Skip to content

Topic

Patch And Redeploy Latency

The operational gap between a fix shipping and estates applying it, sharpened when remediation requires rebuilding and redeploying an application.

Current stories

build1 publisher

CERT-BUND's high-risk Drupal advisory puts 36 CVEs in 16 contributed modules

CERT-BUND has rated 36 CVEs in 16 contributed Drupal projects high risk, and Drupal core is not listed as affected. Each site team has to check the modules it has installed against 19 fixed releases and confirm that the code serving requests actually changed.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence60
security4 publishers

GitLab patches sandbox escape that lets Duo agent users run commands on self-hosted AI Gateways

GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 59%
Investor
Investor 17%

Reality

Evidence78
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence74
build1 publisher

Exploit attempts for WordPress CVE-2026-87902 began the day 7.1.2 shipped

WordPress released 7.1.2 on 22 September 2026 to fix remote file inclusion flaw CVE-2026-87902, and the first exploit attempt was recorded the same day. The fix was back-ported to every maintained branch down to 4.7, so an exposed site has hours before scanners find it.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
security5 publishers

SharePoint flaw CVE-2026-65660 came under attack within days of Viettel's technical write-up

Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 68%
Investor
Investor 6%

Reality

Evidence74
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence70
security7 publishers

GitLab's 9.4 GraphQL bug went from patch to in-the-wild traffic in about two days

WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 62%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence70
security3 publishers

Plex tells NAS owners to hand-install a security release it will not describe

Plex Media Server 1.43.3 and Desktop 1.115.0 fix flaws that still carry no CVE IDs and no description, which leaves anyone running the server on a NAS waiting on a package manager while the patched builds are already public.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 67%
Investor
Investor 10%

Reality

Evidence55
Adoption40
Hype gap+20
Incentives
Insufficient
Confidence55
security3 publishers

Crafted packets execute code on ArubaOS-CX switches without a login

CVE-2026-73749 lets an unauthenticated attacker run privileged code on HPE Aruba switches by sending malformed packets to a daemon the bulletin never names. The oldest affected branch is already out of maintenance.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 67%
Investor
Investor 10%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence70
security4 publishers

A default bind on ten Silicon One Nexus 9000 switches exposes root over ports 43210 and 43211

CVE-2026-20212 needs no credentials and returns root on ten Silicon One Nexus 9000 models. Cisco named no fixed release with the advisory. Remediation starts with a web lookup and an access list.

Perspective Coverage

4 publishers
Builder
Builder 15%
Operator
Operator 75%
Investor
Investor 10%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence68
security4 publishers

Intruders reached Mathspace's unpatched Metabase four days after the fix shipped

Metabase published a critical fix on August 6, Mathspace's escalation process never surfaced it, and by the time the update went in on August 29 an intruder had been inside the reporting instance for 19 days and had already exported 1,079,819 records.

Perspective Coverage

4 publishers
Builder
Builder 36%
Operator
Operator 53%
Investor
Investor 11%

Reality

Evidence78
Adoption
Insufficient
Hype gap+5
Incentives45
Confidence74
security5 publishers

Attackers are exploiting a medium-rated V8 write in Chrome's 230-fix release

CVE-2026-87491 gives a crafted web page code execution inside Chrome's sandbox. The fix only takes effect when the browser restarts, and long-running sessions carry that exposure until they do.

Perspective Coverage

5 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence68
Adoption
Insufficient
Hype gap0
Incentives30
Confidence70
security4 publishers

Two Artifactory flaws turned an anonymous JWT into admin in under five minutes

Wiz observed multiple actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8, creating admin accounts, loading Groovy plugins and dropping a Rust backdoor.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence68
Adoption35
Hype gap+10
Incentives35
Confidence70
security5 publishers

Check Point patches two 9.8 VPN certificate flaws without naming what triggers them

Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.

