KEV-listed, confirmed in-the-wild probes, patches released, CISA warning.
What: Unauthenticated path traversal in GitLab CE/EE repository commits API (versions 18.7–19.3.1) enabling arbitrary file read; CVSS 10.0 CRITICAL.
Why it matters: KEV-listed as of 2026-09-11; CISA confirmed active exploitation within hours of disclosure. Patches released (19.1.8, 19.2.6, 19.3.2). In-the-wild reconnaissance probes observed immediately post-patch. No authentication required; affects all self-managed deployments in vulnerable ranges.
Where it's seen: Security news outlets and threat intel platforms reporting confirmed exploitation; CISA advisory; vendor patch releases; defenders triaging urgently across social channels.
Confirmed in-the-wild exploitation, KEV-listed same day as disclosure, urgent vendor patching, multi-region media coverage.
What: Cisco AsyncOS for Secure Email Gateway suffers a critical (CVSS 9.8) unauthenticated remote code execution flaw via malformed email parsing, allowing root command execution.
Why it matters: KEV-listed on 2026-09-14; Cisco confirmed active exploitation in the wild before disclosure. No workaround available; patches released same day. Global security orgs (JPCERT, CISA) flagged as high-risk. This is a zero-day with confirmed threat actor use.
Where it's seen: International media coverage (Japanese, Dutch, English), security digest aggregators, and vendor advisory citations across social platforms. Defenders are being urged to patch immediately.
KEV-listed, vendor-confirmed in-the-wild exploitation, federal deadline, mass defender response.
What: Unauthenticated authentication bypass and remote code execution in Cisco Secure Firewall Management Center (FMC) web interface, allowing root access. CVSS 10.0, EPSS 97.4th percentile.
Why it matters: KEV-listed as of 2026-09-09; Cisco confirmed active in-the-wild exploitation by nation-state and ransomware actors. CISA federal remediation deadline 2026-09-12. No workaround; patch mandatory. Originally disclosed March 2026 but exploitation began recently, triggering urgent defender triage.
Where it's seen: Major security news outlets (BleepingComputer, HelpNetSecurity), CISA/Cisco advisories, international security communities (French CERT, Dutch reporting). Consistent high-signal chatter across multiple languages and regions.
Also trending
- 4 CVE-2026-51990 score 19 · 32 postshype LIKELY HACK · 78 hack
What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.
Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.
Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.
- 5 CVE-2026-85102 CRITICAL · 9.8 score 13 · 31 postshype MIXED · 58 hack
What: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway (CVSS 9.8 CRITICAL) allowing unauthenticated remote code execution.
Why it matters: Check Point has released patches for this unauthenticated RCE on a critical infrastructure VPN appliance. CVSS 9.8 and vendor patch activity signal real urgency, though EPSS remains very low (0.003) and KEV listing is absent, suggesting no confirmed in-the-wild exploitation yet. Defenders managing Check Point gateways are triaging patch deployment.
Where it's seen: Social media posts link to vendor patches and mitigation guidance; chatter emphasizes patch-Tuesday urgency and manual VPN rule workarounds. No public PoC or exploitation reports detected; posts are advisory-driven rather than incident-driven.
- 6 CVE-2026-85103 CRITICAL · 9.8 score 12 · 29 postshype MIXED · 58 hack
What: Heap-based buffer overflow in Check Point Quantum Security Gateway VPN certificate ASN.1 decoding allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL, EPSS 0.29%).
Why it matters: Critical severity affects widely-deployed security appliances; vendor has released patches with manual mitigations available; unauthenticated attack vector requires no credentials. Not KEV-listed yet, but patch availability and vendor advisory signal active remediation efforts by Check Point.
Where it's seen: Social media dominated by patch announcements and vendor guidance; SecurityWeek coverage; threat radar tracking; minimal technical PoC chatter or in-the-wild exploitation signals detected in posts.
- 7 CVE-2026-72710 CRITICAL · 9.8 score 12 · 26 postshype MIXED · 38 hack
What: SPIP CMS before 4.4.18 remote code execution via SQL table injection in editer_objet action; requires valid nonce; CVSS 9.8 CRITICAL.
Why it matters: Published yesterday; CVSS 9.8 and claimed public PoC raise urgency. Not yet KEV-listed. Social chatter is near-identical automated feeds citing "public exploit" without independent verification of working code or in-the-wild use. No vendor advisory or defender triage signals observed.
Where it's seen: Repetitive Bluesky posts amplifying vulnerability metadata; no substantive discussion, PoC repositories, or SPIP team advisory visible.
- 8 CVE-2025-25249 HIGH · 8.1 KEV score 11 · 25 postshype ACTIVE HACK · 92 hack
What: Heap-based buffer overflow in Fortinet FortiOS 7.6.0–7.0.0 and FortiSwitchManager 7.2.0–7.0.0 allows remote code execution via malformed packets (CVSS 8.1).
