CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 66%
- Investor
- Investor 7%
Reality
- Evidence64
- Adoption70
- Hype gap+8
- Incentives
- Insufficient
- Confidence62
CERT-BUND has rated 36 CVEs in 16 contributed Drupal projects high risk, and Drupal core is not listed as affected. Each site team has to check the modules it has installed against 19 fixed releases and confirm that the code serving requests actually changed.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
DIVD says an attacker chained two unpublished Zammad bugs from an unauthenticated web session to root on its helpdesk host. Its claim that an autonomous AI agent did it is still a first-party assessment with no independent confirmation yet.
Reality
- Evidence55
- Adoption35
- Hype gap+30
- Incentives55
- Confidence55
Automated exploit attempts hit MediaWiki's External Data extension within a day of the 25 September disclosure of CVE-2026-100382, a CVSS 10.0 flaw. Upgrading to 3.7 closes the entry point but leaves behind any PHP shell an attacker already wrote to disk.
Reality
- Evidence50
- Adoption30
- Hype gap+10
- Incentives
- Insufficient
- Confidence45
Attackers using two NetScaler zero-days since early September left webshells that patching to 14.1-73.37 or 13.1-64.23 does not remove. Operators have to search every appliance for those traces, patched or not, and move OT remote access onto a jump host of its own.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
Gunra affiliates get in through two FortiOS and FortiProxy authentication bypasses, CVE-2024-55591 and CVE-2025-24472, says a 10 August 2026 advisory. Its fix for exposed RDP routes remote access through that same class of appliance, so the gateway has to be secured before RDP moves behind it.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence50
CVE-2026-65660, an exploited SharePoint Server code injection flaw rated 8.8, lets any user with a low-privilege login run code on the farm. Farms that admit vendors and contractors need to count who can sign in, alongside what faces the internet.
Reality
- Evidence45
- Adoption50
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
CERT-In bundled 14 ISC BIND CVEs, including cache-poisoning and zone-data modification flaws, under one HIGH rating on 21 September 2026. The batch suits one planned upgrade window, provided recursion and zone transfers are locked down until it runs.
Reality
- Evidence50
- Adoption80
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
Australia's ACSC told Fortinet users on 18 June to rotate all admin and VPN credentials immediately, the first of six steps in its alert. On hosted or co-managed gateways, each step first needs someone to settle who holds the accounts and who has to act.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
CERT Polska tied 17 Google Play apps and 852 Meta ads to one Android toll-fraud operation aimed at Polish users. Its billing code arrived after install from an object-storage bucket. The public ad records told analysts more than the store listing did.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence55
CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
ZoomEye's fingerprint index returned 736,893 matches for Mattermost on 23 September 2026, each a service identifying itself as the self-hosted chat server. Teams that self-host to keep chat internal also own the job of checking whether their server is among them.
Reality
- Evidence45
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence45
D-Link's DIR-822A firmware A_101 has two critical flaws, scored 9.9 and 10.0, with public proof-of-concept code and no fixed release yet. Until D-Link ships a build, owners are left isolating the router from untrusted networks or planning its replacement.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
CERT-In rates CVE-2026-76441 critical for letting unauthenticated remote attackers into restricted functions on Cisco email gateways 15.5 and earlier. The gateway inspects mail in both directions, so the fix belongs ahead of the next scheduled window, using the release Cisco's own advisory names.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Adobe's Connect 12.12 fixes CVE-2026-75682, a 9.9 SQL injection that reaches code execution from any low-privileged account. Connect deployments typically hand those accounts to students, contractors and partners, so the login barrier stops few attackers.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Adobe's September Connect patch fixes a CVSS 9.9 SQL injection that lets a low-privileged user run arbitrary code. Connect gives accounts to outside students and partners, so that bar is low enough to justify a separate 12.12 window even with no exploitation reported.
Reality
- Evidence55
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
ZoomEye ties CVE-2023-49105 to 152,655 hosts, exactly its ownCloud fingerprint count, four weeks after CISA listed the bug as exploited. The tag cannot tell patched from unpatched, so owners must check version and signing keys on each instance.
Reality
- Evidence50
- Adoption55
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
ACSC flagged credential attacks on Fortinet gateways with no CVE or version list, so scans counting 983,996 FortiGate assets are the sizing fallback. A certificate-key filter narrows the count to 254,801 but cannot show which admin logins face the internet.
Reality
- Evidence45
- Adoption65
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
Earlier coverage
- Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000
Build · September 21, 2026 · 1 publisher
- A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy
Build · September 20, 2026 · 1 publisher
- Firewalling RouterOS SSH to a management network removes MikroTrick's precondition
Build · September 19, 2026 · 1 publisher
- A ZoomEye port query returned 4,138,087 hosts on Kubernetes' conventional API port
Build · September 20, 2026 · 1 publisher
- Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue
Build · September 19, 2026 · 1 publisher
- A crafted request to one Cisco ISE API endpoint reaches root without a credential
Build · September 19, 2026 · 2 publishers
- ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts
Build · September 19, 2026 · 1 publisher
- ZoomEye's SonicWall SMA fingerprint returns 7 records against Shadowserver's several hundred
Build · September 19, 2026 · 1 publisher
- GitLab's commits API returns arbitrary files to an unauthenticated caller at CVSS 10.0
Build · September 19, 2026 · 1 publisher
- CISA gave federal SonicWall SMA 1000 operators three days to patch a pre-auth SSRF
Build · September 19, 2026 · 1 publisher
- A prohibited leading character in a RouterOS username rewrites the session's policy mask
Build · September 16, 2026 · 1 publisher
- Attackers are authenticating to unpatched Proxmox hosts with an arbitrary ticket value
Build · September 18, 2026 · 1 publisher
- A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API
Build · September 17, 2026 · 1 publisher
- An empty string in Artifactory's default join keys mints a platform admin token
Build · September 17, 2026 · 1 publisher
- LiteLLM's MCP endpoint answered a failed key check with an empty auth object
Build · September 16, 2026 · 1 publisher
- Sizing AA26-231A with ZoomEye returns 173 assets or 161,764, depending on the query
Build · September 16, 2026 · 1 publisher
- ZoomEye counts 202,686 Modbus and S7 ports that answer whoever can route to them
Build · September 16, 2026 · 1 publisher
- One slash in a Host header moves the path Starlette's middleware checks
Build · September 16, 2026 · 1 publisher
- CISA warns of rising attacks on internet-exposed water sector PLCs
Build · September 14, 2026 · 1 publisher
- Any Kestra API path ending in /configs skipped Basic Authentication
Build · September 15, 2026 · 1 publisher
- U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first
Security · August 24, 2026 · 1 publisher
- AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure
Build · August 19, 2026 · 2 publishers