Skip to content

Topic

Zero-Day Exploitation

The practice of exploiting a software vulnerability before a patch or public fix exists, often targeting internet-facing appliances and enterprise software.

Current stories

security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Publishers:dev.tothestack.technologywatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
security10 publishers

Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process

Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 60%
Investor
Investor 13%

Reality

Evidence85
Adoption70
Hype gap−10
Incentives40
Confidence78
security6 publishers

Check Point patches a Security Management zero-day it saw exploited on July 23

The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.

Perspective Coverage

6 publishers
Builder
Builder 21%
Operator
Operator 70%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives60
Confidence70
security6 publishers

Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.

Perspective Coverage

6 publishers
Builder
Builder 19%
Operator
Operator 64%
Investor
Investor 17%

Reality

Evidence78
Adoption40
Hype gap+10
Incentives30
Confidence75
leadership3 publishers

ShinyHunters claims 2 to 3 terabytes of FBI personnel data from an Oracle PeopleSoft flaw

The bureau has not confirmed a breach and says it cannot yet tell whether its own systems or a third-party provider were the way in, while Reuters and 404 Media report that sample records match real personnel.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 63%
Investor
Investor 15%

Reality

Evidence55
Adoption45
Hype gap+30
Incentives80
Confidence60
security16 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

16 publishers
Builder
Builder 18%
Operator
Operator 64%
Investor
Investor 18%

Reality

Evidence82
Adoption58
Hype gap−8
Incentives62
Confidence80

Earlier coverage

  1. StyleSmuggler turns a Magento payment-reminder email into unauthenticated code execution

    Security · September 8, 2026 · 1 publisher

  2. Google patches a V8 type confusion already being exploited against Chrome users

    Security · September 4, 2026 · 9 publishers

  3. Eight random characters in a repo name gave away 700 compromised Gogs servers

    Science · August 28, 2026 · 1 publisher

  4. OpenAI's Black Hat account gives agent containment a timeline, two zero-days and a body count

    Product · August 25, 2026 · 2 publishers

  5. Hugging Face breach ran 69 days: a containment failure, not a rogue-agent flash

    Security · August 14, 2026 · 1 publisher