Confirmed in-the-wild exploitation, KEV-listed same day as disclosure, urgent vendor patching, multi-region media coverage.
What: Cisco AsyncOS for Secure Email Gateway suffers a critical (CVSS 9.8) unauthenticated remote code execution flaw via malformed email parsing, allowing root command execution.
Why it matters: KEV-listed on 2026-09-14; Cisco confirmed active exploitation in the wild before disclosure. No workaround available; patches released same day. Global security orgs (JPCERT, CISA) flagged as high-risk. This is a zero-day with confirmed threat actor use.
Where it's seen: International media coverage (Japanese, Dutch, English), security digest aggregators, and vendor advisory citations across social platforms. Defenders are being urged to patch immediately.
KEV-listed, confirmed in-the-wild probes, patches released, CISA warning.
What: Unauthenticated path traversal in GitLab CE/EE repository commits API (versions 18.7–19.3.1) enabling arbitrary file read; CVSS 10.0 CRITICAL.
Why it matters: KEV-listed as of 2026-09-11; CISA confirmed active exploitation within hours of disclosure. Patches released (19.1.8, 19.2.6, 19.3.2). In-the-wild reconnaissance probes observed immediately post-patch. No authentication required; affects all self-managed deployments in vulnerable ranges.
Where it's seen: Security news outlets and threat intel platforms reporting confirmed exploitation; CISA advisory; vendor patch releases; defenders triaging urgently across social channels.
Recent critical disclosure, vendor patching active, defender guidance live; no KEV, no public PoC yet.
What: mySCADA myPRO Manager command API lacks authentication enforcement for privileged functions, allowing unauthenticated network attackers to access management controls (CVSS 9.8 CRITICAL).
Why it matters: Published yesterday with critical CVSS score; social chatter references patch availability (version 2.2) and ICS/OT relevance. Not yet KEV-listed, but urgent patching language and restricted API guidance suggest active defender triage. No confirmed public PoC mentioned in posts.
Where it's seen: Bluesky posts from security vendors and threat intel accounts emphasizing patch urgency, API restriction mitigations, and cross-reference to related CVE-2026-82567. Discourse focuses on OT/ICS impact and version-specific guidance rather than speculation.
Also trending
- 4 CVE-2026-39364 HIGH · 7.5 score 5 · 6 postshype LIKELY HACK · 74 hack
What: Vite dev server (v7.1.0–7.3.1, v8.0.0–8.0.4) file-access bypass via query parameters (?raw, ?import&raw, etc.) bypasses server.fs.deny protections, exposing .env, .crt, and sensitive config files. CVSS 7.5 HIGH.
Why it matters: Mass scanning observed by F5 Labs (32,000+ events) targeting exposed dev servers to harvest AWS/Azure credentials and infrastructure secrets. Patches available (7.3.2, 8.0.5). Not yet KEV-listed but active in-the-wild exploitation reported with high-engagement social signal from security researchers and vendors.
Where it's seen: Multiple Bluesky posts citing F5 Labs telemetry on mass scanning campaigns, credential harvesting tactics, and urgent patching guidance. Coverage emphasizes cloud credential theft and exposed port 5173 scanning.
- 5 CVE-2026-59310 CRITICAL · 9.8 KEV score 5 · 5 postshype MIXED · 58 hack
What: Directory traversal in VMware vCenter Syslog Server allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL).
Why it matters: Social chatter reports active exploitation campaigns deploying reverse SSH tools for persistence. Multiple security news outlets covering in-the-wild attacks. VMware has patched (advisory issued 2026-07-30). However, CVE is NOT yet on CISA KEV list, and EPSS remains extremely low (0.63 percentile), suggesting limited observed exploitation despite claimed global campaign reports.
Where it's seen: Security blogs, Bluesky posts, and threat intelligence feeds claiming "active global intrusion campaign" and "scanning in the wild." Posts link to Bleeping Computer and HackerNews coverage amplifying the threat narrative.
- 6 CVE-2026-90711 CRITICAL · 9.1 score 4 · 5 postshype MIXED · 62 hack
What: proxy-addr Node.js module (versions 1.1.0–2.0.7) mishandles IPv4-mapped IPv6 trust subnets with incorrect prefix lengths, trusting all IPv4 addresses globally instead of the intended subnet. CVSS 9.1 CRITICAL.
