CERT-BUND has rated 36 CVEs in 16 contributed Drupal projects high risk, and Drupal core is not listed as affected. Each site team has to check the modules it has installed against 19 fixed releases and confirm that the code serving requests actually changed.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
CVE-2026-65660, an exploited SharePoint Server code injection flaw rated 8.8, lets any user with a low-privilege login run code on the farm. Farms that admit vendors and contractors need to count who can sign in, alongside what faces the internet.
Reality
- Evidence45
- Adoption50
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
ZoomEye's fingerprint index returned 736,893 matches for Mattermost on 23 September 2026, each a service identifying itself as the self-hosted chat server. Teams that self-host to keep chat internal also own the job of checking whether their server is among them.
Reality
- Evidence45
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence45
ZoomEye ties CVE-2023-49105 to 152,655 hosts, exactly its ownCloud fingerprint count, four weeks after CISA listed the bug as exploited. The tag cannot tell patched from unpatched, so owners must check version and signing keys on each instance.
Reality
- Evidence50
- Adoption55
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
ACSC flagged credential attacks on Fortinet gateways with no CVE or version list, so scans counting 983,996 FortiGate assets are the sizing fallback. A certificate-key filter narrows the count to 254,801 but cannot show which admin logins face the internet.
Reality
- Evidence45
- Adoption65
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
SonicWall confirmed both SMA1000 flaws were exploited before disclosure, and CISA gave federal agencies three days to remediate. The lower-scored console bug is the step that reaches the operating system.
Reality
- Evidence55
- Adoption60
- Hype gap+8
- Incentives35
- Confidence48
Cisco Talos says three separate clusters, one sharing tooling with Sandworm, worked the same CVSS 10.0 bypass in Secure Firewall Management Center. The scope change in that vector reaches every firewall the console manages.
Reality
- Evidence72
- Adoption61
- Hype gap+8
- Incentives38
- Confidence68
CERT Polska confirmed exploitation of the MikroTrick chain on September 5, and the two bugs need no password and no private key, only a reachable SSH service, so the firewall rule scopes the risk before any build audit can.
Reality
- Evidence55
- Adoption70
- Hype gap−8
- Incentives40
- Confidence58
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
SonicWall shipped fixed builds on the day the two flaws were disclosed, so the September 5 deadline tested patch cadence. One measurement service's product fingerprint finds seven SMA appliances; a certificate match on the vendor name finds 2,295,225.
Reality
- Evidence55
- Adoption30
- Hype gap+12
- Incentives60
- Confidence48
Proxmox says multiple independent reports have attackers using PSA-2026-00043-1 to encrypt data for extortion. A port-8006 query returns 4,043,230 hosts; the Proxmox VE fingerprint returns 34,219, a factor of about 118 apart.
Reality
- Evidence55
- Adoption60
- Hype gap−12
- Incentives40
- Confidence52
The bypass needs no credential, and exploitation followed JFrog's 28 August disclosure by three days. ZoomEye's fingerprint puts 17,874 Artifactory services on the internet, though only self-hosted instances on affected versions are in scope.
Reality
- Evidence46
- Adoption60
- Hype gap+6
- Incentives55
- Confidence44
Five US agencies told PLC owners that scanners are finding exposed Siemens S7 controllers. ZoomEye puts that surface at 173 assets by product fingerprint, or 161,764 by open port.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
The bypass is a suffix match inside Kestra's AuthenticationFilter, and the vendor fix pins the check to /api/v1/configs exactly. The two ZoomEye queries that count exposed instances disagree by nearly a factor of two.
Reality
- Evidence55
- Adoption28
- Hype gap−12
- Incentives35
- Confidence52
SPEAKINGSTONE and DARKLANTERN both hand unauthenticated attackers root on ZBT-built hardware, and because neither advisory names a fixed firmware release, the remedy for an affected model is replacing it.
Reality
- Evidence64
- Adoption38
- Hype gap+12
- Incentives72
- Confidence62