Why it matters: KEV-listed as actively exploited (added 2026-09-09). SOCRadar reported threat actors deploying PivotC2 RAT post-exploitation in the wild. CISA alert confirms active exploitation. Fortinet firmware across multiple versions is affected; patching is urgent for defenders.
Where it's seen: CISA KEV announcement, SOCRadar threat research advisory reporting post-exploitation RAT deployment, security monitoring platforms (cvemon) tracking as trending. Repeated calls for urgent patching across infosec community.
- 9 CVE-2026-19490 KEV score 11 · 30 postshype MIXED · 38 hack
What: Authentication bypass in Citrix NetScaler ADC and Gateway (versions 13.1–63.21, 14.1–73.32) enabling unauthenticated remote access to VPN and AAA deployments.
Why it matters: Published 2026-08-19; social chatter cites critical severity and urgent patching calls from Citrix. However, CVSS is unlisted (posts claim 9.3), EPSS is extremely low (0.27736 percentile), and CVE is not KEV-listed. No public PoC or in-the-wild exploitation confirmed in posts. Vendor advisory referenced but no confirmed active defense activity yet.
Where it's seen: Bluesky posts amplifying Citrix vendor advisory; security news aggregation; no defender triage or PoC repositories mentioned.
- 10 CVE-2026-85880 HIGH · 7.8 KEV score 11 · 31 postshype ACTIVE HACK · 88 hack
What: Heap-based buffer overflow in Windows ALPC allowing local privilege escalation (CVSS 7.8 HIGH); affects authorized attackers on Windows systems.
Why it matters: KEV-listed as exploited in-the-wild zero-day as of 2026-09-08. Microsoft patched it same day in Patch Tuesday alongside CVE-2026-81963; multiple vendor advisories (Tenable, Talos, Krebs) confirm active exploitation. Part of larger LPE chains targeting older Windows builds; requires initial foothold but escalates to SYSTEM.
Where it's seen: Patch Tuesday coverage across security blogs and news outlets; exploit chains documented involving Chromium V8 RCE + Windows kernel LPE; defender alerts on Bluesky discussing triage priority and mitigation.
- 11 CVE-2026-81578 KEV score 10 · 18 postshype LIKELY HACK · 82 hack
What: Improper access control in PaperCut MF/NG web management interface allows unauthenticated remote attackers to modify system configurations; often chained with CVE-2026-82078 for RCE. EPSS 0.32% (very low base score).
Why it matters: KEV-listed 2026-08-31. Rapid7 published working Metasploit module and confirmed active in-the-wild exploitation. Chaining with CVE-2026-82078 enables unauthenticated RCE. PaperCut released emergency patch. Defenders actively triaging and patching.
Where it's seen: Rapid7 advisory + Metasploit PR, CISA KEV list, security blogs, trending on CVE tracking sites. Social chatter references chain exploitation confirmed, patching urgency stressed.
- 12 CVE-2026-86218 KEV score 10 · 35 postshype LIKELY HACK · 82 hack
What: N-central pre-authentication remote code execution affecting versions before 2026.3.1.14; CISA KEV-listed as actively exploited.
Why it matters: Added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08; vendor N-able released Hotfix 4; multiple posts confirm active in-the-wild exploitation targeting enterprise perimeter devices; CISA deadline imposed for federal agencies.
Where it's seen: Security digests, threat intelligence feeds, and urgent patching advisories across Bluesky; vendor acknowledgment and hotfix release documented; CISA KEV alert circulating; defenders mobilizing for immediate remediation.
- 13 CVE-2026-87491 KEV score 10 · 38 postshype LIKELY HACK · 82 hack
What: Out-of-bounds write in Chrome V8 engine prior to version 153.0.8010.36, allowing remote arbitrary code execution inside the sandbox via crafted HTML. Medium severity (CVSS unavailable).
Why it matters: KEV-listed as of today with confirmed in-the-wild exploitation by Chinese threat actors (per Volexity). Google shipped patch in Chrome 153 containing 230 fixes including 5 critical vulns. Active defender triage underway across multiple vendors.
Where it's seen: Volexity APT report linking this to chained 0-day campaign; vendor advisories; urgent update messaging across security media and threat intel channels in multiple languages. No standalone PoC code posted, but exploitation already attributed to threat actors.
- 14 CVE-2026-84869 CRITICAL · 9.9 KEV score 10 · 19 postshype ACTIVE HACK · 88 hack
What: ConnectWise ScreenConnect client vulnerability (CVSS 9.9) allowing unauthorized file transfer and execution during remote sessions without host confirmation.
