Attackers are chaining two unpatched AhsayCBS flaws to run code as SYSTEM and plant webshells and XMRig miners, according to Huntress. Managed service providers are the main users of the console, so the hosts being hit are the ones that manage backup users and policies for clients.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence66
VulnCheck says a China-based actor began targeting vulnerable U.S. Rejetto HFS servers on October 1, exploiting CVE-2026-61500 to forge admin sessions. The fix shipped in July as version 3.2.1. Exposed instances that have not updated are reachable now.
Perspective Coverage
4 publishers
- Builder
- Builder 43%
- Operator
- Operator 47%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives50
- Confidence60
buildOne report1 publisher F5 and Cisco say attackers are exploiting flaws in BIG-IP APM and ISE, two of the three security products in Canada's September 2026 Cyber Centre alerts. Three alerts are too few to show a trend in attacker targeting, but the two exploited products need fixed software now.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence50
buildConfirmed2 publishers Attackers are chaining three self-hosted JFrog Artifactory flaws, one rated CVSS 9.8, to mint administrator tokens in under five minutes. Because every build resolves its packages through that one repository, it is as efficient to attack as to run.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence65
Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives
- Insufficient
- Confidence60
CVE-2026-5430 lets a token signed with an algorithm WSO2 does not support pass authentication as an administrator. watchTowr says tokens with administrator privileges baked in reached its honeypots on September 13.
Reality
- Evidence68
- Adoption20
- Hype gap+25
- Incentives45
- Confidence65
Orkes Conductor evaluates workflow expressions on a GraalVM context with the sandbox disabled, and Fortinet blocked about 1,300 exploitation attempts against CVE-2026-58138 over two days in September.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Arista says the pre-authentication flaw is already being used against on-premises orchestrators that issue certificates to their Edge devices, and the fixed build an operator needs may not exist for their release train yet.
Perspective Coverage
4 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence75
CVE-2026-76461 is one of three flaws confirmed under active attack in a single week. Revolut's customer records left by a different route, a request sent from an email address on a government agency's own domain.
Reality
- Evidence42
- Adoption62
- Hype gap+12
- Incentives58
- Confidence47
buildOne report1 publisher Cisco and CISA confirm CVE-2026-76460 is being exploited in the wild. The flaw sits in the ISE and ISE-PIC management API, scores 10.0, and affects vulnerable releases whatever optional features are turned on.
Reality
- Evidence62
- Adoption52
- Hype gap0
- Incentives30
- Confidence58
Fortinet switched off FortiCloud SSO worldwide on January 26 and turned it back on the next day with server-side changes. Devices already fully patched against the two 2025 SAML bypasses were compromised anyway.
Reality
- Evidence70
- Adoption66
- Hype gap−8
- Incentives40
- Confidence65
ConnectWise fixed CVE-2026-84869 in ScreenConnect 26.6.5 after Huntress traced a modified client dropping four VBScript files onto machines it held active sessions with. CISA gave federal agencies three days.
Reality
- Evidence64
- Adoption58
- Hype gap+12
- Incentives55
- Confidence62
CVE-2026-63077 was in CISA's KEV catalog on August 5. JetBrains dates the intrusion into its own Cadence environment from August 8 to August 24, and every secret that touched the service now needs rotating.
Reality
- Evidence62
- Adoption38
- Hype gap−8
- Incentives66
- Confidence64
PaperCut shipped emergency fixes for CVE-2026-81578 and CVE-2026-82078 on Thursday and Friday, and by the weekend Defused was watching honeypot intruders bypass authentication and read database tables instead of running code.
Reality
- Evidence62
- Adoption58
- Hype gap+18
- Incentives58
- Confidence60
buildOne report1 publisher CVE-2026-33824 gives unauthenticated attackers SYSTEM on Windows hosts answering IKEv2 on UDP/500 or 4500, and exploitation is confirmed. The fix shipped in April 2026.
Reality
- Evidence44
- Adoption38
- Hype gap+12
- Incentives41
- Confidence52