Confirmed in-the-wild exploitation, KEV-listed same day as disclosure, urgent vendor patching, multi-region media coverage.
What: Cisco AsyncOS for Secure Email Gateway suffers a critical (CVSS 9.8) unauthenticated remote code execution flaw via malformed email parsing, allowing root command execution.
Why it matters: KEV-listed on 2026-09-14; Cisco confirmed active exploitation in the wild before disclosure. No workaround available; patches released same day. Global security orgs (JPCERT, CISA) flagged as high-risk. This is a zero-day with confirmed threat actor use.
Where it's seen: International media coverage (Japanese, Dutch, English), security digest aggregators, and vendor advisory citations across social platforms. Defenders are being urged to patch immediately.
KEV-listed, confirmed in-the-wild probes, patches released, CISA warning.
What: Unauthenticated path traversal in GitLab CE/EE repository commits API (versions 18.7–19.3.1) enabling arbitrary file read; CVSS 10.0 CRITICAL.
Why it matters: KEV-listed as of 2026-09-11; CISA confirmed active exploitation within hours of disclosure. Patches released (19.1.8, 19.2.6, 19.3.2). In-the-wild reconnaissance probes observed immediately post-patch. No authentication required; affects all self-managed deployments in vulnerable ranges.
Where it's seen: Security news outlets and threat intel platforms reporting confirmed exploitation; CISA advisory; vendor patch releases; defenders triaging urgently across social channels.
F5 Labs telemetry and mass scanning claims credible, but KEV absent; PoC unclear.
What: Vite dev server (v7.1.0–7.3.1, v8.0.0–8.0.4) file-access bypass via query parameters (?raw, ?import&raw, etc.) bypasses server.fs.deny protections, exposing .env, .crt, and sensitive config files. CVSS 7.5 HIGH.
Why it matters: Mass scanning observed by F5 Labs (32,000+ events) targeting exposed dev servers to harvest AWS/Azure credentials and infrastructure secrets. Patches available (7.3.2, 8.0.5). Not yet KEV-listed but active in-the-wild exploitation reported with high-engagement social signal from security researchers and vendors.
Where it's seen: Multiple Bluesky posts citing F5 Labs telemetry on mass scanning campaigns, credential harvesting tactics, and urgent patching guidance. Coverage emphasizes cloud credential theft and exposed port 5173 scanning.
Also trending
- 4 CVE-2026-27540 CRITICAL · 9.0 score 5 · 5 postshype LIKELY HACK · 78 hack
What: Unrestricted file upload vulnerability in WooCommerce Wholesale Lead Capture plugin (≤2.0.3.1) allows unauthenticated PHP webshell uploads on WordPress sites. CVSS 9.0 CRITICAL.
Why it matters: Wordfence reports 100k+ active exploitation attempts blocked; patch released (v2.0.3.2); mass scanning and PHP backdoor deployment observed in the wild. Not yet KEV-listed but defender triage and vendor patching underway confirm real-world weaponization.
Where it's seen: Security vendor (Wordfence) telemetry, urgent patch advisories, multi-language social amplification calling for immediate updates, practitioner warning threads.
- 5 CVE-2026-51990 score 5 · 5 postshype LIKELY HACK · 78 hack
What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.
Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.
Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.
- 6 CVE-2026-89308 score 4 · 4 postshype MIXED · 42 hack
What: Unauthenticated OS command injection in TrxTimeAttendance ping.php endpoint (versions 1.0.5–1.9.5) enabling remote code execution. CVSS reported as 9.3 in social posts, though NVD lists n/a.
Why it matters: Published today with immediate social amplification flagging RCE risk in widely-deployed time-attendance software. No KEV listing yet; no confirmed public PoC or active exploitation reported. Chatter emphasizes "patch or restrict access now" but lacks defender triage feedback or vendor advisory confirmation.
Where it's seen: Same-day coordinated posts across Bluesky citing CVSS 9.3 and urging immediate mitigation. References to threat intelligence aggregators (stackflag, stemshop, offseq, radar) indicate rapid feed syndication rather than organic discovery.
- 7 CVE-2026-39987 CRITICAL · 9.8 KEV EPSS 99% score 4 · 4 postshype ACTIVE HACK · 92 hack
What: Pre-auth remote code execution in marimo (Python reactive notebook) via unauthenticated WebSocket endpoint /terminal/ws; CVSS 9.8 CRITICAL, EPSS 0.82 (99th percentile).
Why it matters: KEV-listed 2026-04-23. Confirmed in-the-wild exploitation within 10 hours of public disclosure (2026-04-09). Multiple threat actors observed chaining RCE with LLM-driven post-exploitation (credential theft, database exfiltration, lateral movement to AWS/SSH). Marimo 0.23.0+ required; patch window critically narrow.
