Confirmed in-the-wild exploitation, KEV-listed same day as disclosure, urgent vendor patching, multi-region media coverage.
What: Cisco AsyncOS for Secure Email Gateway suffers a critical (CVSS 9.8) unauthenticated remote code execution flaw via malformed email parsing, allowing root command execution.
Why it matters: KEV-listed on 2026-09-14; Cisco confirmed active exploitation in the wild before disclosure. No workaround available; patches released same day. Global security orgs (JPCERT, CISA) flagged as high-risk. This is a zero-day with confirmed threat actor use.
Where it's seen: International media coverage (Japanese, Dutch, English), security digest aggregators, and vendor advisory citations across social platforms. Defenders are being urged to patch immediately.
KEV-listed, confirmed in-the-wild probes, patches released, CISA warning.
What: Unauthenticated path traversal in GitLab CE/EE repository commits API (versions 18.7–19.3.1) enabling arbitrary file read; CVSS 10.0 CRITICAL.
Why it matters: KEV-listed as of 2026-09-11; CISA confirmed active exploitation within hours of disclosure. Patches released (19.1.8, 19.2.6, 19.3.2). In-the-wild reconnaissance probes observed immediately post-patch. No authentication required; affects all self-managed deployments in vulnerable ranges.
Where it's seen: Security news outlets and threat intel platforms reporting confirmed exploitation; CISA advisory; vendor patch releases; defenders triaging urgently across social channels.
F5 Labs telemetry and mass scanning claims credible, but KEV absent; PoC unclear.
What: Vite dev server (v7.1.0–7.3.1, v8.0.0–8.0.4) file-access bypass via query parameters (?raw, ?import&raw, etc.) bypasses server.fs.deny protections, exposing .env, .crt, and sensitive config files. CVSS 7.5 HIGH.
Why it matters: Mass scanning observed by F5 Labs (32,000+ events) targeting exposed dev servers to harvest AWS/Azure credentials and infrastructure secrets. Patches available (7.3.2, 8.0.5). Not yet KEV-listed but active in-the-wild exploitation reported with high-engagement social signal from security researchers and vendors.
Where it's seen: Multiple Bluesky posts citing F5 Labs telemetry on mass scanning campaigns, credential harvesting tactics, and urgent patching guidance. Coverage emphasizes cloud credential theft and exposed port 5173 scanning.
Also trending
- 4 CVE-2026-90711 CRITICAL · 9.1 score 4 · 5 postshype MIXED · 62 hack
What: proxy-addr Node.js module (versions 1.1.0–2.0.7) mishandles IPv4-mapped IPv6 trust subnets with incorrect prefix lengths, trusting all IPv4 addresses globally instead of the intended subnet. CVSS 9.1 CRITICAL.
Why it matters: Fail-open regression allows unauthenticated clients to spoof IP addresses via X-Forwarded-For header, bypassing IP-based access control, rate limiting, and geolocation checks. Patch (2.0.8) released same day as CVE publication; not yet KEV-listed but affects Express.js req.ip/req.ips widely used in production Node.js applications.
Where it's seen: Advisory and patch announcement on GitHub, social amplification via security news aggregators and vendor feeds (same-day chatter pattern). No PoC or in-the-wild exploitation reports visible yet.
- 5 CVE-2026-51990 score 4 · 5 postshype LIKELY HACK · 78 hack
What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.
Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.
Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.
- 6 CVE-2024-53920 HIGH · 7.8 score 4 · 4 postshype MOSTLY HYPE · 22 hack
What: GNU Emacs before 30.1 unsafe Lisp macro expansion during code completion or on-the-fly diagnosis allows arbitrary code execution (CVSS 7.8 HIGH).
Why it matters: Not KEV-listed and no public PoC signal in posts. Chatter is entirely NixOS package maintainers applying upstream patches post-disclosure. No indication of active exploitation or defender triage—routine patching workflow.
Where it's seen: NixOS/nixpkgs pull requests backporting Emacs patches. No security researcher PoCs, vendor advisories beyond NVD, or operator concern posts.
- 7 CVE-2023-54398 CRITICAL · 9.8 score 4 · 4 postshype LIKELY HACK · 72 hack
What: Unauthenticated Java deserialization in Yonyou U8 Cloud FileManageServlet allows remote code execution (CVSS 9.8 CRITICAL).
Why it matters: In-the-wild exploitation confirmed by Shadowserver Foundation on 2025-02-13; no authentication required; immediate RCE. Not yet KEV-listed but active abuse documented nearly two years before today's social surge suggests defenders have patched or are actively triaging.
