CVE-2026-87902: Actively Exploited, but Preconditions Decide Your Real Exposure
WordPress core's CVSS 9.2 path traversal drew exploitation attempts within hours of the patch. It is also a case study in why a vulnerable version is not the same as an exploitable one — the route to code execution depends on a site's theme layout and PHP configuration.
Cisco ISE Zero-Day (CVE-2026-76460, CVSS 10.0) Actively Exploited — No Workaround
A maximum-severity authentication bypass in Cisco Identity Services Engine is being exploited in the wild, with no interim mitigation beyond restricting network access — patching is the only real fix.
Microsoft's Record 973-CVE Patch Tuesday: Two SYSTEM-Level Zero-Days Under Attack
September 2026 is Microsoft's largest Patch Tuesday on record, and two of the fixes — both elevation-of-privilege bugs — are already being exploited to seize SYSTEM control on Windows machines.
VM Escape via VMXNET3: Critical VMware Workstation/Fusion Flaw Patched
Broadcom has patched a critical integer-overflow bug in VMware Workstation and Fusion that lets an attacker with admin rights inside a VM run code on the host — plus a related HGFS buffer overflow. Neither is remotely exploitable, but both break the guest/host boundary that desktop virtualization depends on.
CISA Adds Seven Actively Exploited Flaws to KEV — Shells and Miners Follow
A fresh CISA KEV batch spans SonicWall, Sangoma, JFrog, Kestra and LiteLLM — and in several cases the exploitation has already moved past initial access to reverse shells and cryptomining.
Patch Discussion to Exploit Probe: Now Measured in Minutes, Not Days
Maintainers are reporting that automated attackers are weaponising vulnerability rumours before a patch even ships — collapsing the gap between disclosure and exploitation from days to minutes.
CISA KEV Alert: Langflow RCE Exploited at Scale, AI Agents in the Loop
CISA added an unauthenticated Langflow RCE, an Apache Tomcat cluster-encryption bypass, and two N-able N-central auth-bypass bugs to its KEV catalog on August 5 — one of them already chained by an actor using agentic AI tooling.
11 Old Microsoft-Signed UEFI Shims Left Secure Boot Bypassable for 13 Years
ESET found that 11 old UEFI shim bootloaders, still validly signed under Microsoft's third-party CA, let attackers bypass Secure Boot on any UEFI machine that trusts that certificate — no exploit development required.
CVE-2026-63077: Critical TeamCity Flaw Enables Unauthenticated RCE
A critical bug in the agent polling protocol lets an unauthenticated attacker with network access to a TeamCity On-Premises server run arbitrary OS commands — no credentials required.
OpenSSL's HollowByte DoS Flaw Shipped With No CVE — Here's Why That Matters
An 11-byte TLS handshake header can lock up hundreds of megabytes of server memory before authentication even starts. OpenSSL fixed it in June 2026 without a CVE, an advisory, or a changelog entry.