Why it matters: KEV-listed as of 2026-09-11 with CISA-mandated remediation deadline of 2026-09-14. ConnectWise released patch 26.6.5 on 2026-09-08. CISA warns of active exploitation. High severity and rapid official response signal real-world risk.
Where it's seen: Widespread social chatter across Bluesky; CISA advisory; vendor patch released same day as CVE publication; trending on vulnerability monitoring platforms; no public PoC mentioned but active exploitation confirmed by CISA.
- 15 CVE-2026-82078 KEV score 10 · 15 postshype ACTIVE HACK · 92 hack
What: Unsafe dynamic class loading in PaperCut MF/NG database utilities allowing arbitrary Java bytecode execution under server context when configuration is manipulated (EPSS 0.38%).
Why it matters: KEV-listed as actively exploited in-the-wild since 2026-08-31. Chained with CVE-2026-81578 (auth bypass) to achieve unauthenticated RCE. Metasploit PoC published; Rapid7 and vendor (PaperCut Emergency Patch Release 2) confirm active abuse. Defenders triaging now.
Where it's seen: Security researchers posting exploitation chains, Metasploit module submission, vendor emergency patch released, CISA KEV alert, detection runbooks published (CrowdStrike CQL rules), threat intelligence feeds.
- 16 CVE-2026-89086 CRITICAL · 9.1 score 10 · 22 postshype MIXED · 42 hack
What: OCaml jose package (before 0.11.0) RSA signature validation bypass—accepts signatures without verifying the public key, allowing signature forgery. CVSS 9.1 (CRITICAL).
Why it matters: Chatter claims "public exploit" but no PoC link or working code visible in posts. Not KEV-listed yet. Social signal is repetitive automated aggregation (identical posts from multiple accounts); posts reference "abyssal" severity tag and claim public exploit without substantiation. Real vulnerability—improper cryptographic validation is severe—but social noise lacks evidence of active weaponization or defender triage.
Where it's seen: Bluesky feeds dominated by near-duplicate posts from CVE aggregators (vulnsea, stemshop). One post (7) clarifies impact (forged signatures). No vendor advisories, PoCs, or defender questions visible.
- 17 CVE-2026-78006 CRITICAL · 9.8 score 9 · 15 postshype LIKELY HACK · 78 hack
What: The Events Calendar WordPress plugin (≤6.17.4) is vulnerable to unauthenticated remote code execution via PHP object injection in the is_safe_widget_instance function, with CVSS 9.8.
Why it matters: Published 2026-09-12, this CRITICAL vulnerability has a public exploit circulating within 24 hours. The attack chain bypasses authentication via comment moderation mechanics, requiring only that event comments be enabled. No KEV listing yet, but immediate patching signal is strong across threat feeds and defender alerts.
Where it's seen: Threat intelligence platforms (VulnSea, Patchstack, OffSeq) reporting public PoC same day; widespread social amplification across security networks flagging WordPress site operators to disable event comments pending patches.
- 18 CVE-2026-42018 HIGH · 7.5 KEV score 9 · 21 postshype LIKELY HACK · 82 hack
What: JFrog Artifactory authentication bypass leaking internal anonymous tokens to unauthenticated users when anonymous access is disabled (CVSS 7.5 HIGH, EPSS 0.28%).
Why it matters: Added to CISA KEV 2026-09-11 as actively exploited. Multiple sources report in-the-wild exploitation, including chaining with CVE-2026-42016 for admin access and Rust backdoor deployment. Vendor patching urgently signaled by defender chatter.
Where it's seen: CISA advisory, security researcher writeups (NetSPI, Wiz), threat intel alerts, mass social amplification. Posts frame as active attack chain affecting self-hosted Artifactory instances with immediate remediation calls.
- 19 CVE-2026-85046 HIGH · 8.8 KEV score 9 · 21 postshype ACTIVE HACK · 89 hack
What: Type confusion in V8 JavaScript engine in Google Chrome prior to v152.0.7977.82 allows remote arbitrary code execution within the sandbox via crafted HTML. CVSS 8.8 (HIGH).
Why it matters: KEV-listed as of 2026-09-04; Google issued urgent patch within 24 hours of CVE publication. Social chatter consistently reports active exploitation in the wild across all Chromium versions. High-severity sandbox escape affecting billions of users demands immediate patching.
Where it's seen: Bluesky and Hacker News amplifying patch advisory and KEV status. Repetitive posts emphasize "actively exploited" and link to NVD/vendor guidance. No public PoC code shared yet, but urgency signals vendor awareness of ongoing abuse.
- 20 CVE-2026-75650 CRITICAL · 10.0 KEV score 9 · 27 postshype ACTIVE HACK · 92 hack
What: Adobe Commerce and Magento template engine injection vulnerability (CVE-2026-75650) allowing unauthenticated arbitrary code execution; CVSS 10.0 CRITICAL.