Where it's seen: Social media chatter (Bluesky) surfacing today with CVSS/component details and references to public exploits; posts mention "critical with public exploit" and link to vulnerability aggregators; signals appear synchronized, suggesting routine security feed amplification.
- 8 CVE-2026-73807 CRITICAL · 9.8 score 4 · 3 postshype LIKELY HACK · 68 hack
What: mySCADA myPRO Manager command API lacks authentication enforcement for privileged functions, allowing unauthenticated network attackers to access management controls (CVSS 9.8 CRITICAL).
Why it matters: Published yesterday with critical CVSS score; social chatter references patch availability (version 2.2) and ICS/OT relevance. Not yet KEV-listed, but urgent patching language and restricted API guidance suggest active defender triage. No confirmed public PoC mentioned in posts.
Where it's seen: Bluesky posts from security vendors and threat intel accounts emphasizing patch urgency, API restriction mitigations, and cross-reference to related CVE-2026-82567. Discourse focuses on OT/ICS impact and version-specific guidance rather than speculation.
- 9 CVE-2026-59310 CRITICAL · 9.8 KEV score 4 · 4 postshype MIXED · 58 hack
What: Directory traversal in VMware vCenter Syslog Server allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL).
Why it matters: Social chatter reports active exploitation campaigns deploying reverse SSH tools for persistence. Multiple security news outlets covering in-the-wild attacks. VMware has patched (advisory issued 2026-07-30). However, CVE is NOT yet on CISA KEV list, and EPSS remains extremely low (0.63 percentile), suggesting limited observed exploitation despite claimed global campaign reports.
Where it's seen: Security blogs, Bluesky posts, and threat intelligence feeds claiming "active global intrusion campaign" and "scanning in the wild." Posts link to Bleeping Computer and HackerNews coverage amplifying the threat narrative.
- 10 CVE-2026-76670 CRITICAL · 9.9 score 4 · 3 postshype MOSTLY HYPE · 32 hack
What: Privilege escalation in HPE Networking EdgeConnect SD-WAN Orchestrator API allowing authenticated low-privileged users to gain admin access; CVSS 9.9 CRITICAL.
Why it matters: Published 15 Sept 2026 with maximum severity rating. No KEV listing yet, no public PoC confirmed in posts, no vendor advisory timestamp provided in metadata. Social chatter is early-stage alert recycling without exploitation signal or patch guidance.
Where it's seen: Initial Bluesky posts amplifying NVD description; generic "patch now" messaging; no defender triage questions, no PoC links, no HPE advisory linked.
- 11 CVE-2026-27540 CRITICAL · 9.0 score 4 · 4 postshype LIKELY HACK · 78 hack
What: Unrestricted file upload vulnerability in WooCommerce Wholesale Lead Capture plugin (≤2.0.3.1) allows unauthenticated PHP webshell uploads on WordPress sites. CVSS 9.0 CRITICAL.
Why it matters: Wordfence reports 100k+ active exploitation attempts blocked; patch released (v2.0.3.2); mass scanning and PHP backdoor deployment observed in the wild. Not yet KEV-listed but defender triage and vendor patching underway confirm real-world weaponization.
Where it's seen: Security vendor (Wordfence) telemetry, urgent patch advisories, multi-language social amplification calling for immediate updates, practitioner warning threads.
- 12 CVE-2026-89308 score 4 · 4 postshype MIXED · 42 hack
What: Unauthenticated OS command injection in TrxTimeAttendance ping.php endpoint (versions 1.0.5–1.9.5) enabling remote code execution. CVSS reported as 9.3 in social posts, though NVD lists n/a.
Why it matters: Published today with immediate social amplification flagging RCE risk in widely-deployed time-attendance software. No KEV listing yet; no confirmed public PoC or active exploitation reported. Chatter emphasizes "patch or restrict access now" but lacks defender triage feedback or vendor advisory confirmation.
Where it's seen: Same-day coordinated posts across Bluesky citing CVSS 9.3 and urging immediate mitigation. References to threat intelligence aggregators (stackflag, stemshop, offseq, radar) indicate rapid feed syndication rather than organic discovery.
- 13 CVE-2026-39987 CRITICAL · 9.8 KEV EPSS 99% score 4 · 4 postshype ACTIVE HACK · 92 hack
What: Pre-auth remote code execution in marimo (Python reactive notebook) via unauthenticated WebSocket endpoint /terminal/ws; CVSS 9.8 CRITICAL, EPSS 0.82 (99th percentile).
