Skip to content

Published Science9 min read

Exposure and reachability were more informative risk indicators than severity scores in H1 2026 exploited CVEs

Two WordPress file-upload bugs drew more than 440,000 blocked exploit attempts; a Cisco switch flaw with the same 9.8 score drew none Cisco knows of. The bug class that hands over a developer's credentials scores 7.0.

17 publishersFor you

Written for builders.See today for builders

Artwork accompanying Exposure and reachability were more informative risk indicators than severity scores in H1 2026 exploited CVEs

What happened

  • Recorded Future's Insikt Group identified 215 actively exploited CVEs in H1 2026, up 34% from 161 in H1 2025.
  • Of the H1 2026 actively exploited set, 142 of the 146 vulnerabilities exploitable without prior authentication were also network-accessible, and 60 of the 82 remote code execution vulnerabilities combined network access with no authentication requirement.
  • Recorded Future said threat actors reused established post-exploitation playbooks across both newly disclosed and long-standing vulnerabilities, making exposure and impact more informative indicators of operational risk than vendor ranking or severity score alone.
  • Recorded Future said H1 2026 AI-enabled malware activity was concentrated in levels 1 to 3 of its AI Malware Maturity Model, with actors using AI to augment existing malware and intrusion workflows rather than conduct fully autonomous attacks, while AI-assisted research increased the volume of vulnerability reports.
  • CVE-2026-14894 (CVSS score 9.8) is a missing file type validation flaw in the WordPress plugin Super Forms allowing unauthenticated attackers to upload any file type, including executable PHP, leading to remote code execution; fixed in version 6.3.314.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

Same score, different denominator

Wordfence has blocked more than 250,000 exploit attempts against one WordPress file-upload flaw and more than 190,000 against a second [7], upward of 440,000 between them [8]. Cisco disclosed an unauthenticated remote code execution bug in ten Silicon One-based Nexus 9000 switches on September 2 and said it was not aware of any malicious use [11][12]. The Super Forms flaw and the Nexus flaw both carry a CVSS score of 9.8 [5][11].

The difference is in the preconditions rather than the impact. Attacking Super Forms means sending an unauthenticated HTTP POST to /wp-admin/admin-ajax.php carrying a base64-encoded PHP payload and an attacker-chosen filename, which lands a web shell that then uploads whatever comes next [10]. Attacking the Nexus flaw means reaching TCP port 43210 or 43211 on a switch in its default Layer 3 VRF, at which point crafted input to that service executes as root [11]. One target population is every site on the public web running a plugin. The other is a management-plane port on a data-center switch, and the set of people who can reach one is far smaller than the set who can send a POST.

Recorded Future's Insikt Group counted 215 actively exploited CVEs in the first half of 2026, up 34% from 161 in the same period of 2025 [1]. Within that set, 142 of the 146 bugs exploitable without prior authentication were also network-accessible, and 60 of the 82 remote code execution bugs combined network access with no authentication requirement [2]. Insikt's own reading is that exposure and impact tell you more about operational risk than vendor ranking or severity score alone [3].

The thing that pattern does not settle is how much of it is sensor placement. Wordfence sits in front of a large WordPress population and counts blocked requests [7]; no comparable public telemetry exists for the control plane of a Nexus 9000. "Not aware of any malicious use" [12] is a claim about what one vendor has observed, and absence of observation is weak evidence that can be revised backwards. Attempt counts have their own inflation: the Elementor Pro bug only works if the target site has at least one published Elementor page carrying a Form widget with a File Upload field [6], and roughly 190,000 attempts landed against it anyway [7]. Attackers spray without checking. So 440,000 blocked attempts is a measure of attacker interest, not of compromised sites. Interest is still the number that has a start date, July 14, and a single-day peak above 40,000 requests on August 18 [9].

What sits at the top of a severity-ordered queue

The Nexus advisory is also the most expensive item in the week. Cisco published no fixed-release table and directs customers to its Software Checker, offering an infrastructure access control list blocking the two ports and a temporary Live Protect shield as stopgaps [13]. The CVE Program record, which The Hacker News confirmed on September 3, lists 45 affected NX-OS releases from 10.3(1) through 10.6(3s) [15]. The shield, lp00031, is supported only on NX-OS 10.6(3) and, through a second package, on 10.6(3s) for two Smart Switches; it is unsupported on the Nexus 9804 and 9808, and installing it requires SSH, Telnet or NX-API access [14]. The IOS XR hardening release in the same disclosure bundles seven umbrella CVEs, two of them rated 9.8, affects all releases regardless of device configuration with no workaround, and comes with what Cisco says may be approximately 16 software maintenance updates for each release, with 26.2.2 and 26.3.1 the first fixed releases needing none [16].