Why it matters: KEV-listed as of 2026-09-08 with active in-the-wild exploitation confirmed. Adobe released emergency hotfix. Multiple vendor versions affected (Commerce B2B, Commerce, Magento Open Source). No user interaction required; scope changed indicates privilege escalation risk.
Where it's seen: Security digest and threat intelligence feeds flagging immediate patching need. Adobe emergency patch released. Dubbed "StyleSmuggler." Defenders triaging patch applicability across Magento/Commerce deployments.
- 21 CVE-2026-88018 CRITICAL · 9.8 score 9 · 20 postshype MIXED · 58 hack
What: rclone serve s3 with --auth-proxy but without --auth-key allows SigV4 signature bypass, enabling unauthenticated attackers to impersonate any access key and reach backend storage. CVSS 9.8 CRITICAL.
Why it matters: Published yesterday; NVD confirms authentication bypass in production configurations. Posts claim "public exploit" exists, but metadata lacks KEV listing or confirmed PoC links. Vendor (rclone team) has issued fix (v1.75.1) same day, signaling urgent patching. Real vuln affecting cloud sync workflows, but social signal is largely automated feed repetition.
Where it's seen: Six near-identical posts from a vulnerability feed (ABYSSAL) amplifying the CVSS score and claiming public exploit without substantiating links. One additional post from another feed. No defender triage questions, no independent researcher confirmation yet.
- 22 CVE-2026-42016 HIGH · 8.1 KEV score 9 · 17 postshype ACTIVE HACK · 92 hack
What: JFrog Artifactory Self Hosted (before v7.133.11) privilege escalation via improper token scope validation; CVSS 8.1 HIGH.
Why it matters: KEV-listed as of 2026-09-11 with confirmed active exploitation. Wiz Research documented in-the-wild chaining of CVE-2026-42016 with CVE-2026-42018 to achieve auth bypass, privilege escalation, and C2 backdoor deployment on self-hosted instances. CISA issued alert. Urgent patching required.
Where it's seen: CISA KEV alert, Wiz threat intel, Bleeping Computer coverage, security researcher posts describing live attack chains and Rust backdoor payloads. High engagement across Bluesky and threat feeds.
- 23 CVE-2026-44402 CRITICAL · 9.8 score 8 · 15 postshype MOSTLY HYPE · 28 hack
What: Unauthenticated remote code execution in Voltronic Power SNMP Web Pro 1.1 via malicious tar upload to firmware endpoint; CVSS 9.8 (CRITICAL).
Why it matters: High CVSS and claimed public PoC availability drive social signal, but no KEV listing, no confirmed vendor patch, and no defender triage reports yet. Chatter is dominated by automated vulnerability feed reposts from a single aggregator with minimal organic engagement.
Where it's seen: Identical templated posts from vulnerability scanning/aggregation service repeating the same CVE details across Bluesky. No independent researcher PoC confirmation, no vendor advisory linking, no downstream security team questions visible.
- 24 CVE-2026-72709 CRITICAL · 9.8 score 8 · 16 postshype MIXED · 58 hack
What: SPIP < 4.4.18 missing authorization in ecrire/action/ endpoints allows unauthenticated attackers to reset any user password via forged HMAC-SHA256 nonce without permission checks. CVSS 9.8 CRITICAL.
Why it matters: Published 2026-09-11; social posts claim "public exploit" available. CVSS 9.8 and straightforward auth-bypass primitive (password reset) make this immediately exploitable. Not KEV-listed yet but single-day-old disclosure with widespread automated chatter suggests rapid awareness.
Where it's seen: Automated syndication posts across Bluesky referencing vulnsea and similar feed aggregators; posts repeat identical text with "public exploit" tag. No independent researcher PoC drops, vendor advisory citations, or defender triage questions yet—chatter is feed-driven noise rather than organic security community response.
- 25 CVE-2026-44756 CRITICAL · 10.0 score 8 · 21 postshype LIKELY HACK · 72 hack
What: Memory safety vulnerability in SAP Extended Passport Protocol (EPP) processing library allowing unauthenticated remote code execution or DoS; CVSS 10.0 CRITICAL.
Why it matters: Published today with CVSS 10.0, SAP has released a patch. No KEV listing yet, no public PoC confirmed in posts, but vendor advisory and urgent patch availability signal real vulnerability requiring immediate triage by SAP customers. All major posts reference SAP's official patch day announcement.
Where it's seen: Coordinated social media amplification across multiple platforms (Bluesky, German security outlets, Japanese and English infosec accounts) citing SAP Security Patch Day September 2026, vendor advisory links, and patch availability. Chatter is factual and patch-focused, not speculative.