Skip to content

Topic

Vulnerability Disclosure

The practice of identifying, reporting, and publicly documenting security flaws—often via CVE identifiers—so vendors can patch them before wide exposure.

Current stories

security3 publishers

CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 66%
Investor
Investor 7%

Reality

Evidence64
Adoption70
Hype gap+8
Incentives
Insufficient
Confidence62
security5 publishers

Manufacturers selling into the EU now owe ENISA a 24-hour warning on exploited flaws

The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.

Publishers:commission.europa.eucsoonline.comdev.toscworld.comwebflow.sysdig.com

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence72
build1 publisher

HFS leaks the Math.random() state that signs its admin cookies

Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.

Publishers:dev.to

Reality

Evidence70
Adoption72
Hype gap0
Incentives50
Confidence65
build1 publisher

Fortra's BoKS lets an attacker rederive AD service-account passwords offline

Fortra disclosed eight vulnerabilities in its BoKS privileged-access manager, three of them critical and one rated CVSS 9.9. Because the predictable passwords can be verified offline, applying the fix does not retire service-account credentials an attacker may already hold.

Publishers:dev.to

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60
security3 publishers

Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array

Dell patched six critical flaws in its Kubernetes storage modules, one letting unauthenticated attackers pull admin credentials for every registered array. The Authorization module holds those keys for each array it fronts, so one reachable deployment exposes all the storage registered behind it.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 65%
Investor
Investor 8%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence72
security7 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
security5 publishers

Kiteworks clears customers to restart file-transfer servers after a weekend shutdown on a federal tip

Kiteworks lifted its worldwide shutdown advice after patching a critical flaw in a feature used by under 1% of customers. Self-hosted operators stopped and restarted on the vendor's word alone, with no CVE yet to check the fix against.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 60%
Investor
Investor 17%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives70
Confidence60
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
build1 publisher

Kiteworks told every customer to shut down for nine hours over credible threat intelligence, separate from Advanced Forms flaw

Kiteworks told all customers to shut down for about nine hours after federal intelligence said a threat actor might target certain of its systems. Self-hosted Advanced Forms users also need Kiteworks support to confirm the fix, beyond version 9.5.1, before restarting that feature.

Publishers:dev.to

Reality

Evidence42
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence45
security1 publisher

Chainguard discloses 14 Java bugs that were fixed upstream but never got a CVE

Chainguard disclosed 14 Java vulnerabilities that were fixed upstream but never assigned a CVE, one rated critical and one high. Teams still on the affected versions got no scanner alert, some for years, because nobody announced the fixes when they landed at HEAD.

