Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence50
Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
CISA added Citrix NetScaler flaw CVE-2026-88779 to its exploited-vulnerabilities catalog on 4 October, citing evidence of active exploitation. For anyone running the appliance, confirmed use by attackers puts this fix ahead of work ranked by severity score alone.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence70
Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
Cisco confirmed attackers are exploiting CVE-2026-76460, a CVSS 10.0 flaw giving unauthenticated root on Identity Services Engine. ISE decides which devices join the network, so a rooted node hands over every access decision and the device credentials it stores.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Two exploited Citrix NetScaler zero-days and a CVSS 9.8 Cisco SD-WAN Manager flaw top a weekly DACH OT risk bulletin. For many operators, both products enforce segmentation into OT, so an attacker who takes one over is standing in front of the control systems.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence45
Attackers chained two self-hosted JFrog Artifactory flaws, both patched more than a month before exploitation, to take admin and install backdoor plugins. Either fix breaks the chain, yet on the published tables only release 7.133.28 closes both.
Reality
- Evidence66
- Adoption70
- Hype gap−6
- Incentives45
- Confidence55
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence55
LiteLLM's MCP test endpoints let any valid proxy key run arbitrary commands on the gateway, rated CVSS 8.8. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 8, 2026, confirming exploitation in the wild.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
CISA added Apple's CoreGraphics out-of-bounds write, CVE-2026-86950, to its KEV catalog with an October 2 deadline for federal agencies. Apple's iOS advisory is dated September 28, so agencies have four days to move iPhones, iPads and Macs onto patched builds.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence58
Citrix has patched eight NetScaler flaws, including two zero-days scored 9.5 that CISA says attackers are exploiting globally. The safest response costs a planned outage of remote access now and months of monitoring afterwards.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
Exposure to CVE-2026-19490, a CVSS 9.8 NetScaler bypass CISA lists as exploited, depends on each appliance's exact build and SAML setup. Older builds qualify with any Gateway or AAA virtual server, while later builds short of the fix also need a SAML action configured.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence55
CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Shell says it is investigating after Clop claimed 89GB of engineering data. It is one of 43 names the gang tied to a single flaw in internet-exposed PTC Windchill and FlexPLM.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence58
CVE-2025-62593 carries a CVSS 9.4 and a federal remediation deadline of August 20, 2026. The unauthenticated endpoints behind it are a design decision, not an oversight.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 60%
- Investor
- Investor 6%
Reality
- Evidence68
- Adoption50
- Hype gap+15
- Incentives35
- Confidence66
watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 63%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption55
- Hype gap+20
- Incentives35
- Confidence70
Suspected Cl0p operators chain a FlexPLM WSDL disclosure to CVE-2026-12569 for unauthenticated code execution. No encryption stage means ransomware-tuned detections stay silent.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 57%
- Investor
- Investor 18%
Reality
- Evidence68
- Adoption55
- Hype gap−10
- Incentives60
- Confidence62
CVE-2026-21962 reached CISA's exploited-vulnerabilities catalog on August 24 with an August 27 deadline. Honeypots logged attempts in March, and Oracle's fix has been available since January.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
CVE-2026-60004 turns Gitea's diffpatch API into remote code execution for anyone who can register an account. The fix is three steps, and CISA's federal deadline is August 28, 2026.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Earlier coverage
- Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.
Security · August 26, 2026 · 7 publishers
- ZoomEye's CVE-2023-49105 count matches its entire ownCloud fingerprint at 152,655 hosts
Build · September 26, 2026 · 1 publisher
- Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers
Security · August 28, 2026 · 7 publishers
- CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass
Security · August 29, 2026 · 4 publishers
- Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process
Security · August 28, 2026 · 10 publishers
- CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock
Security · September 3, 2026 · 13 publishers
- CVE-2026-86218 gives unauthenticated attackers code execution on N-able N-central consoles
Security · September 7, 2026 · 7 publishers
- CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later
Security · September 10, 2026 · 2 publishers
- A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV
Security · September 10, 2026 · 4 publishers
- Cisco's own July 23 log indicator predates its August date for FMC exploitation
Security · September 9, 2026 · 6 publishers
- CISA sets a September 13 deadline for the MikroTrick RouterOS chain
Security · September 12, 2026 · 13 publishers
- CISA put N-able's pre-auth N-central RCE on KEV three days after the hotfix shipped
Security · September 16, 2026 · 2 publishers
- Artifactory's access layer trusted an empty join key in a default install
Build · September 19, 2026 · 1 publisher
- Check Point patches a Security Management zero-day it saw exploited on July 23
Security · September 22, 2026 · 6 publishers
- Eclypsium finds the month's exploited infrastructure flaws again in the management consoles
Security · September 23, 2026 · 1 publisher
- Red Hat's interim mitigations cover two of the three kernel flaws CISA lists as exploited
Build · September 22, 2026 · 1 publisher
- CISA gives agencies one business day to patch three exploited Linux kernel flaws
Security · September 21, 2026 · 6 publishers
- ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts
Build · September 19, 2026 · 1 publisher
- A crafted style attribute in Magento's payment-failure reminder executes as PHP
Build · September 19, 2026 · 1 publisher
- LiteLLM's MCP endpoint answered a failed key check with an empty auth object
Build · September 16, 2026 · 1 publisher
- CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session
Security · September 16, 2026 · 1 publisher
- CISA gives federal agencies three days to fix the ScreenConnect flaw already under attack
Security · September 16, 2026 · 1 publisher
- A process created at boot lets one HTTP request take root on Cisco's firewall console
Build · September 14, 2026 · 1 publisher
- Metasploit packages the SonicWall SMA1000 root chain into one module
Security · September 11, 2026 · 1 publisher
- Attackers lifted the cluster join key out of self-hosted Artifactory
Build · September 11, 2026 · 1 publisher
- Attackers have been planting web shells on Magento stores since September 4
Security · September 10, 2026 · 2 publishers
- Gitea's unpatched older branches force migration to 1.27.x as CISA flags active exploitation
Leadership · September 5, 2026 · 1 publisher
- CISA's exploited-vulnerability catalog now reaches the LLM gateway
Build · September 2, 2026 · 1 publisher
- CISA asks buyers to make eliminated vulnerability classes a contract condition
Security · September 1, 2026 · 1 publisher
- A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories
Security · August 27, 2026 · 1 publisher
- CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal
Security · August 21, 2026 · 1 publisher
- CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN
Security · August 21, 2026 · 1 publisher
- MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list
Build · August 20, 2026 · 1 publisher
- CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines
Product · August 18, 2026 · 1 publisher