Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence50
CISA added Citrix NetScaler flaw CVE-2026-88779 to its exploited-vulnerabilities catalog on 4 October, citing evidence of active exploitation. For anyone running the appliance, confirmed use by attackers puts this fix ahead of work ranked by severity score alone.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence70
Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence65
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
Publishers:dev.to · thestack.technology · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 60%
- Investor
- Investor 13%
Reality
- Evidence85
- Adoption70
- Hype gap−10
- Incentives40
- Confidence78
The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.
Perspective Coverage
6 publishers
- Builder
- Builder 21%
- Operator
- Operator 70%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence70
F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.
Perspective Coverage
6 publishers
- Builder
- Builder 19%
- Operator
- Operator 64%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption40
- Hype gap+10
- Incentives30
- Confidence75
The bureau has not confirmed a breach and says it cannot yet tell whether its own systems or a third-party provider were the way in, while Reuters and 404 Media report that sample records match real personnel.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 63%
- Investor
- Investor 15%
Reality
- Evidence55
- Adoption45
- Hype gap+30
- Incentives80
- Confidence60
ScriptAI drafts detection and remediation logic for software flaws that have no vendor patch behind them. Vicarius says the draft, review and verify cycle finishes in under an hour, against weeks by hand. It is live for vRx customers today.
Reality
- Evidence32
- Adoption12
- Hype gap+35
- Incentives80
- Confidence40
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64
CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.
Perspective Coverage
16 publishers
- Builder
- Builder 18%
- Operator
- Operator 64%
- Investor
- Investor 18%
Reality
- Evidence82
- Adoption58
- Hype gap−8
- Incentives62
- Confidence80
The September Pixel bulletin closes a logic error in the cellular modem that escalates privileges from an adjacent position with no user interaction, and published guidance for checking a device stops at the patch level.
Reality
- Evidence55
- Adoption30
- Hype gap−10
- Incentives45
- Confidence50
Twelve of the 20 Identity Services Engine CVEs Cisco fixed on September 16 are critical and three were public before the patch, but all three need an administrator account, so the queue starts elsewhere.
Reality
- Evidence58
- Adoption52
- Hype gap−10
- Incentives40
- Confidence62
CVE-2026-76461 was in use before Monday's advisory and Cisco says multiple customers were likely compromised first, so a gateway patched this week still needs a hunt against indicators that root access can erase.
Reality
- Evidence72
- Adoption58
- Hype gap0
- Incentives55
- Confidence66
PaperCut's founder and CEO says the NG/MF incident is still open. Logs from two customers in the same region let his engineers rebuild most of the exploit chain, and the 2023 aftermath drove the order to unplug.
Publishers:papercut.com
Reality
- Evidence52
- Adoption30
- Hype gap−12
- Incentives78
- Confidence55
Microsoft fixed 974 flaws in September and two were already under attack, but both need an attacker who is already on the machine, while the twenty bugs Dustin Childs classes as wormable need no login at all.
Reality
- Evidence74
- Adoption58
- Hype gap+14
- Incentives60
- Confidence71
Tenable's tally for September 2026 is the largest Patch Tuesday on record. It shipped with two bugs already exploited in the wild. The other 962 sit on the calendar as a scheduling problem, and the severity ratings do not sort them by urgency.
Reality
- Evidence55
- Adoption25
- Hype gap+20
- Incentives60
- Confidence50
Adobe shipped the out-of-band hotfix on September 8. Sansec dates exploitation to September 4, and that four-day gap is why the advisory pairs the patch with a required encryption-key rotation.
Reality
- Evidence60
- Adoption35
- Hype gap+15
- Incentives65
- Confidence55