Where it's seen: Infosec community posts document active attacks with telemetry (Sysdig), C2 traffic established within 14 hours. Posts reference real-world compromises (PostgreSQL data loss, AWS Secrets access). No apparent speculation or FUD — chatter tied to defender observations and incident reporting.
- 8 CVE-2024-53920 HIGH · 7.8 score 4 · 3 postshype MOSTLY HYPE · 28 hack
What: GNU Emacs before 30.1 allows arbitrary code execution when elisp-completion-at-point or on-the-fly byte-compile diagnosis is invoked on untrusted Lisp source code via unsafe macro expansion (CVSS 7.8 HIGH).
Why it matters: Requires user interaction (code completion or diagnostic opt-in on untrusted code), so real-world risk depends on developer workflows. Not KEV-listed. No public PoC or in-the-wild exploitation reported. Chatter is limited to NixOS package patches.
Where it's seen: Three NixOS GitHub pull requests backporting the patch across multiple Emacs versions; no broader security discussion, vendor advisories, or researcher PoCs visible.
- 9 CVE-2026-63696 CRITICAL · 9.1 score 4 · 3 postshype MOSTLY HYPE · 28 hack
What: Dell SmartFabric OS10 versions before 10.6.1.3 fail to verify software update integrity, allowing remote code execution. CVSS 9.1 CRITICAL.
Why it matters: Requires high privilege and remote access (not unauthenticated). Not KEV-listed. No public PoC or in-the-wild exploitation reported yet. No urgent vendor patching signals in metadata. Social chatter amplifies CVSS score but lacks defender triage or exploitation evidence.
Where it's seen: Generic social amplification of CVE metadata across Bluesky; posts link to aggregator sites but cite no incident data, working exploit, or defender activity.
- 10 CVE-2026-63695 CRITICAL · 9.8 score 4 · 3 postshype MIXED · 62 hack
What: Session fixation vulnerability in Dell SmartFabric OS10 prior to 10.6.1.3 allowing unauthenticated remote session theft (CVSS 9.8 CRITICAL).
Why it matters: Dell has released a patch same-day (10.6.1.3); CRITICAL severity and unauthenticated remote access vector drive urgent triage. No KEV listing yet or public PoC observed in posts, but patch availability and vendor advisory confirm real vulnerability requiring immediate deployment.
Where it's seen: Social posts reference Dell's patched version and urge SmartFabric OS10 switch updates; chatter emphasizes severity and remediation path rather than exploitation details or working exploits.
- 11 CVE-2026-90711 CRITICAL · 9.1 score 4 · 4 postshype MIXED · 42 hack
What: proxy-addr Node.js module (versions 1.1.0–2.0.7) misinterprets IPv4-mapped IPv6 CIDR notation, trusting all IPv4 addresses instead of intended subnets; CVSS 9.1 CRITICAL.
Why it matters: Regression defeats IP-based access control, rate limiting, geolocation, and audit logging via forged X-Forwarded-For headers. Fix available in 2.0.8. No KEV listing or public PoC reported yet, but advisory and patched release published same day; widely used in Express.js ecosystems.
Where it's seen: Aggregator alerts (stemshop, hackerwire, stackflag) and GitHub release notifications dominating chatter; no active exploitation chatter, mostly vendor advisory amplification.
- 12 CVE-2026-91001 CRITICAL · 9.9 score 4 · 4 postshype LIKELY HACK · 78 hack
What: Stack-based buffer overflow in D-Link DI-8400 16.07 DDNS configuration (CVE-2026-91001, CVSS 9.9 CRITICAL) allowing remote code execution via manipulation of multiple DDNS parameters.
Why it matters: Public exploit released same day as CVE publication; CVSS 9.9 indicates unauthenticated remote RCE on widely-deployed router hardware. Not yet KEV-listed but exploitation barrier is eliminated. Defenders managing D-Link deployments must triage immediately.
Where it's seen: Threat intelligence feeds and security media amplifying advisory within hours of publication; multiple posts emphasizing public exploit availability and criticality; limited but direct defender guidance (access restriction recommendations appearing).
- 13 CVE-2026-91998 CRITICAL · 9.9 score 4 · 3 postshype MIXED · 42 hack
What: Casdoor ≤4.4.0 authorization bypass in /api/mcp endpoint allows attackers with any app's clientId/clientSecret to gain unrestricted cross-organization user admin access (CVSS 9.9 CRITICAL).
Why it matters: Published today with CVSS 9.9; enables user enumeration, password salt extraction, admin account creation, and deletion across all orgs. Not yet KEV-listed but severity and ease of exploitation (valid credentials only) warrant immediate triage by Casdoor deployments.
