+15
- Incentives55
- Confidence70
QTYF built and ran the scanning and routing frameworks other Chinese teams pointed at U.S. critical infrastructure. That means the proxy addresses and scan fingerprints in your logs point to the supplier; the intruder behind them stays unnamed.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 58%
- Investor
- Investor 19%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence66
Cisco Talos says three separate clusters, one sharing tooling with Sandworm, worked the same CVSS 10.0 bypass in Secure Firewall Management Center. The scope change in that vector reaches every firewall the console manages.
Reality
- Evidence72
- Adoption61
- Hype gap+8
- Incentives38
- Confidence68
CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.
Perspective Coverage
16 publishers
- Builder
- Builder 18%
- Operator
- Operator 64%
- Investor
- Investor 18%
Reality
- Evidence82
- Adoption58
- Hype gap−8
- Incentives62
- Confidence80
Cisco patched CVE-2026-20079 in March 2026 and confirmed in September that attackers had used it in August. Talos ties three clusters to the console, including one it links to Sandworm tooling and a Qilin affiliate.
Reality
- Evidence74
- Adoption72
- Hype gap+5
- Incentives38
- Confidence62
CVE-2026-76461 was in use before Monday's advisory and Cisco says multiple customers were likely compromised first, so a gateway patched this week still needs a hunt against indicators that root access can erase.
Reality
- Evidence72
- Adoption58
- Hype gap0
- Incentives55
- Confidence66
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
An authentication bypass in Cisco's firewall management console was fixed in March 2026 and exploited in the wild by August. Cisco Talos attributes the activity to three separate clusters with three different objectives.
Reality
- Evidence58
- Adoption55
- Hype gap+14
- Incentives45
- Confidence55
Chen Yixin's signed article calls Claude Mythos and GPT-5.5-Cyber a serious risk to China's critical information infrastructure. It cites no incident, and only one of the two is sold to customers at all.
Reality
- Evidence58
- Adoption35
- Hype gap+45
- Incentives72
- Confidence55
VulnCheck logged 884 vulnerabilities with first-time exploitation evidence in 2025, and 28.96% of them were already being exploited by the day their CVE appeared, up from 23.6% a year earlier. The same report calls the year's timing highly consistent with 2024.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+18
- Incentives78
- Confidence48
Earlier coverage
- A spoofed Host header let DeepSeek Harness agents switch off their own sandbox
Product · September 9, 2026 · 1 publisher
- One shell command let a DeepSeek Harness agent switch off its own file sandbox
Security · September 9, 2026 · 1 publisher
- Two agent sandboxes ship an unauthenticated shell endpoint on every interface
Build · September 6, 2026 · 1 publisher
- Counting from the vendor advisory stretches the exploitation window to 116 days
Build · September 5, 2026 · 1 publisher
- Langflow's exploited-in-the-wild count climbed from one bug to twelve in six months
Product · September 2, 2026 · 1 publisher
- A root implant in ZBT router firmware takes orders from whoever holds the C2 position
Build · September 2, 2026 · 1 publisher
- Active Storage routed stranger-supplied uploads into libvips MATLAB and NIfTI loaders
Security · August 31, 2026 · 1 publisher
- Answering one hardcoded address gives you root on 20+ Zbtlink router models
Build · August 31, 2026 · 1 publisher
- Two Nim implants shipped inside a US-branded router VulnCheck bought on Amazon
Product · August 29, 2026 · 1 publisher
- An all-zero MAC address bypasses the root command check in ZBT-derived white-label routers
Build · August 28, 2026 · 2 publishers
- ZBT router firmware ships two factory implants that beacon out on UDP/10000
Security · August 28, 2026 · 1 publisher
- Most of 19 audited MCP servers keep their context-injection surfaces out of the docs
Product · August 28, 2026 · 1 publisher
- Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink
Build · August 27, 2026 · 1 publisher