Why it matters: Fail-open regression allows unauthenticated clients to spoof IP addresses via X-Forwarded-For header, bypassing IP-based access control, rate limiting, and geolocation checks. Patch (2.0.8) released same day as CVE publication; not yet KEV-listed but affects Express.js req.ip/req.ips widely used in production Node.js applications.
Where it's seen: Advisory and patch announcement on GitHub, social amplification via security news aggregators and vendor feeds (same-day chatter pattern). No PoC or in-the-wild exploitation reports visible yet.
- 7 CVE-2026-87886 score 4 · 3 postshype LIKELY HACK · 72 hack
What: Linux local privilege escalation (CVSS 7.8) in Acronis backup plugins for cPanel, WHM, and Plesk affecting server hosting control panel integrations.
Why it matters: Acronis disclosed active limited exploitation in the wild; vendor has issued patches (1.9.3 HF3, 1.8.11+). Social chatter reflects legitimate advisory coverage and defender urgency to patch affected backup integrations.
Where it's seen: Bleeping Computer coverage of Acronis advisory; multiple posts flagging patch versions and active exploitation; no public PoC confirmed yet but vendor disclosure confirms real-world attacks.
- 8 CVE-2026-51990 score 4 · 5 postshype LIKELY HACK · 78 hack
What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.
Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.
Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.
- 9 CVE-2024-53920 HIGH · 7.8 score 4 · 4 postshype MOSTLY HYPE · 22 hack
What: GNU Emacs before 30.1 unsafe Lisp macro expansion during code completion or on-the-fly diagnosis allows arbitrary code execution (CVSS 7.8 HIGH).
Why it matters: Not KEV-listed and no public PoC signal in posts. Chatter is entirely NixOS package maintainers applying upstream patches post-disclosure. No indication of active exploitation or defender triage—routine patching workflow.
Where it's seen: NixOS/nixpkgs pull requests backporting Emacs patches. No security researcher PoCs, vendor advisories beyond NVD, or operator concern posts.
- 10 CVE-2023-54398 CRITICAL · 9.8 score 4 · 4 postshype LIKELY HACK · 72 hack
What: Unauthenticated Java deserialization in Yonyou U8 Cloud FileManageServlet allows remote code execution (CVSS 9.8 CRITICAL).
Why it matters: In-the-wild exploitation confirmed by Shadowserver Foundation on 2025-02-13; no authentication required; immediate RCE. Not yet KEV-listed but active abuse documented nearly two years before today's social surge suggests defenders have patched or are actively triaging.
Where it's seen: Social media chatter (Bluesky) surfacing today with CVSS/component details and references to public exploits; posts mention "critical with public exploit" and link to vulnerability aggregators; signals appear synchronized, suggesting routine security feed amplification.
- 11 CVE-2026-27540 CRITICAL · 9.0 score 4 · 4 postshype LIKELY HACK · 78 hack
What: Unrestricted file upload vulnerability in WooCommerce Wholesale Lead Capture plugin (≤2.0.3.1) allows unauthenticated PHP webshell uploads on WordPress sites. CVSS 9.0 CRITICAL.
Why it matters: Wordfence reports 100k+ active exploitation attempts blocked; patch released (v2.0.3.2); mass scanning and PHP backdoor deployment observed in the wild. Not yet KEV-listed but defender triage and vendor patching underway confirm real-world weaponization.
Where it's seen: Security vendor (Wordfence) telemetry, urgent patch advisories, multi-language social amplification calling for immediate updates, practitioner warning threads.
- 12 CVE-2026-89308 score 4 · 4 postshype MIXED · 42 hack
What: Unauthenticated OS command injection in TrxTimeAttendance ping.php endpoint (versions 1.0.5–1.9.5) enabling remote code execution. CVSS reported as 9.3 in social posts, though NVD lists n/a.
Why it matters: Published today with immediate social amplification flagging RCE risk in widely-deployed time-attendance software. No KEV listing yet; no confirmed public PoC or active exploitation reported. Chatter emphasizes "patch or restrict access now" but lacks defender triage feedback or vendor advisory confirmation.
Where it's seen: Same-day coordinated posts across Bluesky citing CVSS 9.3 and urging immediate mitigation. References to threat intelligence aggregators (stackflag, stemshop, offseq, radar) indicate rapid feed syndication rather than organic discovery.