Work that queue by score and the first thing you spend a change window on is the item with the largest remediation surface and the emptiest exploitation column. The access control list is the cheap half of that advisory, and it is cheap for the reason that matters: it changes reachability, which is the variable the exploitation data actually tracks [3][13].

Cisco's own framing sits awkwardly against its advisory. Russ Smoak, the company's vice president of information security, wrote in June that "the window between disclosure and exploitation has effectively closed", announcing the twice-monthly model that groups internally found bugs into umbrella CVEs [17]. That is a statement about the general case, and the specific case in front of customers on September 2 was a 9.8 with nothing observed [12].

Chrome is the counterweight. CVE-2026-85046 is a type confusion bug in V8 scored at 8.8, exploited in the wild, and fixed in 152.0.7977.82 alongside eleven other flaws [18]. It is the sixth actively exploited Chrome zero-day of the year [19]. Lower on the scale than either 9.8, higher on evidence than both. Salvatore Gulizia reported it on August 4 and was paid a $1,000 bounty [20], which prices responsible disclosure through Google's program and nothing else.

The class that carries no score at all

Manifold Security disclosed eight findings across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent then runs on the developer's machine, four of them unpatched at publication [21]. The sink is ordinary: core.fsmonitor is a Git performance setting whose value is a command Git runs to identify changed files, read from the repository's own .git/config, and any operation that refreshes the index, including git status and git diff, executes it [22]. Agents call exactly those commands in the background at startup to work out which branch they are on. The command runs as the user, outside the agent's sandbox, with no approval prompt [23]. On Claude Code and Hermes Agent it fires before the workspace-trust prompt is accepted, on Qwen Code before the user has authenticated, and on Grok Build on the first keystroke [25]. What that buys an attacker, per Manifold, is code execution as the developer, with their SSH keys, the cloud credentials in their environment, the tokens in their shell config, and every repository on disk [31].

One correction worth making precisely, because it decides whether this reaches you: cloning a hostile URL does nothing, and neither does fetch or pull. The repository has to arrive as files with its .git directory already inside, which a shared archive, a shared drive, a sync folder or a USB stick preserves [24]. This is a delivery problem, not a supply-chain-registry problem.

Fixes have shipped for goose, Claude Code and Cursor, while Hermes Agent, Qwen Code, Grok Build and a second path in Claude Code were still executing repository-supplied commands when Manifold retested on September 1 [26]. OpenAI published three CVEs of its own the same day for the identical class in Codex, credited to three unrelated research groups, and in the record for CVE-2026-19592 described a helper that runs outside the command sandbox and without a user-approval prompt, with the user's privileges [27]. Five of Manifold's reports came back as duplicates of findings other researchers had already filed, one on the same day [33]. Independent rediscovery from several directions is a better predictor of exploitation than any score, and there is almost no score here: GitHub assigned CVE-2026-72718 a CVSS 4.0 base of 7.0 in an advisory crediting Francisco Rosales, the only number any of these findings carries [28].

Nor is the sink new. Sonar reported it in April and noted that Claude Code 2.0.34 stopped running git status before the trust dialog; 2.0.34 shipped on November 5, 2025, and Manifold found the same startup behavior in 2.1.193, which shipped on June 25, 2026 [29]. Anthropic's own June advisory for CVE-2026-55607 identifies git fsmonitor execution during worktree operations [30]. A fix that consists of moving a subprocess later in the startup sequence is a fix the next refactor can undo, which is what appears to have happened. Manifold puts it plainly: the vulnerability is not in the model, it is in "the ordinary plumbing underneath, the subprocess an agent spawns at session startup to work out where it is" [34].

Scale here is the weakest part of the record. Claude Code ships over 77 million npm downloads a month, and across five projects Hermes carries over 237,000 GitHub stars, Claude Code more than 143,000, Goose over 54,000, Qwen Code 27,000 and Grok Build 26,000 [32]. Downloads count package fetches, including continuous integration; stars count attention. Neither counts machines that hold live production credentials and open folders from elsewhere, which is the population that matters and which nobody has measured.