Perspective Coverage

5 publishers
Builder
Builder 15%
Operator
Operator 74%
Investor
Investor 11%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence62

Earlier coverage

  1. Chrome 154's 11 critical fixes: seven in webpage-reachable graphics code, four use-after-free bugs elsewhere

    Security · September 24, 2026 · 2 publishers

  2. SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure

    Security · September 24, 2026 · 1 publisher

  3. Canonical puts Ubuntu's one-week kernel fix in the -proposed pocket, ahead of certification testing

    Security · September 23, 2026 · 1 publisher

  4. Always On VPN hangs on Windows 11 clients set to fall back between IKEv2 and SSTP

    Security · September 23, 2026 · 1 publisher

  5. Unauthenticated requests to TCP/19009 run scripts on Check Point management servers

    Build · September 22, 2026 · 1 publisher

  6. Siemens lists four SIMATIC AX Runtime Core Linux packages as affected by the Copy Fail flaw, with no fix available

    Security · September 22, 2026 · 1 publisher

  7. Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server

    Build · September 22, 2026 · 1 publisher

  8. Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000

    Build · September 21, 2026 · 1 publisher

  9. Microsoft ships four manual patches for the Excel paste failure September's updates caused

    Security · September 21, 2026 · 1 publisher

  10. Microsoft: September 2026 update may stop File History from writing backups on some systems

    Security · September 21, 2026 · 1 publisher

  11. CISA updates KEV catalog page to reference new directive BOD 26-04

    Security · September 20, 2026 · 1 publisher

  12. Utilities meet AI-assisted attackers on a once-a-quarter patch schedule

    Product · September 20, 2026 · 1 publisher

  13. A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem

    Build · September 19, 2026 · 1 publisher

  14. Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue

    Build · September 19, 2026 · 1 publisher

  15. A crafted request to one Cisco ISE API endpoint reaches root without a credential

    Build · September 19, 2026 · 2 publishers

  16. Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE

    Security · September 19, 2026 · 1 publisher

  17. Microsoft's record 974 patches are one month inside a year that has logged 66,401 CVEs

    Product · September 19, 2026 · 1 publisher

  18. A prohibited leading character in a RouterOS username rewrites the session's policy mask

    Build · September 16, 2026 · 1 publisher

  19. Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass

    Build · September 18, 2026 · 1 publisher

  20. WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme

    Security · September 18, 2026 · 1 publisher

  21. ConnectWise patches a ScreenConnect client that can run transferred files without host consent

    Security · September 18, 2026 · 1 publisher

  22. Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0

    Security · September 18, 2026 · 1 publisher

  23. A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API

    Build · September 17, 2026 · 1 publisher

  24. Microsoft's Excel paste fix reaches only the installer edition of Office 2016

    Security · September 18, 2026 · 1 publisher

  25. Verizon's 43-day median patch time, against a five-day weaponization clock

    Security · September 17, 2026 · 1 publisher

  26. Seven sandbox bypasses in the September Jenkins advisory all terminate in the same plugin

    Build · September 17, 2026 · 1 publisher

  27. Delinea's 2 September hotfixes all land inside the new SAML impersonation range

    Build · September 17, 2026 · 1 publisher

  28. Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day

    Security · September 17, 2026 · 1 publisher

  29. CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session

    Security · September 16, 2026 · 1 publisher

  30. Acronis bases its CVE-2026-87886 exploitation warning on one customer report

    Security · September 16, 2026 · 4 publishers

  31. Deferring iOS 27 leaves about 56 of its 126 fixes out of the 26.7 build

    Security · September 16, 2026 · 2 publishers

  32. Microsoft's extra hotpatching year for Windows Server 2022 covers only Azure Edition Datacenter

    Security · September 16, 2026 · 1 publisher

  33. Half of Oracle's Fusion Middleware patches fix flaws reachable without a login

    Security · September 16, 2026 · 2 publishers

  34. A third bypass of the same Defender flaw landed hours after Microsoft's second fix shipped

    Build · September 15, 2026 · 2 publishers

  35. Siemens patches a Mendix SAML module that failed to validate response signatures

    Security · September 15, 2026 · 1 publisher

  36. Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source

    Leadership · September 15, 2026 · 1 publisher

  37. Confirmed exploitation now lands 40 days sooner after a CVE goes public

    Product · September 15, 2026 · 1 publisher

  38. Apple bundles more than 120 security fixes into the iOS 27 upgrade

    Product · September 14, 2026 · 1 publisher

  39. Rolling back the update that broke RDS also removes September's 9.8-rated RDS fix

    Build · September 14, 2026 · 1 publisher

  40. Debian 13.7 folds 92 already-published advisories into the trixie installer

    Security · September 14, 2026 · 1 publisher