- 13 CVE-2026-76670 CRITICAL · 9.9 score 4 · 3 postshype MOSTLY HYPE · 32 hack
What: Privilege escalation in HPE Networking EdgeConnect SD-WAN Orchestrator API allowing authenticated low-privileged users to gain admin access; CVSS 9.9 CRITICAL.
Why it matters: Published 15 Sept 2026 with maximum severity rating. No KEV listing yet, no public PoC confirmed in posts, no vendor advisory timestamp provided in metadata. Social chatter is early-stage alert recycling without exploitation signal or patch guidance.
Where it's seen: Initial Bluesky posts amplifying NVD description; generic "patch now" messaging; no defender triage questions, no PoC links, no HPE advisory linked.
- 14 CVE-2026-39987 CRITICAL · 9.8 KEV EPSS 99% score 4 · 4 postshype ACTIVE HACK · 92 hack
What: Pre-auth remote code execution in marimo (Python reactive notebook) via unauthenticated WebSocket endpoint /terminal/ws; CVSS 9.8 CRITICAL, EPSS 0.82 (99th percentile).
Why it matters: KEV-listed 2026-04-23. Confirmed in-the-wild exploitation within 10 hours of public disclosure (2026-04-09). Multiple threat actors observed chaining RCE with LLM-driven post-exploitation (credential theft, database exfiltration, lateral movement to AWS/SSH). Marimo 0.23.0+ required; patch window critically narrow.
Where it's seen: Infosec community posts document active attacks with telemetry (Sysdig), C2 traffic established within 14 hours. Posts reference real-world compromises (PostgreSQL data loss, AWS Secrets access). No apparent speculation or FUD — chatter tied to defender observations and incident reporting.
- 15 CVE-2026-91001 CRITICAL · 9.9 score 3 · 4 postshype LIKELY HACK · 78 hack
What: Stack-based buffer overflow in D-Link DI-8400 16.07 DDNS configuration (CVE-2026-91001, CVSS 9.9 CRITICAL) allowing remote code execution via manipulation of multiple DDNS parameters.
Why it matters: Public exploit released same day as CVE publication; CVSS 9.9 indicates unauthenticated remote RCE on widely-deployed router hardware. Not yet KEV-listed but exploitation barrier is eliminated. Defenders managing D-Link deployments must triage immediately.
Where it's seen: Threat intelligence feeds and security media amplifying advisory within hours of publication; multiple posts emphasizing public exploit availability and criticality; limited but direct defender guidance (access restriction recommendations appearing).
- 16 CVE-2026-19773 CRITICAL · 9.8 score 3 · 3 postshype MOSTLY HYPE · 28 hack
What: libwebsockets HTTP/2 HPACK path header parser lacks input validation, allowing unauthenticated remote attackers to write past buffer boundaries and execute arbitrary code (CVSS 9.8 CRITICAL).
Why it matters: Published today with CVSS 9.8 and no authentication required, but not yet KEV-listed. Social chatter claims "active exploitation" as 0day, but no public PoC, vendor advisory timeline, or defender reports visible. Claims lack corroborating evidence.
Where it's seen: Bluesky posts amplifying NVD description with "actively exploited" language; links to third-party CVE aggregators. No vendor patching announcements, researcher PoC, or CISA advisory found yet.
- 17 CVE-2024-58385 CRITICAL · 9.8 score 3 · 3 postshype LIKELY HACK · 78 hack
What: Unauthenticated SQL injection in Yonyou U8 CRM fillbacksettingedit.php endpoint (CVSS 9.8 CRITICAL) allowing arbitrary SQL execution and OS command execution on MSSQL with xp_cmdshell.
Why it matters: No authentication required; exploitation confirmed in-the-wild by Shadowserver Foundation on 2025-02-13. CVSS 9.8 reflects severity. Not yet KEV-listed but active exploitation signal is strong and documented by authoritative researcher.
Where it's seen: Social chatter across Bluesky repeating NVD advisory text; posts emphasizing "anyone can access" and database/file manipulation risk. No public PoC drops observed in posts, but Shadowserver evidence dates back seven months.
- 18 CVE-2026-43692 HIGH · 8.8 score 3 · 2 postshype MOSTLY HYPE · 28 hack
What: Input validation flaw in macOS (Golden Gate 27, Sequoia 15.8, Tahoe 26.7) allowing remote code execution or app crash; CVSS 8.8 HIGH.
Why it matters: Apple released patches on 2026-09-14, indicating vendor acknowledgment of severity. No KEV listing, no public PoC confirmed in social chatter. Two posts cite the NVD description verbatim without exploitation details or defender triage reports.
