Australia's ACSC told Fortinet users on 18 June to rotate all admin and VPN credentials immediately, the first of six steps in its alert. On hosted or co-managed gateways, each step first needs someone to settle who holds the accounts and who has to act.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence55
Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 73%
- Investor
- Investor 12%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence60
Fortinet says the Mirai-derived botnet bolts a SOCKS5 relay onto compromised routers, cameras and Confluence hosts. Sellable proxy capacity changes what you hunt for.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 63%
- Investor
- Investor 12%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence65
ACSC flagged credential attacks on Fortinet gateways with no CVE or version list, so scans counting 983,996 FortiGate assets are the sizing fallback. A certificate-key filter narrows the count to 254,801 but cannot show which admin logins face the internet.
Reality
- Evidence45
- Adoption65
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.
Perspective Coverage
13 publishers
- Builder
- Builder 24%
- Operator
- Operator 63%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption30
- Hype gap+15
- Incentives55
- Confidence68
CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.
Perspective Coverage
4 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
watchTowr diffed two builds of BIG-IP's tmm64 and found that F5's fix for CVE-2026-94127 is a single length test on the Authorization header, a field parsed at the edge. watchTowr says attackers were already exploiting it.
Publishers:labs.watchtowr.com
Reality
- Evidence62
- Adoption20
- Hype gap+18
- Incentives55
- Confidence55
The DOJ and FBI pulled down two platforms a commentary attributes to Chinese state-sponsored operators. The same piece argues the routers and gateways recruited into those relays are still deployed and still weakly governed.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+35
- Incentives80
- Confidence55
The Hanover, New Hampshire company says more than $7 million of Space Force, Navy and DARPA work is already signed, more than double what its investors just put in, and the single-chip technology behind it dates to a 2016 startup called WebSensing.
Reality
- Evidence34
- Adoption27
- Hype gap+21
- Incentives72
- Confidence44
BOD 26-04 revoked the federal CVSS requirement on June 10. The two decision fields CISA promised, automatability and technical impact, go out through Vulnrichment; the KEV feed does not carry them, so every defender does the join.
Reality
- Evidence55
- Adoption30
- Hype gap+12
- Incentives45
- Confidence58
The city's report on its 2025 Flock trial says data went to outside law enforcement agencies while both the agreement and the company said sharing was off, and hackers separately pulled people and bicycle detections off a camera.
Reality
- Evidence36
- Adoption52
- Hype gap+18
- Incentives58
- Confidence42
Hackers pulled a Flock camera off a roadway and copied its storage. The key to the encrypted media sat on an unencrypted partition, and the recovered logs show the device detects people and bicycles as well as plates.
Reality
- Evidence64
- Adoption76
- Hype gap+10
- Incentives72
- Confidence60
CVE-2026-76461 is under active exploitation, hits every physical and virtual Secure Email Gateway whatever its configuration, and has no workaround. CISA gave federal civilian agencies until September 17 to install the fixed builds.
Reality
- Evidence72
- Adoption55
- Hype gap0
- Incentives60
- Confidence68
Root Evidence rebuilt the exploitation clock on vendor advisory dates rather than NVD publication, and Jeremiah Grossman's team reads the resulting four-month median as a measure of inventory that stopped being maintained.
Publishers:cyrilsimonnet.substack.com
Reality
- Evidence62
- Adoption20
- Hype gap+12
- Incentives58
- Confidence55
Black Lotus Labs assesses the botnet as Chinese state work under Flax Typhoon, assembled from SOHO routers, NVRs, NAS boxes and IP cameras whose 17-day average lifespan makes the infrastructure disposable by design.
Publishers:lumen.com
Reality
- Evidence58
- Adoption62
- Hype gap+15
- Incentives68
- Confidence57