CERT-BUND has rated 36 CVEs in 16 contributed Drupal projects high risk, and Drupal core is not listed as affected. Each site team has to check the modules it has installed against 19 fixed releases and confirm that the code serving requests actually changed.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 59%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence74
WordPress released 7.1.2 on 22 September 2026 to fix remote file inclusion flaw CVE-2026-87902, and the first exploit attempt was recorded the same day. The fix was back-ported to every maintained branch down to 4.7, so an exposed site has hours before scanners find it.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 68%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
The kernel fixed CVE-2026-80521 on August 6. Ubuntu has shipped nothing for 22.04, 24.04 or 26.04, including its AWS, Azure and GCP kernels, and DepthFirst's exploit for 26.04 went public on September 22.
Publishers:linuxjournal.com · thehackernews.com Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence68
CISA added Linux kernel flaw CVE-2026-53266 to its Known Exploited Vulnerabilities catalog on 18 September 2026. Affected versions and fixed builds come from each distribution's security notice, and a host is protected only once it reboots into the fixed kernel.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Adobe's September Connect patch fixes a CVSS 9.9 SQL injection that lets a low-privileged user run arbitrary code. Connect gives accounts to outside students and partners, so that bar is low enough to justify a separate 12.12 window even with no exploitation reported.
Reality
- Evidence55
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
The August 2026 Critical Security Patch Update carried 943 fixes across 23 product families, roughly 65% of Oracle's largest quarterly release. Monthly windows now need quarterly-sized capacity.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence65
WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.
Perspective Coverage
7 publishers
- Builder
- Builder 29%
- Operator
- Operator 62%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence70
CVE-2026-21962 reached CISA's exploited-vulnerabilities catalog on August 24 with an August 27 deadline. Honeypots logged attempts in March, and Oracle's fix has been available since January.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
Plex Media Server 1.43.3 and Desktop 1.115.0 fix flaws that still carry no CVE IDs and no description, which leaves anyone running the server on a NAS waiting on a package manager while the patched builds are already public.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 67%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
CVE-2026-73749 lets an unauthenticated attacker run privileged code on HPE Aruba switches by sending malformed packets to a daemon the bulletin never names. The oldest affected branch is already out of maintenance.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 67%
- Investor
- Investor 10%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence70
CVE-2026-20212 needs no credentials and returns root on ten Silicon One Nexus 9000 models. Cisco named no fixed release with the advisory. Remediation starts with a web lookup and an access list.
Perspective Coverage
4 publishers
- Builder
- Builder 15%
- Operator
- Operator 75%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Metabase published a critical fix on August 6, Mathspace's escalation process never surfaced it, and by the time the update went in on August 29 an intruder had been inside the reporting instance for 19 days and had already exported 1,079,819 records.
Perspective Coverage
4 publishers
- Builder
- Builder 36%
- Operator
- Operator 53%
- Investor
- Investor 11%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+5
- Incentives45
- Confidence74
CVE-2026-87491 gives a crafted web page code execution inside Chrome's sandbox. The fix only takes effect when the browser restarts, and long-running sessions carry that exposure until they do.
Perspective Coverage
5 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence70
PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 carry every fix from three emergency patch rounds plus two regression fixes, while GreyNoise and Blackpoint Cyber count at least 395 organizations already breached.
Publishers:papercut.com · thehackernews.com Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+8
- Incentives40
- Confidence72
Wiz observed multiple actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8, creating admin accounts, loading Groovy plugins and dropping a Rust backdoor.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 61%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption35
- Hype gap+10
- Incentives35
- Confidence70
Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.
