Skip to content

Topic

Vulnerability Exploitation

The use of known software vulnerabilities, often soon after a patch is released, to gain unauthorized access or compromise systems.

Current stories

security5 publishers

Three days from patch to probe: SAP Commerce Cloud RCE is already being hunted

CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence70
Adoption55
Hype gap+25
Incentives40
Confidence68
security7 publishers

Medusa's patch window is negative: 500 victims, and exploits used before disclosure

The updated CISA-FBI advisory puts Medusa at more than 500 victims as of April 2026, up from 300, with exploits weaponized within 24 hours and sometimes a week before disclosure.

Perspective Coverage

7 publishers
Builder
Builder 12%
Operator
Operator 79%
Investor
Investor 9%

Reality

Evidence76
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence74
security4 publishers

Detections on VulnCheck's canaries climb from 50 to 360 amid Langflow, Rails exploitation

The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.

Perspective Coverage

4 publishers
Builder
Builder 30%
Operator
Operator 60%
Investor
Investor 10%

Reality

Evidence62
Adoption40
Hype gap+15
Incentives65
Confidence60
security6 publishers

Hundreds of AI agents drove one IP into 440 PaperCut servers across 48 countries

GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.

Perspective Coverage

6 publishers
Builder
Builder 31%
Operator
Operator 57%
Investor
Investor 12%

Reality

Evidence62
Adoption38
Hype gap+20
Incentives40
Confidence66
build3 publishers

A file.path parameter in GitLab's commit API reads server files before authentication

The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.

Publishers:dev.todocs.gitlab.comwatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 73%
Investor
Investor 5%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives45
Confidence74
security4 publishers

Two Artifactory flaws turned an anonymous JWT into admin in under five minutes

Wiz observed multiple actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8, creating admin accounts, loading Groovy plugins and dropping a Rust backdoor.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence68
Adoption35
Hype gap+10
Incentives35
Confidence70
security4 publishers

Acronis bases its CVE-2026-87886 exploitation warning on one customer report

The 7.8-rated privilege escalation in Acronis' cPanel and WHM backup plugin needs a local account on the server to work. The hosting providers and MSPs that run those servers are the only party who can install the fix.

Perspective Coverage

4 publishers
Builder
Builder 28%
Operator
Operator 61%
Investor
Investor 11%

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives65
Confidence65

Earlier coverage

  1. Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success

    Security · August 27, 2026 · 1 publisher

  2. Zimbra's SNMP notifier turns a crafted SMTP message into command execution as the zimbra user

    Build · August 20, 2026 · 1 publisher

  3. Clop's Windchill implant borrows the app's own keystore, so app logs are the only witness

    Build · August 18, 2026 · 1 publisher

  4. A vCenter bug patched on July 29 is already a ransomware chain, not a ticket

    Security · August 17, 2026 · 1 publisher