CISA added Citrix NetScaler flaw CVE-2026-88779 to its exploited-vulnerabilities catalog on 4 October, citing evidence of active exploitation. For anyone running the appliance, confirmed use by attackers puts this fix ahead of work ranked by severity score alone.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence70
The stable AndroidX Security State libraries report patch state for the core OS, Play system modules and the Linux kernel separately, and let an app ask whether a named CVE is fixed before it turns a feature on.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence65
Fortinet confirmed a 9.8-rated, unauthenticated file-write zero-day in FortiMail that attackers are using to drop a reboot-surviving ld.so.preload rootkit. Patching closes the hole but leaves any implant already on the appliance in place.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Five of nine FreeSWITCH CVEs from June 2026 sit in mod_verto, including an unauthenticated 9.8 heap overflow that unloading the module closes without a patch. The second critical, a 9.1 in the Event Socket Library, stays loaded and reaches any binary linked against libesl.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence55
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
CVE-2026-65660, an exploited SharePoint Server code injection flaw rated 8.8, lets any user with a low-privilege login run code on the farm. Farms that admit vendors and contractors need to count who can sign in, alongside what faces the internet.
Reality
- Evidence45
- Adoption50
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.
Perspective Coverage
5 publishers
- Builder
- Builder 23%
- Operator
- Operator 63%
- Investor
- Investor 14%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives60
- Confidence60
F5 and Cisco say attackers are exploiting flaws in BIG-IP APM and ISE, two of the three security products in Canada's September 2026 Cyber Centre alerts. Three alerts are too few to show a trend in attacker targeting, but the two exploited products need fixed software now.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence50
CERT-In bundled 14 ISC BIND CVEs, including cache-poisoning and zone-data modification flaws, under one HIGH rating on 21 September 2026. The batch suits one planned upgrade window, provided recursion and zone transfers are locked down until it runs.
Reality
- Evidence50
- Adoption80
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
GTT launched Defense Halo, which re-checks firewall and device configs whenever they change and ranks known vulnerabilities by the assets a customer runs. For the team rolling it out, catching a bad config sooner only pays off if someone can also ship the fix sooner.
Reality
- Evidence35
- Adoption12
- Hype gap+40
- Incentives65
- Confidence40
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
Detectify found 86% to 97% of open critical and high flaws on 1,293 customers' internet-facing systems had been exposed for more than 90 days. Its scanner confirmed each with a working attack request, so these are known, reachable flaws left to age.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence55
CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
Adobe's Connect 12.12 fixes CVE-2026-75682, a 9.9 SQL injection that reaches code execution from any low-privileged account. Connect deployments typically hand those accounts to students, contractors and partners, so the login barrier stops few attackers.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Check Point says the Operation Dream Job chain now escalates through CVE-2026-68820 to install FudModule v3.1. CISA has told federal agencies to patch by August 25.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 61%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence72
A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
The August 2026 Critical Security Patch Update carried 943 fixes across 23 product families, roughly 65% of Oracle's largest quarterly release. Monthly windows now need quarterly-sized capacity.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence65
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
Earlier coverage
- CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive
Security · August 19, 2026 · 2 publishers
- Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check
Security · August 20, 2026 · 4 publishers
- NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week
Security · August 20, 2026 · 5 publishers
- CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass
Security · August 29, 2026 · 4 publishers
- CISA ties federal patch deadlines to four yes-or-no questions about each CVE
Security · September 6, 2026 · 2 publishers
- CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later
Security · September 10, 2026 · 2 publishers
- Patchable VPN flaw exposed 246,000 personnel records on Japan's shared government platform
Security · September 15, 2026 · 3 publishers
- Certification rules slow election-system patching, CISA's 2026 security plan says
Security · September 25, 2026 · 2 publishers
- Check Point patches unauthenticated root code execution in Security Management and Log Server
Security · September 18, 2026 · 4 publishers
- SolarWinds Observability Self-Hosted 2026.2.3 closes two pre-auth RCEs with different preconditions
Build · September 25, 2026 · 1 publisher
- CJIS v6.1 doubles the key strength required for criminal justice data outside secure locations
Security · September 21, 2026 · 2 publishers
- Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers
Security · September 23, 2026 · 6 publishers
- FedRAMP's December 7 rules shrink the worst-case remediation window to 12 hours
Security · September 24, 2026 · 1 publisher
- The UK Civil Service is replacing cyber mandates with services departments choose to use
Security · September 24, 2026 · 1 publisher
- CISA orders agencies to fix four exploited edge-network flaws by September 25
Security · September 23, 2026 · 2 publishers
- An agent now picks the packages the person prompting it will never see
Build · September 23, 2026 · 1 publisher
- A banner-grabbing scanner flags patched OpenSSL 3.0.2 on RHEL 9 as potentially vulnerable
Build · September 22, 2026 · 1 publisher
- One unauthenticated request to LiteLLM's admin endpoint dumps every provider key the proxy routes
Build · September 21, 2026 · 1 publisher
- CISA updates KEV catalog page to reference new directive BOD 26-04
Security · September 20, 2026 · 1 publisher
- Vendor backporting leaves the old version number that scanners flag as vulnerable
Build · September 20, 2026 · 1 publisher
- A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem
Build · September 19, 2026 · 1 publisher
- N-able's fourth hotfix is the one that closes the N-central code injection
Build · September 19, 2026 · 1 publisher
- ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts
Build · September 19, 2026 · 1 publisher
- GitLab's commits API returns arbitrary files to an unauthenticated caller at CVSS 10.0
Build · September 19, 2026 · 1 publisher
- Operators rebuilding CISA's post-CVSS patch sort must merge KEV with Vulnrichment themselves
Security · September 18, 2026 · 1 publisher
- Buildpacks move the base image choice out of every application repository
Build · September 18, 2026 · 1 publisher
- Gremlin reports clearing nine times as many vulnerabilities with the same staff
Security · September 17, 2026 · 1 publisher
- Claude Code turned a published Drupal patch into a working exploit in 51 minutes
Security · September 16, 2026 · 1 publisher
- Deferring iOS 27 leaves about 56 of its 126 fixes out of the 26.7 build
Security · September 16, 2026 · 2 publishers
- Hackuity raises $19M to help security teams prioritize which vulnerabilities to fix first
Invest · September 16, 2026 · 1 publisher
- CISA ties 40% of 2024's exploited flaws to a handful of long-known weakness classes
Security · September 15, 2026 · 1 publisher
- ENISA puts weaponisation of a disclosed vulnerability at 15 minutes
Security · September 14, 2026 · 1 publisher
- CISA mirrors the KEV catalog on GitHub with a public commit history
Security · September 12, 2026 · 1 publisher
- CISA marks which KEV vulnerabilities ransomware crews are known to use
Security · September 12, 2026 · 1 publisher
- IP Services' CEO would audit a security program by asking when it last restored from backup
Leadership · September 10, 2026 · 1 publisher
- Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year
Security · September 10, 2026 · 1 publisher
- Microsoft's record 964-CVE Patch Tuesday includes two exploited zero-days
Security · September 8, 2026 · 1 publisher
- Google patches a V8 type confusion already being exploited against Chrome users
Security · September 4, 2026 · 9 publishers
- Wiz research: base images account for 39 percent of critical container CVE findings; hardened images cut CVEs by 94 percent
Security · September 4, 2026 · 1 publisher
- Check Point moves OpenAI models into the step that decides what gets patched
Security · September 4, 2026 · 1 publisher