Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
Cisco says attackers are exploiting CVE-2026-76504, a 9.8 CVSS flaw that lets anyone reaching SD-WAN Manager's API act as admin with no credentials. Managers patched for the May and June flaws still need the new releases, because those fixes predate this one.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Attackers are chaining three self-hosted JFrog Artifactory flaws, one rated CVSS 9.8, to mint administrator tokens in under five minutes. Because every build resolves its packages through that one repository, it is as efficient to attack as to run.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence65
Exposure to CVE-2026-19490, a CVSS 9.8 NetScaler bypass CISA lists as exploited, depends on each appliance's exact build and SAML setup. Older builds qualify with any Gateway or AAA virtual server, while later builds short of the fix also need a SAML action configured.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence55
Unauthenticated attackers can drop PHP onto WordPress sites running Forminator 1.56.1 or earlier. The install base is 600,000; the exposed subset depends on how the forms were built.
Reality
- Evidence72
- Adoption45
- Hype gap+30
- Incentives
- Insufficient
- Confidence68
CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.
Perspective Coverage
5 publishers
- Builder
- Builder 14%
- Operator
- Operator 73%
- Investor
- Investor 13%
Reality
- Evidence78
- Adoption62
- Hype gap+10
- Incentives38
- Confidence75
Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.
Perspective Coverage
5 publishers
- Builder
- Builder 32%
- Operator
- Operator 56%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 60%
- Investor
- Investor 13%
Reality
- Evidence85
- Adoption70
- Hype gap−10
- Incentives40
- Confidence78
CVE-2026-82329 is reported as a pre-auth authentication bypass in JFrog Artifactory's Access microservice, and it reaches every dependency your builds pull from the platform. One publisher, no vendor advisory.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 63%
- Investor
- Investor 9%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence64
CVE-2026-5430 lets a token signed with an algorithm WSO2 does not support pass authentication as an administrator. watchTowr says tokens with administrator privileges baked in reached its honeypots on September 13.
Reality
- Evidence68
- Adoption20
- Hype gap+25
- Incentives45
- Confidence65
A default self-hosted Artifactory install trusted an empty string as a join key. Because JFrog supports non-expiring tokens, an upgrade can leave a forged administrator token valid.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
The five options that decide which private key opens a client certificate lived in a struct libcurl's connection-reuse check never reads, so two handles sharing a pool could share one authenticated connection. Commit 7541ae5 moves them.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives22
- Confidence55
CVE-2026-18963 sits in the Keycloak reset-credentials flow that Siemens embeds in Industrial Edge Management. Siemens closed its own Cloud service on September 2, and owners of self-hosted IEM Pro and IEM Virtual patch or block the path themselves.
Reality
- Evidence72
- Adoption35
- Hype gap−10
- Incentives55
- Confidence70
Cisco's PSIRT says CVE-2026-76460 is being exploited, and the company has published no workaround, so the fix is a branch-specific patch. ISE 3.0 is past End of Software Maintenance and gets a migration.
Publishers:cisco.com · dev.to Reality
- Evidence72
- Adoption42
- Hype gap+6
- Incentives38
- Confidence68
Cisco and CISA confirm CVE-2026-76460 is being exploited in the wild. The flaw sits in the ISE and ISE-PIC management API, scores 10.0, and affects vulnerable releases whatever optional features are turned on.
Reality
- Evidence62
- Adoption52
- Hype gap0
- Incentives30
- Confidence58
Proxmox says multiple independent reports have attackers using PSA-2026-00043-1 to encrypt data for extortion. A port-8006 query returns 4,043,230 hosts; the Proxmox VE fingerprint returns 34,219, a factor of about 118 apart.
Reality
- Evidence55
- Adoption60
- Hype gap−12
- Incentives40
- Confidence52
Cisco disclosed an unauthenticated authorization bypass in the Identity Services Engine REST API on 16 September. Because the request never presents a credential, it leaves just one trace: a privileged API call that succeeded.
Reality
- Evidence45
- Adoption30
- Hype gap+18
- Incentives52
- Confidence58
The bypass needs no credential, and exploitation followed JFrog's 28 August disclosure by three days. ZoomEye's fingerprint puts 17,874 Artifactory services on the internet, though only self-hosted instances on affected versions are in scope.
Reality
- Evidence46
- Adoption60
- Hype gap+6
- Incentives55
- Confidence44
CVE-2026-15688 lets someone running the software locally get past a block password and edit the loaded module in memory. Mitsubishi Electric's remedy is a new build plus a security setting applied project by project.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap0
- Incentives55
- Confidence66
Earlier coverage
- Delinea's 2 September hotfixes all land inside the new SAML impersonation range
Build · September 17, 2026 · 1 publisher
- CVE-2026-24858 let attackers log into Fortinet devices registered to other customers
Security · September 17, 2026 · 1 publisher
- LiteLLM's MCP endpoint answered a failed key check with an empty auth object
Build · September 16, 2026 · 1 publisher
- Any Kestra API path ending in /configs skipped Basic Authentication
Build · September 15, 2026 · 1 publisher
- mySCADA myPRO Manager takes privileged commands from anyone who can reach its API
Security · September 15, 2026 · 1 publisher
- Unauthenticated request pulls plaintext admin credentials off Digital Watchdog VMAX recorders
Security · September 15, 2026 · 1 publisher
- Attackers lifted the cluster join key out of self-hosted Artifactory
Build · September 11, 2026 · 1 publisher
- Two chained N-central bugs hand an unauthenticated caller a System administrator account
Security · September 8, 2026 · 1 publisher
- Anthropic says everyday infostealers are lifting live Claude sessions off victim machines
Security · September 4, 2026 · 1 publisher
- Exploit attempts hit NetScaler's August auth bypass 15 days after Citrix shipped the fix
Security · September 4, 2026 · 1 publisher
- A query string smuggled into the Host header makes Starlette skip authentication
Build · September 4, 2026 · 1 publisher
- Pillar chains a 9.1 SSRF to self-minted session IDs in Grafana's MCP server
Security · September 3, 2026 · 1 publisher
- Dovecot's 2.4 settings refactor drops the SQL escape its own passdb asked for
Build · September 2, 2026 · 1 publisher
- Hive's SAML validator hands out a session to any Bearer token you forge
Build · August 30, 2026 · 1 publisher
- Xiiaozet's LK100W lets an unauthenticated caller switch on its admin services
Security · August 27, 2026 · 1 publisher
- Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink
Build · August 27, 2026 · 1 publisher
- Apple patches a network-reachable Screen Sharing auth bypass in macOS Tahoe 26.6.1
Security · August 16, 2026 · 1 publisher
- Unauthenticated root on macOS Screen Sharing: CVE-2026-65400 is already dropping miners
Build · August 14, 2026 · 1 publisher