Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.
Perspective Coverage
4 publishers
- Builder
- Builder 21%
- Operator
- Operator 68%
- Investor
- Investor 11%
Reality
- Evidence80
- Adoption40
- Hype gap+5
- Incentives
- Insufficient
- Confidence75
AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence50
OpenAI has fixed a Critical Codex flaw in which a semicolon in a branch name leaked the agent's GitHub OAuth token on all four Codex surfaces. How far one leaked token could reach was set by its scope, which is chosen by whoever provisions the agent.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence60
CISA lists 37 VIVOTEK camera models open to CVE-2026-22755, a command injection bug that can give attackers remote command execution, potentially as root. Exploit code was public before the advisory, so the first job for owners is finding out which of their cameras are on the list.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
JFrog says a non-admin account on a Mac can reach root through Parallels Desktop's dispatcher service by planting a double quote in a folder name. The change that stops it is in version 27, and that release needs Apple silicon.
Reality
- Evidence60
- Adoption25
- Hype gap+12
- Incentives65
- Confidence55
Sonar's developer routed a custom resolver string straight into the arguments of a privileged networksetup call. He found it himself, in a pre-version-2 pass that produced twenty-six fixes, four of which he describes.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence45
CERT Polska says CVE-2026-73570 is already being exploited. Two of the three preconditions are configuration, not code, which makes reachability the control you can change now.
Reality
- Evidence58
- Adoption42
- Hype gap−8
- Incentives30
- Confidence55