Executive assessment
Today's brief leads with Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 02 should lead today because it is CRITICAL, is exploited in the wild, and has a fixed version available. Finding 11 also needs urgent attention because it is exploited in the wild, but its grounded severity is HIGH rather than CRITICAL. Themes: Exposed management and workflow APIs; PoC-backed infrastructure flaws; Container, sandbox and host-boundary risks. Patch order: Finding 02 (CRITICAL Orkes Conductor vulnerability exploited in the wild; fixed in Conductor 3.30.2 or later); Finding 11 (HIGH Acronis Backup incorrect default permissions vulnerability exploited in the wild; listed fixed plugin and extension versions are available); Finding 07 (CRITICAL Sonatype Nexus Repository task-management vulnerability with PoC exploitation; fixed in CE/Pro version 3.91.0); Finding 01 (CRITICAL Docker Sandboxes flaw lets malicious guest code read and modify macOS host files; fixed in Docker Sandboxes 0.42.0); Finding 06 (CRITICAL XWiki rendering XML eval injection issue with PoC exploitation; fixed in XWiki 14.10.2 and 15.0 RC1).
Finding 01 — Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
What changed: Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine.
Technical evidence: CVE-2026-77179; CVSS v4.0 9.4; weakness CWE-59; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Use clone mode and avoid adding read-write host mounts. SecurityOnline reports no active in-the-wild exploitation or public proof-of-concept. ([docs.docker.com](https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994), [securityonline.info](https://securityonline.info/docker-sandboxes-vulnerabilities-patched/))
Affected: Docker Sandboxes versions 0.28.0 up to, but not including, 0.42.0 on macOS. ([docs.docker.com](https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994))
Fix: Docker Sandboxes 0.42.0. ([docs.docker.com](https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994))
Panel assessment: Patch affected macOS deployments now: even without reported exploitation or a public proof-of-concept, this is a Critical host-file escape where malicious guest code can read or modify files with the host account’s rights, so the blast radius is much larger than the project directory. (priority: patch now)
Action: Map CVE-2026-77179 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html)
Finding 02 — Critical Orkes Conductor Vulnerability Exploited in Attacks
What changed: CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. (Unconfirmed, single-source.)
Technical evidence: CVE-2026-58138; CVSS v4.0 9.3; weakness CWE-94; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict external access to Conductor workflow API endpoints, place instances behind network access controls and segmentation, and do not expose vulnerable services directly to the internet. Monitor for suspicious workflow submissions and unexpected command execution from the Conductor process. FortiGuard reports active attack attempts targeting vulnerable Orkes Conductor deployments in its telemetry. ([fortiguard.com](https://www.fortiguard.com/threat-signal-report/6527/orkes-conductor-evaluator-remote-code-execution), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-58138))
Affected: Conductor 3.21.21 through versions earlier than 3.30.2. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-58138))
Fix: Conductor 3.30.2 or later. ([fortiguard.com](https://www.fortiguard.com/threat-signal-report/6527/orkes-conductor-evaluator-remote-code-execution))
Action: Map CVE-2026-58138 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: securityweek.com](https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/)
Finding 03 — Multiple vulnerabilities in mySCADA myPRO Manager
What changed: Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. CVE coverage: CVE-2026-73807, CVE-2026-82567.
Technical evidence: CVE-2026-73807; CVSS v3.1 9.8; weakness CWE-862; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Prevent internet access to control-system devices and systems. Place control-system networks and remote devices behind firewalls, isolate them from business networks, and use an updated VPN for remote access. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported to it. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03))
Affected: mySCADA myPRO Manager versions 2.1 and earlier. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03))
Fix: Version 2.2. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03))
Action: Map CVE-2026-73807 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03)
Finding 04 — Multiple vulnerabilities in Wärtsilä FOS-Onboard
What changed: Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. CVE coverage: CVE-2026-78225, CVE-2026-81855.
