CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 66%
- Investor
- Investor 7%
Reality
- Evidence64
- Adoption70
- Hype gap+8
- Incentives
- Insufficient
- Confidence62
Automated exploit attempts hit MediaWiki's External Data extension within a day of the 25 September disclosure of CVE-2026-100382, a CVSS 10.0 flaw. Upgrading to 3.7 closes the entry point but leaves behind any PHP shell an attacker already wrote to disk.
Reality
- Evidence50
- Adoption30
- Hype gap+10
- Incentives
- Insufficient
- Confidence45
Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.
Reality
- Evidence70
- Adoption72
- Hype gap0
- Incentives50
- Confidence65
CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 62%
- Investor
- Investor 3%
Reality
- Evidence79
- Adoption42
- Hype gap+14
- Incentives67
- Confidence70
Kiteworks fixed CVE-2026-54154, a CVSS 10.0 flaw letting unauthenticated attackers run code on its Email Protection Gateway, in version 9.4.1. Other EPG flaws disclosed the same day are fixed only in 9.5.1, so internet-facing gateways should go straight to that release.
Reality
- Evidence72
- Adoption35
- Hype gap+5
- Incentives
- Insufficient
- Confidence68
LiteLLM's MCP test endpoints let any valid proxy key run arbitrary commands on the gateway, rated CVSS 8.8. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 8, 2026, confirming exploitation in the wild.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
OpenBao fixed a four-bug chain in 2.6.3 and 2.7.0 that lets unauthenticated attackers seize servers with a Raft snapshot policy set. A dev.to post says HashiCorp Vault has no fix yet, so Vault operators have to close network paths to the API themselves.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+45
- Incentives
- Insufficient
- Confidence25
Unsloth fixed Studio in version 2026.6.9 after Pillar Security showed that reading a malicious model's config.json could run an attacker's Python code. Unsloth disputed parts of the finding and declined to publish an advisory, so no CVE was assigned.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence52
CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence68
The affected releases stretch back to Next.js 13.4, and for Windows self-hosters the only remedy Vercel offers is the version bump. The AVIF bug shipped in the same release at least has a config gate.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence58
Rapid7 scored it 9.9 and Gogs shipped 0.14.3 on June 7, 2026. The reason it rates that high is configuration: open registration and unlimited repository creation let a stranger own the repo they attack from.
Publishers:rapid7.com · runzero.com
Reality
- Evidence86
- Adoption50
- Hype gap+8
- Incentives72
- Confidence70
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
Olivier Laflamme walked an unpaired Bluetooth write up to root on the G1 EDU's Locomotion PC by way of a Unitree cloud API that decrypted key material for any logged-in account. Unitree fixed that check in July, but no patched firmware has been named.
Perspective Coverage
4 publishers
- Builder
- Builder 38%
- Operator
- Operator 50%
- Investor
- Investor 12%
Reality
- Evidence72
- Adoption38
- Hype gap+8
- Incentives45
- Confidence62
Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.
Perspective Coverage
3 publishers
- Builder
- Builder 40%
- Operator
- Operator 52%
- Investor
- Investor 8%
Reality
- Evidence68
- Adoption45
- Hype gap+15
- Incentives30
- Confidence70
CVE-2026-73749 lets an unauthenticated attacker run privileged code on HPE Aruba switches by sending malformed packets to a daemon the bulletin never names. The oldest affected branch is already out of maintenance.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 67%
- Investor
- Investor 10%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence70
CVE-2026-6471 has sat in every PostgreSQL release since 9.4 shipped in 2014. Cyera says the plugin name in a replication slot request reaches dlopen() unvalidated, which makes the fix a privilege audit as much as a patch.
Perspective Coverage
4 publishers
- Builder
- Builder 32%
- Operator
- Operator 59%
- Investor
- Investor 9%
Reality
- Evidence74
- Adoption55
- Hype gap+24
- Incentives58
- Confidence72
Progress fixed the chain on July 8, and TantoSec published the method plus a working tool on September 7, so the exposed installs are the ones where an administrator set the explicit upload encryption key Telerik recommends.
Publishers:tantosec.com · thehackernews.com Reality
- Evidence82
- Adoption15
- Hype gap+5
- Incentives60
- Confidence68
Sysdig's threat research team watched one operator work a marimo notebook host for nine hours with hand-written scripts, and the eight-second jump to a bastion host at the end ran on tooling already staged on disk.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 60%
- Investor
- Investor 7%
Reality
- Evidence68
- Adoption66
- Hype gap+8
- Incentives72
- Confidence70
StellarWP split the fix across two releases, so a WordPress site updated on August 25 stayed open to CVE-2026-78006 until 6.17.4.1 shipped on September 10. Version data puts about 240,000 installs behind both bugs.
Reality
- Evidence62
- Adoption60
- Hype gap+20
- Incentives40
- Confidence60
SolarWinds fixed two pre-authentication RCEs in Observability Self-Hosted 2026.2.3, rated CVSS 9.8 and 8.8. Operators have no public detail to check either flaw's precondition against, so for most teams upgrading is the quickest way to know where a monitoring server stands.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Earlier coverage
- Click2Shell runs attacker PHP on WordPress servers after a single administrator click
Security · September 21, 2026 · 2 publishers
- SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure
Security · September 24, 2026 · 1 publisher
- Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server
Build · September 22, 2026 · 1 publisher
- A fake branch name defeats the commit pin four AI coding agents rely on
Product · September 21, 2026 · 1 publisher
- Plugin4Shell turned a pinned commit into attacker code in four AI coding agents
Leadership · September 20, 2026 · 1 publisher
- Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue
Build · September 19, 2026 · 1 publisher
- Conductor OSS runs a stranger's inline JavaScript as root in its default container
Build · September 18, 2026 · 1 publisher
- WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme
Security · September 18, 2026 · 1 publisher
- Semantic Kernel ran a model-controlled search filter through eval() at query time
Build · September 17, 2026 · 1 publisher
- A Fastjson RCE walks in through the annotation check, not the type blacklist
Build · September 16, 2026 · 1 publisher
- YARD's --load flag ran uploaded gem code inside RubyDoc.info's build workers
Build · September 15, 2026 · 1 publisher
- Adobe's out-of-band Magento hotfix lands after attackers installed backdoors disguised as kworker
Security · September 10, 2026 · 1 publisher
- StyleSmuggler runs its PHP inside Magento's failed-payment email renderer
Build · September 8, 2026 · 1 publisher
- Attacker PHP executes when Magento renders its failed-payment reminder email
Build · September 8, 2026 · 1 publisher
- StyleSmuggler turns a Magento payment-reminder email into unauthenticated code execution
Security · September 8, 2026 · 1 publisher
- CVE-2025-62593: A Ray Developer's Browser Is Now the Attack Surface
Security · August 19, 2026 · 1 publisher