CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 62%
- Investor
- Investor 3%
Reality
- Evidence79
- Adoption42
- Hype gap+14
- Incentives67
- Confidence70
CISA's Malcolm before v26.06.0 lets an attacker with no account run script in an analyst's session through one crafted link. Four other flaws in the same advisory need a login, and CISA's fix for all five is the September 2026 release.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives30
- Confidence60
Microsoft will allow only scripts from its own CDN domains during Entra ID browser sign-ins under a Content Security Policy enforced from mid-October 2026. Browser extensions and tools that inject code into the sign-in page will stop working as the rollout completes in late October.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence70
Google's PageBreak agent confirmed over 500 XSS flaws in ordinary Google web apps and two in hundreds built on its hardened frameworks. The gap supports building defences into frameworks, and the agent that measured it had more inside access than an outside attacker would.
Reality
- Evidence55
- Adoption20
- Hype gap+20
- Incentives65
- Confidence55
The release Zimbra rates High severity closes a command injection in SNMP monitoring plus four Classic Web Client scripting bugs. Sites that acted on the June advisory still have work queued.
Publishers:blog.zimbra.com · wiki.zimbra.com
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
ExPatch says Telegram Desktop wrote bot button text into HTML chat exports without escaping it from March 2024 until a July fix, and updating the app leaves every file the earlier builds wrote unchanged on disk.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence72
GitHub patched CVE-2026-77987, a GitHub Enterprise Server flaw that let an unauthenticated attacker read instance secrets by timing notebook viewer responses. The secrets could yield remote code execution, and with private mode off the attack needed no login.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives40
- Confidence60
The strict-dynamic directive passes a script's trust to everything that script loads, and Ryan Chaplin of Raxis used that rule to get an XSS payload executing under a nonce-based policy that had blocked it.
Reality
- Evidence55
- Adoption30
- Hype gap+22
- Incentives62
- Confidence50
CVE-2026-58113 sits in the /auth/ redirect flow of Siemens Teamcenter. The attacker needs no credentials and no more than a link an engineer loads, and Siemens has shipped fixed builds for four release branches.
Reality
- Evidence74
- Adoption18
- Hype gap+8
- Incentives45
- Confidence66
A PortSwigger researcher turns a tag name into executed script by reading its lowercase copy from localName, a spot sanitizers and WAF signatures treat as inert. It reportedly works everywhere.
Publishers:portswigger.net
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence55
CVE-2026-71368 affects F-RevoCRM 7.3.0 through 8.0.3 and runs attacker script inside the CRM's own origin. JVN rates it Medium; the published remedy is a version bump.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+8
- Incentives28
- Confidence55