Where it's seen: Same-day social amplification on Bluesky with CVE aggregators resharing NVD data; no public PoC confirmed, no vendor patch announcement yet visible, no defender incident reports.
- 14 CVE-2026-91995 CRITICAL · 9.1 score 4 · 3 postshype MIXED · 58 hack
What: Authentication bypass in pig (pig-mesh) <4.1.0 allows remote attackers to reset any account password, including admin, via the /register/password endpoint by submitting any value as the current password. CVSS 9.1 CRITICAL.
Why it matters: Same-day disclosure (published 2026-09-15); critical CVSS score; direct path to full administrative takeover. No KEV listing yet, no public PoC confirmed in posts, but vulnerability is trivial to exploit and immediately actionable for attackers. Defenders should assume rapid weaponization.
Where it's seen: Early social chatter on Bluesky summarizing NVD details; no vendor advisory or patch confirmation visible yet; no working PoC drops reported; mostly awareness/alert posts linking to CVE aggregators.
- 15 CVE-2026-59310 CRITICAL · 9.8 KEV score 4 · 3 postshype MIXED · 58 hack
What: Directory traversal in VMware vCenter Syslog Server allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL).
Why it matters: Social chatter reports active exploitation campaigns deploying reverse SSH tools for persistence. Multiple security news outlets covering in-the-wild attacks. VMware has patched (advisory issued 2026-07-30). However, CVE is NOT yet on CISA KEV list, and EPSS remains extremely low (0.63 percentile), suggesting limited observed exploitation despite claimed global campaign reports.
Where it's seen: Security blogs, Bluesky posts, and threat intelligence feeds claiming "active global intrusion campaign" and "scanning in the wild." Posts link to Bleeping Computer and HackerNews coverage amplifying the threat narrative.
- 16 CVE-2026-60004 CRITICAL · 9.8 KEV EPSS 87% score 4 · 4 postshype ACTIVE HACK · 92 hack
What: Code injection / remote code execution in Gitea (self-hosted Git service) affecting authenticated users via the diffpatch API; CVSS 9.8 reported.
Why it matters: KEV-listed as of 2026-08-25 with confirmed in-the-wild exploitation. Multiple sources cite active attacks against Gitea instances. Patch available (v1.27.1+). Self-hosted deployments with open registration particularly at risk, often positioned near build and OT networks.
Where it's seen: CISA KEV announcement driving coordinated social signal across security media. Posts cite threat intelligence reports, urgent patching guidance, and technical details (signup form → shell access via diffpatch). No public PoC linked in posts, but exploitation confirmed by threat feeds.
- 17 CVE-2024-21762 CRITICAL · 9.8 KEV EPSS 84% score 3 · 3 postshype ACTIVE HACK · 92 hack
What: Out-of-bounds write in Fortinet FortiOS and FortiProxy SSL VPN (versions 6.0–7.4) enabling unauthenticated remote code execution; CVSS 9.8 CRITICAL, EPSS 84.3%.
Why it matters: KEV-listed on day of publication (2024-02-09); confirmed in-the-wild exploitation documented against Thai ISP 3BB with MeshCentral backdoor deployment; actively exploited by multiple threat actors including Qilin ransomware gang using it for initial access; defenders triaging mass VPN exposure across customer base.
Where it's seen: Security researchers and threat intel vendors posting exploitation timelines and IOCs; ransomware playbook references; incident reports linking 3BB breach to active toolkit deployment; patching urgency emphasized by CISO-facing threat feeds.
- 18 CVE-2026-12944 CRITICAL · 9.6 score 3 · 4 postshype LIKELY HACK · 72 hack
What: IBM Langflow OSS 1.0.0–1.10.0 allows unauthenticated arbitrary Python code execution as root via socket/urllib imports in components, enabling credential theft, file exfiltration, and lateral movement. CVSS 9.6 CRITICAL.
Why it matters: Published yesterday; affects widely-used open-source LLM orchestration tool. NVD confirms root RCE with AWS IMDSv1 SSRF chain and container escape potential. No KEV-listing yet, but CRITICAL CVSS and immediate patch urgency signal real exposure in deployed instances.
Where it's seen: Bluesky infosec community amplifying NVD data and threat intel aggregators (Radar, HackerWire, StackFlag) within 24 hours of publication. No public PoC or in-the-wild exploitation reported; chatter is advisory-driven awareness-raising.
- 19 CVE-2026-91200 HIGH · 8.8 score 3 · 3 postshype MOSTLY HYPE · 28 hack
What: DevSpace versions up to 6.3.21 allow path traversal in tar extraction from in-pod sync streams, enabling arbitrary file write and code execution on developer workstations (CVSS 8.8).