Why it matters: KEV-listed 2026-04-23. Confirmed in-the-wild exploitation within 10 hours of public disclosure (2026-04-09). Multiple threat actors observed chaining RCE with LLM-driven post-exploitation (credential theft, database exfiltration, lateral movement to AWS/SSH). Marimo 0.23.0+ required; patch window critically narrow.
Where it's seen: Infosec community posts document active attacks with telemetry (Sysdig), C2 traffic established within 14 hours. Posts reference real-world compromises (PostgreSQL data loss, AWS Secrets access). No apparent speculation or FUD — chatter tied to defender observations and incident reporting.
- 14 CVE-2026-91001 CRITICAL · 9.9 score 3 · 4 postshype LIKELY HACK · 78 hack
What: Stack-based buffer overflow in D-Link DI-8400 16.07 DDNS configuration (CVE-2026-91001, CVSS 9.9 CRITICAL) allowing remote code execution via manipulation of multiple DDNS parameters.
Why it matters: Public exploit released same day as CVE publication; CVSS 9.9 indicates unauthenticated remote RCE on widely-deployed router hardware. Not yet KEV-listed but exploitation barrier is eliminated. Defenders managing D-Link deployments must triage immediately.
Where it's seen: Threat intelligence feeds and security media amplifying advisory within hours of publication; multiple posts emphasizing public exploit availability and criticality; limited but direct defender guidance (access restriction recommendations appearing).
- 15 CVE-2026-19773 CRITICAL · 9.8 score 3 · 3 postshype MOSTLY HYPE · 28 hack
What: libwebsockets HTTP/2 HPACK path header parser lacks input validation, allowing unauthenticated remote attackers to write past buffer boundaries and execute arbitrary code (CVSS 9.8 CRITICAL).
Why it matters: Published today with CVSS 9.8 and no authentication required, but not yet KEV-listed. Social chatter claims "active exploitation" as 0day, but no public PoC, vendor advisory timeline, or defender reports visible. Claims lack corroborating evidence.
Where it's seen: Bluesky posts amplifying NVD description with "actively exploited" language; links to third-party CVE aggregators. No vendor patching announcements, researcher PoC, or CISA advisory found yet.
- 16 CVE-2024-58385 CRITICAL · 9.8 score 3 · 3 postshype LIKELY HACK · 78 hack
What: Unauthenticated SQL injection in Yonyou U8 CRM fillbacksettingedit.php endpoint (CVSS 9.8 CRITICAL) allowing arbitrary SQL execution and OS command execution on MSSQL with xp_cmdshell.
Why it matters: No authentication required; exploitation confirmed in-the-wild by Shadowserver Foundation on 2025-02-13. CVSS 9.8 reflects severity. Not yet KEV-listed but active exploitation signal is strong and documented by authoritative researcher.
Where it's seen: Social chatter across Bluesky repeating NVD advisory text; posts emphasizing "anyone can access" and database/file manipulation risk. No public PoC drops observed in posts, but Shadowserver evidence dates back seven months.
- 17 CVE-2026-63696 CRITICAL · 9.1 score 3 · 3 postshype MOSTLY HYPE · 28 hack
What: Dell SmartFabric OS10 versions before 10.6.1.3 fail to verify software update integrity, allowing remote code execution. CVSS 9.1 CRITICAL.
Why it matters: Requires high privilege and remote access (not unauthenticated). Not KEV-listed. No public PoC or in-the-wild exploitation reported yet. No urgent vendor patching signals in metadata. Social chatter amplifies CVSS score but lacks defender triage or exploitation evidence.
Where it's seen: Generic social amplification of CVE metadata across Bluesky; posts link to aggregator sites but cite no incident data, working exploit, or defender activity.
- 18 CVE-2026-63695 CRITICAL · 9.8 score 3 · 3 postshype MIXED · 62 hack
What: Session fixation vulnerability in Dell SmartFabric OS10 prior to 10.6.1.3 allowing unauthenticated remote session theft (CVSS 9.8 CRITICAL).
Why it matters: Dell has released a patch same-day (10.6.1.3); CRITICAL severity and unauthenticated remote access vector drive urgent triage. No KEV listing yet or public PoC observed in posts, but patch availability and vendor advisory confirm real vulnerability requiring immediate deployment.
Where it's seen: Social posts reference Dell's patched version and urge SmartFabric OS10 switch updates; chatter emphasizes severity and remediation path rather than exploitation details or working exploits.