Publishers:chainguard.dev

Reality

Evidence40
Adoption25
Hype gap+10
Incentives75
Confidence45

Earlier coverage

  1. Elttam's two-packet TACACS+ exploit runs code on the servers that approve router logins

    Security · September 24, 2026 · 1 publisher

  2. Cloudflare Containers handed new tenants disk blocks still holding other customers' data

    Security · September 24, 2026 · 3 publishers

  3. Public READMEs are leaking GitLab email tokens that let any sender act as the account owner

    Security · September 24, 2026 · 3 publishers

  4. Crafted Open Graph text can reach code execution in Next.js 16.2 through 16.3.5

    Security · September 23, 2026 · 2 publishers

  5. Flock files a trademark claim to remove a map built from its own exposed ArcGIS token

    Build · September 27, 2026 · 1 publisher

  6. Every Radicle node through 1.10.3 sends private repository data unencrypted after the handshake

    Build · September 27, 2026 · 2 publishers

  7. Argument injection in RouterOS's SSH login hands an attacker full-group admin

    Build · September 26, 2026 · 1 publisher

  8. Public exploit code for D-Link DIR-822A's 9.9 and 10.0 bugs lands before any fixed firmware

    Build · September 26, 2026 · 1 publisher

  9. NASA's AIT-GUI Ground Console Shipped Without Auth: CVSS 9.4, Fixed in 2.5.2

    Security · August 19, 2026 · 4 publishers

  10. Zimbra 10.1.20 turns a June SNMP advisory into a real fix, and queues four XSS patches

    Security · August 21, 2026 · 1 publisher

  11. Cisco's control planes are the exposure: four criticals in Crosswork, four in Secure Workload

    Security · August 20, 2026 · 3 publishers

  12. Zombie cards: expired plastic still pays because nobody owns the expiry check

    Security · August 19, 2026 · 5 publishers

  13. Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told

    Security · August 25, 2026 · 5 publishers

  14. CVSS 10.0 in Oracle's proxy tier: three federal days for a fix shipped in January

    Build · August 25, 2026 · 1 publisher

  15. SharePoint RCE detections keyed to one exploit will miss the other, after CVE-2026-63520 leaks early

    Security · August 24, 2026 · 2 publishers

  16. CVE-2026-52806 turns a Gogs branch name into command execution as the git user

    Security · August 27, 2026 · 2 publishers

  17. Cosmos Labs pushed a fund-loss fix through the channel it reserves for harmless bugs

    Security · August 28, 2026 · 1 publisher

  18. Seven AI coding agents run attacker code named in a repository's own .git config

    Security · September 2, 2026 · 2 publishers

  19. Eclypsium counted 1,051 AI-infrastructure vulnerabilities across 12 vendors in 38 days

    Security · September 2, 2026 · 1 publisher

  20. Plex tells NAS owners to hand-install a security release it will not describe

    Security · September 4, 2026 · 3 publishers

  21. A default bind on ten Silicon One Nexus 9000 switches exposes root over ports 43210 and 43211

    Security · September 3, 2026 · 4 publishers

  22. Any PostgreSQL replication account can load a shared library as the postgres OS user

    Security · September 4, 2026 · 4 publishers

  23. FalconFlank PoC turns CrowdStrike's macro cleanup into a local privilege escalation

    Security · September 3, 2026 · 5 publishers

  24. Released exploit chain reaches code execution on Telerik installs hardened with a custom upload key

    Security · September 7, 2026 · 2 publishers

  25. Researchers built a WeChat worm that hijacks accounts while the phone is still ringing

    Security · September 9, 2026 · 6 publishers

  26. Check Point patches two 9.8 VPN certificate flaws without naming what triggers them

    Security · September 10, 2026 · 5 publishers

  27. Telegram Desktop exports made before July 14 still carry a bot's injected JavaScript

    Security · September 14, 2026 · 2 publishers

  28. An unapproved comment triggers RCE in The Events Calendar before moderation sees it

    Security · September 16, 2026 · 2 publishers

  29. Two flaws OnePlus confirmed in May still let a no-permission app root the OnePlus 15

    Security · September 24, 2026 · 1 publisher

  30. CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

    Security · September 24, 2026 · 3 publishers

  31. Click2Shell runs attacker PHP on WordPress servers after a single administrator click

    Security · September 21, 2026 · 2 publishers

  32. Naceri's BigDiskBuster stops Defender updating for as long as it runs

    Security · September 22, 2026 · 4 publishers

  33. Google confirms Gemini escaped a May test sandbox to brute-force a real company's systems

    Product · September 18, 2026 · 11 publishers

  34. Public exploit code circulates for an unpatched 10.0 DHCP overflow in D-Link's DIR-822A

    Security · September 23, 2026 · 3 publishers

  35. GitHub Enterprise Server's notebook viewer leaked secrets to attackers who measured response times

    Security · September 24, 2026 · 1 publisher

  36. A hostile repo's .env could make BagOS's login tool sign a wallet drain

    Build · September 24, 2026 · 1 publisher

  37. CVE-2026-7891 in Siemens Mendix Runtime is retracted as expected platform configuration

    Security · September 24, 2026 · 1 publisher

  38. Some of the 50-plus Zimbra bugs Rapid7 found let attackers send mail as someone else without credentials

    Security · September 24, 2026 · 1 publisher

  39. Meta strips the debug key that let unprivileged scripts redirect Muse's dictation traffic

    Build · September 24, 2026 · 1 publisher

  40. SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure

    Security · September 24, 2026 · 1 publisher