Credentials are the objective, not the endpoint

GitGuardian found in early August that a recent Shai-Hulud infostealer worm variant scans 469 locations for credentials across developer environments, CI/CD tooling, cloud configurations and AI tool configs, where earlier variants checked 189 paths [35]. That is 280 additional locations, roughly two and a half times the original search radius [36]. The worm does not need to know which credential matters before collection; it sorts afterwards. Package publishing credentials are the ones that convert theft into distribution, which is why the recommendation in that analysis is to cut standing long-lived publishing tokens in favour of short-lived OIDC-verified authentication [37].

Put the two together and the developer workstation is the same machine in both stories: the agent flaw supplies execution as the user [31], and the harvesting class supplies the map of where authority is stored [35]. Neither step involves a 9.8.

What a perfect ExploitBench score does not rank

OpenAI's GPT-6 Astra scored 100% on ExploitBench, which evaluates a model's ability to turn known software vulnerabilities into working exploits, against 78.5% for GPT-5.6 Sol [38]. The company said days earlier that the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework [40], and the released version is restricted to secure code review and patching, refusing prompts about creating proof-of-concept exploits, with less restrictive safeguards planned through its Daybreak programme [39].

That benchmark does not measure the constraint on either campaign described above. The Super Forms payload is a base64 web shell in a form field [10]; the agent findings are four lines of Git config [22]. Recorded Future's read on the first half of the year is consistent with that: AI-enabled malware activity clustered at the lower levels of its maturity model, augmenting existing workflows rather than running autonomously, while AI-assisted research raised the volume of vulnerability reports [4].

Where a saturated ExploitBench would change the ranking is the column that currently reads "not aware of any malicious use" [12]. Turning a documented flaw in a switch service into crafted input that executes as root [11] is precisely the known-vulnerability-to-working-exploit task the benchmark scores [38]. My view, stated with its condition: order remediation by observed exploitation and by reachability, keep the access control list on ports 43210 and 43211 because it is the cheap intervention against the predictive variable [13], and treat the developer workstation as a credential store rather than an endpoint [31][35]. The condition is telemetry. That ranking is only as good as the sensors behind it, and the Nexus column is the one with no sensors.

What to watch

  • Any first report of observed exploitation against CVE-2026-20212 on TCP 43210 or 43211, which would move the Nexus item from inference to evidence and reorder the queue.
  • Whether Hermes Agent, Qwen Code and Grok Build ship fixes for the repository-config sink, and whether the second Claude Code path gets one on a release after 2.1.252.
  • Whether OpenAI's Daybreak rollout of less restrictive safeguards extends Astra to proof-of-concept validation, and what it does to the number of hands able to weaponise a disclosed switch flaw.

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Recorded Future's Insikt Group identified 215 actively exploited CVEs in H1 2026, up 34% from 161 in H1 2025.

    Reported
  2. [2]

    Of the H1 2026 actively exploited set, 142 of the 146 vulnerabilities exploitable without prior authentication were also network-accessible, and 60 of the 82 remote code execution vulnerabilities combined network access with no authentication requirement.

    Reported
  3. [3]

    Recorded Future said threat actors reused established post-exploitation playbooks across both newly disclosed and long-standing vulnerabilities, making exposure and impact more informative indicators of operational risk than vendor ranking or severity score alone.

    Reported

Sources & coverage · 17 publishers

The reporting this story was synthesized from, earliest first. Every link goes to the original.

  1. comparitech.comSep 2
    distressingly common
  2. en.wikipedia.orgSep 2
    CALEA system
  3. lumen.comSep 2
    Raptor Train
  4. lumen.comSep 2
    Lumen reports
  5. news.risky.bizSep 2
    decided to unleash
  6. justice.govSep 2
    have been extradited
  7. lumen.comSep 2
    who discovered it
  8. blog.bushidotoken.netSep 2
    Qilin ransomware-as-a-service group
  9. antiguanewsroom.comSep 3
    Antigua News Room
  10. whisper.securitySep 3
    Whisper Security
  11. aikido.devSep 3
    Aikido Security
  12. sharefoundation.infoSep 3
    SHARE Foundation
  13. biz.heraldcorp.comSep 3
    The Herald Business
  14. manifold.securitySep 3
    Manifold Security