Why it matters: Published yesterday; high CVSS score reflects code execution risk. No KEV listing yet, no public PoC confirmed in chatter, no vendor advisory visible in posts. Social signal is pure NVD/metadata amplification with no defender triage or exploitation reports.
Where it's seen: Three near-identical posts on Bluesky quoting NVD description verbatim; references to aggregator sites. No security researcher PoC, no vendor patch announcement, no defender discussion of active exploitation.
- 20 CVE-2026-91003 CRITICAL · 9.1 score 3 · 3 postshype LIKELY HACK · 72 hack
What: Stack-based buffer overflow in D-Link DI-8300 16.07 CGI service (rzgl_asp function, redirct_url parameter) enabling remote code execution. CVSS 9.1 CRITICAL.
Why it matters: Public exploit available same day as disclosure. Remote unauthenticated RCE on network appliance. No KEV listing yet but exploit publication and CRITICAL score warrant immediate triage by D-Link device owners.
Where it's seen: Coordinated social amplification across threat intel feeds (Vulnsea, Hacker Wire, OffSeq radar) flagging exploit availability and RCE risk. Chatter focuses on patch urgency and network access restriction.
- 21 CVE-2026-45051 score 3 · 3 postshype MIXED · 52 hack
What: OpenAM <16.1.1 WebAuthnAuthentication module deserializes untrusted AuthenticatorImpl objects without validation, enabling RCE via classpath gadgets if attacker can write to userAttribute (CVE-2026-45051).
Why it matters: Published same-day with vendor patch (16.1.1); exploitability requires non-default preconditions (prior attribute write access + WebAuthn reachable), limiting widespread immediate risk but affecting access management deployments. Not yet KEV-listed; CVSS claims ~9.2 in chatter but unconfirmed in official metadata.
Where it's seen: Social posts cite CVSS 9.2 and RCE, recommend immediate upgrade to 16.1.1; no public PoC observed yet; vendor patch available; defender triage likely underway in OpenAM shops.
- 22 CVE-2026-59178 CRITICAL · 9.8 score 3 · 4 postshype MOSTLY HYPE · 28 hack
What: ESPHome Device Builder Dashboard (pre-1.0.12) silently disables authentication on upgrade when operators use legacy
$USERNAME/$PASSWORDenvironment variables instead of the new$ESPHOME_USERNAME/$ESPHOME_PASSWORDnames. CVSS 9.8 CRITICAL.Why it matters: Authentication bypass exposes dashboards to unauthenticated access without operator awareness. Published today with vendor fix available (1.0.12, container 2026.6.2). Not yet KEV-listed. No public PoC observed. Vendor has released patched version and documented mitigation (env var rename or network isolation).
Where it's seen: Same-day CVE aggregator and security news amplification on social media (no independent researcher PoCs, no mass scanning reports, standard NVD/vendor advisory distribution).
- 23 CVE-2026-20079 CRITICAL · 10.0 KEV EPSS 76% score 3 · 3 postshype ACTIVE HACK · 92 hack
What: Unauthenticated authentication bypass and remote code execution in Cisco Secure Firewall Management Center (FMC) web interface, allowing root access. CVSS 10.0, EPSS 97.4th percentile.
Why it matters: KEV-listed as of 2026-09-09; Cisco confirmed active in-the-wild exploitation by nation-state and ransomware actors. CISA federal remediation deadline 2026-09-12. No workaround; patch mandatory. Originally disclosed March 2026 but exploitation began recently, triggering urgent defender triage.
Where it's seen: Major security news outlets (BleepingComputer, HelpNetSecurity), CISA/Cisco advisories, international security communities (French CERT, Dutch reporting). Consistent high-signal chatter across multiple languages and regions.
- 24 CVE-2026-85880 HIGH · 7.8 KEV score 3 · 3 postshype ACTIVE HACK · 88 hack
What: Heap-based buffer overflow in Windows ALPC allowing local privilege escalation (CVSS 7.8 HIGH); affects authorized attackers on Windows systems.
Why it matters: KEV-listed as exploited in-the-wild zero-day as of 2026-09-08. Microsoft patched it same day in Patch Tuesday alongside CVE-2026-81963; multiple vendor advisories (Tenable, Talos, Krebs) confirm active exploitation. Part of larger LPE chains targeting older Windows builds; requires initial foothold but escalates to SYSTEM.
Where it's seen: Patch Tuesday coverage across security blogs and news outlets; exploit chains documented involving Chromium V8 RCE + Windows kernel LPE; defender alerts on Bluesky discussing triage priority and mitigation.
- 25 CVE-2026-89026 CRITICAL · 9.8 score 3 · 2 postshype unscored hack
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.