Transluce counted 13 hack attempts, SQL injection probes among them, in 899 AI agent requests to Library and Archives Canada's search service in May and June. Public site operators absorb that traffic while the lab's attribution to OpenAI stays short of confident.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 47%
- Investor
- Investor 28%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence55
Fingerprint, who took data on over 18 million Poles from MyDr, stole Qbusoft's Medyc.pl patient database by SQL injection, Zaufana Trzecia Strona reports. Qbusoft is the second Polish medical-practice software vendor the actor has breached, and one Inowrocław clinic has had patient data taken in both leaks.
Publishers:zaufanatrzeciastrona.pl
Reality
- Evidence50
- Adoption30
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
CVE-2026-67401 lets an ordinary cPanel mail account escalate to root through a SQL injection in the EmailTrack delivery-log feature. cPanel disclosed the vulnerability class but has not published the vulnerable parameter or the query behind it.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence35
Transluce says AI agents sent 899 requests to Library and Archives Canada's search tool on two days in May and June, 13 of them potential attacks. The evidence surfaced months later in Portugal's web archive, so public search operators need logs that can tell an agent's lookups from its injection attempts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives40
- Confidence50
Qbusoft confirmed an attacker stole patient data from its Medyc clinic software through an SQL injection flaw that went unnoticed for about 17 days. It is the second Polish clinic-software supplier to lose ID numbers in weeks, after MyDr lost data on nearly 19 million people in August.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 54%
- Investor
- Investor 18%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence72
CISA says Toptech TMS7 and TopHAT 7.6.3 carry ten CVEs, one of which lets unauthenticated attackers export any database table they choose. Toptech told customers on July 20 that release 7.8 fixes them, so the sites at risk are those still on 7.6.3.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence68
Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives
- Insufficient
- Confidence60
Adobe's Connect 12.12 fixes CVE-2026-75682, a 9.9 SQL injection that reaches code execution from any low-privileged account. Connect deployments typically hand those accounts to students, contractors and partners, so the login barrier stops few attackers.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
A researcher published a GeoServer SQL injection on 12 August 2026 and watchTowr says probing started within hours. With no fix shipped, access control is the only lever available.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Adobe's September Connect patch fixes a CVSS 9.9 SQL injection that lets a low-privileged user run arbitrary code. Connect gives accounts to outside students and partners, so that bar is low enough to justify a separate 12.12 window even with no exploitation reported.
Reality
- Evidence55
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.
Perspective Coverage
13 publishers
- Builder
- Builder 24%
- Operator
- Operator 63%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption30
- Hype gap+15
- Incentives55
- Confidence68
For virtual appliances where exploitation is suspected, Cisco's advisory lists five actions before the box can be trusted again, one of which is installing fixed software. Owners of physical appliances are told to call TAC.
Publishers:cisco.com
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+6
- Incentives70
- Confidence62
Exploit-DB's entry for CVE-2026-42167 carries a CVSS of 8.1, and the proof of concept it publishes only fires after authentication, against a PostgreSQL backend whose database role can already run code. Triage starts in the ProFTPD config.
Reality
- Evidence45
- Adoption20
- Hype gap−15
- Incentives35
- Confidence40
inlet finds Python SQL call sites by matching names, and in four of five packages with documented injection CVEs the vulnerable string reached the database through a framework helper instead. Its author published the 0 for 5.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−20
- Incentives45
- Confidence50
Two Python login functions return the same 200s and 401s, and only the one keeping user values in a parameter tuple survives a test that reads what a fake cursor received. The placeholder it checks is SQLite's.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+12
- Incentives55
- Confidence60
Three flaws in NextGen Healthcare Mirth Connect 4.7.1 and earlier share a single fix in version 4.7.2. The one that changes blast radius lets an authenticated user read the engine's stored credentials for connected systems.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−18
- Incentives32
- Confidence66
cPanel says every supported build of cPanel and WHM is affected by CVE-2026-67401, and its September 8 advisory arrived without a severity score or any interim step for hosts that cannot take the upgrade yet.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives58
- Confidence60
The advisory pins CVE-2026-24031 on admins who cleared auth_username_chars, but a source comparison of 2.4.2 and 2.4.3 traces it to a regression in the settings layer. That is why the fix is a package, not a config edit.
Reality
- Evidence64
- Adoption20
- Hype gap−12
- Incentives38
- Confidence55
Hundreds of exploit attempts landed within hours of public disclosure, according to WatchTowr. With nothing to install, the controls available are network isolation, filter-layer blocking and least privilege.
Reality
- Evidence40
- Adoption42
- Hype gap+18
- Incentives55
- Confidence38