Where it's seen: Automated CVE feed posts on Bluesky; no analyst commentary, researcher PoC, or defender questions visible. Posts appear to be syndicated NVD republication rather than organic security discussion.
- 19 CVE-2026-63696 CRITICAL · 9.1 score 3 · 3 postshype MOSTLY HYPE · 28 hack
What: Dell SmartFabric OS10 versions before 10.6.1.3 fail to verify software update integrity, allowing remote code execution. CVSS 9.1 CRITICAL.
Why it matters: Requires high privilege and remote access (not unauthenticated). Not KEV-listed. No public PoC or in-the-wild exploitation reported yet. No urgent vendor patching signals in metadata. Social chatter amplifies CVSS score but lacks defender triage or exploitation evidence.
Where it's seen: Generic social amplification of CVE metadata across Bluesky; posts link to aggregator sites but cite no incident data, working exploit, or defender activity.
- 20 CVE-2026-63695 CRITICAL · 9.8 score 3 · 3 postshype MIXED · 62 hack
What: Session fixation vulnerability in Dell SmartFabric OS10 prior to 10.6.1.3 allowing unauthenticated remote session theft (CVSS 9.8 CRITICAL).
Why it matters: Dell has released a patch same-day (10.6.1.3); CRITICAL severity and unauthenticated remote access vector drive urgent triage. No KEV listing yet or public PoC observed in posts, but patch availability and vendor advisory confirm real vulnerability requiring immediate deployment.
Where it's seen: Social posts reference Dell's patched version and urge SmartFabric OS10 switch updates; chatter emphasizes severity and remediation path rather than exploitation details or working exploits.
- 21 CVE-2026-83283 CRITICAL · 9.8 score 3 · 2 postshype unscored hack
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- 22 CVE-2026-83269 CRITICAL · 9.8 score 3 · 2 postshype unscored hack
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- 23 CVE-2026-91998 CRITICAL · 9.9 score 3 · 3 postshype MIXED · 42 hack
What: Casdoor ≤4.4.0 authorization bypass in /api/mcp endpoint allows attackers with any app's clientId/clientSecret to gain unrestricted cross-organization user admin access (CVSS 9.9 CRITICAL).
Why it matters: Published today with CVSS 9.9; enables user enumeration, password salt extraction, admin account creation, and deletion across all orgs. Not yet KEV-listed but severity and ease of exploitation (valid credentials only) warrant immediate triage by Casdoor deployments.
Where it's seen: Same-day social amplification on Bluesky with CVE aggregators resharing NVD data; no public PoC confirmed, no vendor patch announcement yet visible, no defender incident reports.
- 24 CVE-2026-91995 CRITICAL · 9.1 score 3 · 3 postshype MIXED · 58 hack
What: Authentication bypass in pig (pig-mesh) <4.1.0 allows remote attackers to reset any account password, including admin, via the /register/password endpoint by submitting any value as the current password. CVSS 9.1 CRITICAL.
Why it matters: Same-day disclosure (published 2026-09-15); critical CVSS score; direct path to full administrative takeover. No KEV listing yet, no public PoC confirmed in posts, but vulnerability is trivial to exploit and immediately actionable for attackers. Defenders should assume rapid weaponization.
Where it's seen: Early social chatter on Bluesky summarizing NVD details; no vendor advisory or patch confirmation visible yet; no working PoC drops reported; mostly awareness/alert posts linking to CVE aggregators.
- 25 CVE-2024-21762 CRITICAL · 9.8 KEV EPSS 84% score 3 · 3 postshype ACTIVE HACK · 92 hack
What: Out-of-bounds write in Fortinet FortiOS and FortiProxy SSL VPN (versions 6.0–7.4) enabling unauthenticated remote code execution; CVSS 9.8 CRITICAL, EPSS 84.3%.
Why it matters: KEV-listed on day of publication (2024-02-09); confirmed in-the-wild exploitation documented against Thai ISP 3BB with MeshCentral backdoor deployment; actively exploited by multiple threat actors including Qilin ransomware gang using it for initial access; defenders triaging mass VPN exposure across customer base.
Where it's seen: Security researchers and threat intel vendors posting exploitation timelines and IOCs; ransomware playbook references; incident reports linking 3BB breach to active toolkit deployment; patching urgency emphasized by CISO-facing threat feeds.