- 19 CVE-2026-91998 CRITICAL · 9.9 score 3 · 3 postshype MIXED · 42 hack
What: Casdoor ≤4.4.0 authorization bypass in /api/mcp endpoint allows attackers with any app's clientId/clientSecret to gain unrestricted cross-organization user admin access (CVSS 9.9 CRITICAL).
Why it matters: Published today with CVSS 9.9; enables user enumeration, password salt extraction, admin account creation, and deletion across all orgs. Not yet KEV-listed but severity and ease of exploitation (valid credentials only) warrant immediate triage by Casdoor deployments.
Where it's seen: Same-day social amplification on Bluesky with CVE aggregators resharing NVD data; no public PoC confirmed, no vendor patch announcement yet visible, no defender incident reports.
- 20 CVE-2026-91995 CRITICAL · 9.1 score 3 · 3 postshype MIXED · 58 hack
What: Authentication bypass in pig (pig-mesh) <4.1.0 allows remote attackers to reset any account password, including admin, via the /register/password endpoint by submitting any value as the current password. CVSS 9.1 CRITICAL.
Why it matters: Same-day disclosure (published 2026-09-15); critical CVSS score; direct path to full administrative takeover. No KEV listing yet, no public PoC confirmed in posts, but vulnerability is trivial to exploit and immediately actionable for attackers. Defenders should assume rapid weaponization.
Where it's seen: Early social chatter on Bluesky summarizing NVD details; no vendor advisory or patch confirmation visible yet; no working PoC drops reported; mostly awareness/alert posts linking to CVE aggregators.
- 21 CVE-2026-15639 score 3 · 2 postshype unscored hack
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.
- 22 CVE-2026-87186 CRITICAL · 9.6 score 3 · 2 postshype MIXED · 38 hack
What: Unauthenticated remote code execution in Oracle Hyperion Financial Management 11.2.26.0.000 (Security component); CVSS 9.6 CRITICAL with scope change affecting downstream systems.
Why it matters: Fresh advisory (published 2026-09-15) targeting a widely-deployed enterprise financial system. High CVSS and scope change indicate broad blast radius. Not yet KEV-listed, no public PoC chatter, but Oracle typically patches within weeks. Early social noise is vendor-driven replication, not active exploitation signal.
Where it's seen: Automated CVSS alert amplification on Bluesky; no working PoC, no defender triage posts, no urgent vendor patching announcement yet observed.
- 23 CVE-2026-87172 CRITICAL · 9.9 score 3 · 2 postshype MOSTLY HYPE · 22 hack
What: Remote code execution in Oracle Hyperion Financial Management v11.2.26.0.000 via HTTP; low-privilege network attacker can achieve full system compromise (CVSS 9.9 CRITICAL).
Why it matters: CVSS 9.9 with scope change and impact to confidentiality, integrity, and availability signals severe risk. However, no KEV listing, no confirmed PoC, and no vendor advisory or patch date disclosed yet. Social chatter is purely alert-amplification without exploitation evidence.
Where it's seen: Generic CVE alerts reposted on Bluesky; no technical PoC repositories, no defender triage reports, no Oracle patch guidance visible.
- 24 CVE-2026-83282 CRITICAL · 9.9 score 3 · 2 postshype MOSTLY HYPE · 28 hack
What: Oracle Business Intelligence Enterprise Edition (v12.2.1.4.0) platform security flaw allowing low-privilege network attackers to achieve full compromise via HTTP; CVSS 9.9 CRITICAL with scope change.
Why it matters: Published yesterday with maximum CVSS score and low attack complexity, but not yet KEV-listed. No public PoC, vendor advisory, or confirmed exploitation reported. Early social amplification appears driven by automated feed scanning rather than active defense triage.
Where it's seen: Bluesky posts linking to third-party CVE aggregators; generic vulnerability notification cadence with no defender questions, exploit code, or patching guidance visible.
- 25 CVE-2026-83268 CRITICAL · 9.1 score 3 · 2 postshype MOSTLY HYPE · 18 hack
What: Oracle BI Publisher (Analytics BI Platform Security) privilege escalation allowing network-accessible takeover; versions 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 affected. CVSS 9.1 CRITICAL.
Why it matters: Published 24 hours ago, not yet KEV-listed. CVSS 9.1 reflects high impact (C/I/A), but requires high-privilege attacker with network access—exploitation surface is narrower than headline severity suggests. No public PoC, vendor advisory, or defender triage reports visible in social chatter; posts are automated feeds reposting NVD metadata.
Where it's seen: Bluesky mentions are generic CVE feed republishes; no vendor patch status, exploit code, or real-world signal. Noise only.