Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
Attackers using two NetScaler zero-days since early September left webshells that patching to 14.1-73.37 or 13.1-64.23 does not remove. Operators have to search every appliance for those traces, patched or not, and move OT remote access onto a jump host of its own.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
Attackers are chaining three self-hosted JFrog Artifactory flaws, one rated CVSS 9.8, to mint administrator tokens in under five minutes. Because every build resolves its packages through that one repository, it is as efficient to attack as to run.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence65
Citrix has patched eight NetScaler flaws, including two zero-days scored 9.5 that CISA says attackers are exploiting globally. The safest response costs a planned outage of remote access now and months of monitoring afterwards.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
watchTowr says attackers exploited CVE-2026-88771, a pre-auth command injection in default-config Citrix NetScaler, before any fix existed. Upgrading to 14.1-73.37 or 13.1-64.23 closes the hole, though a gateway exposed in that window may already have been used.
Publishers:labs.watchtowr.com
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
Publishers:dev.to · thestack.technology · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 73%
- Investor
- Investor 12%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence60
Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 68%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
A researcher published a GeoServer SQL injection on 12 August 2026 and watchTowr says probing started within hours. With no fix shipped, access control is the only lever available.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 63%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption55
- Hype gap+20
- Incentives35
- Confidence70
WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.
Perspective Coverage
7 publishers
- Builder
- Builder 29%
- Operator
- Operator 62%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence70
Kiteworks told customers worldwide to power off its file-sharing servers for six hours on September 26 after a federal warning of a possible attack. Servers with no internet exposure are included, so being on release 9.5.1 with every known fix does not by itself clear a customer.
Perspective Coverage
5 publishers
- Builder
- Builder 18%
- Operator
- Operator 73%
- Investor
- Investor 9%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence62
Five US agencies report attackers scanning for exposed S7 PLCs and using a public library to read and write data blocks. The mitigation list reads like a commissioning checklist.
Publishers:sans.org · scworld.com Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+40
- Incentives
- Insufficient
- Confidence60
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Perspective Coverage
7 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption50
- Hype gap−40
- Incentives
- Insufficient
- Confidence74
Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 60%
- Investor
- Investor 13%
Reality
- Evidence85
- Adoption70
- Hype gap−10
- Incentives40
- Confidence78
CVE-2026-82329 is reported as a pre-auth authentication bypass in JFrog Artifactory's Access microservice, and it reaches every dependency your builds pull from the platform. One publisher, no vendor advisory.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 63%
- Investor
- Investor 9%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence64
SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.
Perspective Coverage
13 publishers
- Builder
- Builder 24%
- Operator
- Operator 63%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption30
- Hype gap+15
- Incentives55
- Confidence68
The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.
Publishers:dev.to · docs.gitlab.com · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 73%
- Investor
- Investor 5%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence74
Earlier coverage
- Two Artifactory flaws turned an anonymous JWT into admin in under five minutes
Security · September 11, 2026 · 4 publishers
- CISA sets a September 13 deadline for the MikroTrick RouterOS chain
Security · September 12, 2026 · 13 publishers
- Forged admin JWTs are landing on WSO2 API Manager four months after the fix shipped
Security · September 16, 2026 · 2 publishers
- Attackers began probing WSO2's JWT bypass 133 days after the fixes went out
Build · September 17, 2026 · 2 publishers
- Artifactory's access layer trusted an empty join key in a default install
Build · September 19, 2026 · 1 publisher
- F5 fixes CVE-2026-94127 by capping the Authorization header at 16,640 bytes
Security · September 23, 2026 · 1 publisher
- N-able's fourth hotfix is the one that closes the N-central code injection
Build · September 19, 2026 · 1 publisher
- An empty string in Artifactory's default join keys mints a platform admin token
Build · September 17, 2026 · 1 publisher
- Scanning for CVE-2026-82329 hit 406,000 attempts five days after JFrog disclosed it
Security · September 17, 2026 · 3 publishers
- Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest
Build · September 14, 2026 · 1 publisher
- Attackers chain two PaperCut flaws to lift LDAP and SAM credentials from school print servers
Security · September 5, 2026 · 4 publishers
- A manipulated Bearer header escalates privileges in Cleo Harmony through 5.8.1.10
Security · September 3, 2026 · 2 publishers
- Artifactory's default configuration hands admin tokens to unauthenticated callers
Build · September 1, 2026 · 1 publisher
- A NetScaler web shell survives the patch that closes CVE-2026-8452
Build · August 29, 2026 · 1 publisher
- GeoServer's jsonArrayContains filter is being probed at scale, with no patch and no CVE
Build · August 14, 2026 · 1 publisher