Perspective Coverage
5 publishers
- Builder
- Builder 15%
- Operator
- Operator 74%
- Investor
- Investor 11%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence62
cPanel's September 14 advisory covers every LiteSpeed Web Server Enterprise build before 6.3.7. The fix shipped on September 11; because auto-update may lag, administrators have to force it onto servers by hand.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence60
Earlier coverage
- Chrome 154's 11 critical fixes: seven in webpage-reachable graphics code, four use-after-free bugs elsewhere
Security · September 24, 2026 · 2 publishers
- SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure
Security · September 24, 2026 · 1 publisher
- Canonical puts Ubuntu's one-week kernel fix in the -proposed pocket, ahead of certification testing
Security · September 23, 2026 · 1 publisher
- Always On VPN hangs on Windows 11 clients set to fall back between IKEv2 and SSTP
Security · September 23, 2026 · 1 publisher
- Unauthenticated requests to TCP/19009 run scripts on Check Point management servers
Build · September 22, 2026 · 1 publisher
- Siemens lists four SIMATIC AX Runtime Core Linux packages as affected by the Copy Fail flaw, with no fix available
Security · September 22, 2026 · 1 publisher
- Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server
Build · September 22, 2026 · 1 publisher
- Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000
Build · September 21, 2026 · 1 publisher
- Microsoft ships four manual patches for the Excel paste failure September's updates caused
Security · September 21, 2026 · 1 publisher
- Microsoft: September 2026 update may stop File History from writing backups on some systems
Security · September 21, 2026 · 1 publisher
- CISA updates KEV catalog page to reference new directive BOD 26-04
Security · September 20, 2026 · 1 publisher
- Utilities meet AI-assisted attackers on a once-a-quarter patch schedule
Product · September 20, 2026 · 1 publisher
- A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem
Build · September 19, 2026 · 1 publisher
- Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue
Build · September 19, 2026 · 1 publisher
- A crafted request to one Cisco ISE API endpoint reaches root without a credential
Build · September 19, 2026 · 2 publishers
- Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE
Security · September 19, 2026 · 1 publisher
- Microsoft's record 974 patches are one month inside a year that has logged 66,401 CVEs
Product · September 19, 2026 · 1 publisher
- A prohibited leading character in a RouterOS username rewrites the session's policy mask
Build · September 16, 2026 · 1 publisher
- Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass
Build · September 18, 2026 · 1 publisher
- WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme
Security · September 18, 2026 · 1 publisher
- ConnectWise patches a ScreenConnect client that can run transferred files without host consent
Security · September 18, 2026 · 1 publisher
- Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0
Security · September 18, 2026 · 1 publisher
- A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API
Build · September 17, 2026 · 1 publisher
- Microsoft's Excel paste fix reaches only the installer edition of Office 2016
Security · September 18, 2026 · 1 publisher
- Verizon's 43-day median patch time, against a five-day weaponization clock
Security · September 17, 2026 · 1 publisher
- Seven sandbox bypasses in the September Jenkins advisory all terminate in the same plugin
Build · September 17, 2026 · 1 publisher
- Delinea's 2 September hotfixes all land inside the new SAML impersonation range
Build · September 17, 2026 · 1 publisher
- Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day
Security · September 17, 2026 · 1 publisher
- CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session
Security · September 16, 2026 · 1 publisher
- Acronis bases its CVE-2026-87886 exploitation warning on one customer report
Security · September 16, 2026 · 4 publishers
- Deferring iOS 27 leaves about 56 of its 126 fixes out of the 26.7 build
Security · September 16, 2026 · 2 publishers
- Microsoft's extra hotpatching year for Windows Server 2022 covers only Azure Edition Datacenter
Security · September 16, 2026 · 1 publisher
- Half of Oracle's Fusion Middleware patches fix flaws reachable without a login
Security · September 16, 2026 · 2 publishers
- A third bypass of the same Defender flaw landed hours after Microsoft's second fix shipped
Build · September 15, 2026 · 2 publishers
- Siemens patches a Mendix SAML module that failed to validate response signatures
Security · September 15, 2026 · 1 publisher
- Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source
Leadership · September 15, 2026 · 1 publisher
- Confirmed exploitation now lands 40 days sooner after a CVE goes public
Product · September 15, 2026 · 1 publisher
- Apple bundles more than 120 security fixes into the iOS 27 upgrade
Product · September 14, 2026 · 1 publisher
- Rolling back the update that broke RDS also removes September's 9.8-rated RDS fix
Build · September 14, 2026 · 1 publisher
- Debian 13.7 folds 92 already-published advisories into the trixie installer
Security · September 14, 2026 · 1 publisher