Technical evidence: CVE-2026-78225; CVSS v3.1 9; weakness CWE-321; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Minimise network exposure for control systems and ensure they are not internet-accessible. Place control-system networks and remote devices behind firewalls and isolate them from business networks. CISA reports no known public exploitation specifically targeting these vulnerabilities. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02))
Affected: Wärtsilä FOS-Onboard 5.07.0923.01. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02))
Action: Map CVE-2026-78225 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02)
Finding 05 — Multiple vulnerabilities in Digital Watchdog VMAX DVR and NVR Product Lineups
What changed: Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. CVE coverage: CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372.
Technical evidence: CVE-2026-66890; CVSS v3.1 9.6; weakness CWE-798; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Remove Internet accessibility. Place the devices behind firewalls and isolate them from business networks. CISA reports no known public exploitation specifically targeting these vulnerabilities. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01))
Affected: All versions of VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4 Recorder and VG4 Recorder. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01))
Action: Map CVE-2026-66890 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01)
Finding 06 — org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
What changed: GitHub Advisory Database published GHSA-26vp-8gxg-v4pg for CVE-2025-53837: Eval Injection, CVSS v3.1 9.9; affected: org.xwiki.rendering:xwiki-rendering-xml versions earlier than 14.10.2.
Technical evidence: CVE-2025-53837; CVSS v3.1 9.9; weakness CWE-95; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict profile and document editing to trusted users until patched. Monitor edited content for attempts to close HTML macros or inject Groovy or Python script macros. ([github.com](https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-26vp-8gxg-v4pg), [jira.xwiki.org](https://jira.xwiki.org/browse/XWIKI-20313))
Affected: org.xwiki.rendering:xwiki-rendering-xml versions earlier than 14.10.2. ([github.com](https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-26vp-8gxg-v4pg))
Fix: XWiki 14.10.2 and 15.0 RC1. ([github.com](https://github.com/xwiki/xwiki-rendering/security/advisories/GHSA-26vp-8gxg-v4pg))
Action: Map CVE-2025-53837 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-26vp-8gxg-v4pg)
Finding 07 — Sonatype Nexus Repository: Deserialization of Untrusted Data
What changed: NVD records CVE-2026-3199 (Sonatype Nexus Repository): Deserialization of Untrusted Data, CVSS v4.0 9.4; affected: Sonatype Nexus Repository versions 3.22.1 through 3.90.2.
Technical evidence: CVE-2026-3199; CVSS v4.0 9.4; weakness CWE-502; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict task creation and update permissions to system administrators and core infrastructure accounts. Restrict network access to Nexus using an IAP, VPN or strict source IP allowlisting. ([armadin.com](https://www.armadin.com/blog-posts/writeup-to-weaponization-cve-2026-3199-llm-assisted-rce-exploitation), [guide.sonatype.com](https://guide.sonatype.com/vulnerability/CVE-2026-3199), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/50615414548499-CVE-2026-3199-Nexus-Repository-3-Authenticated-Remote-Code-Execution-2026-04-08))
Affected: Sonatype Nexus Repository versions 3.22.1 through 3.90.2 ([guide.sonatype.com](https://guide.sonatype.com/vulnerability/CVE-2026-3199))
Fix: Sonatype Nexus Repository CE/Pro version 3.91.0 ([support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/50615414548499-CVE-2026-3199-Nexus-Repository-3-Authenticated-Remote-Code-Execution-2026-04-08))
Action: Map CVE-2026-3199 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-3199)
Finding 08 — LMDeploy: Deserialization of Untrusted Data
What changed: GitHub Advisory Database published GHSA-2vh9-42vm-xmv2 for CVE-2025-66455 (LMDeploy): Deserialization of Untrusted Data, CVSS v3.1 9.8; affected: LMDeploy versions >= 0.9.2 and < 0.16.0.
Technical evidence: CVE-2025-66455; CVSS v3.1 9.8; weakness CWE-502; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Prevent untrusted clients from reaching /distserve/ endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, and configure API-key authentication. Block arbitrary outbound ZeroMQ connections from serving nodes. ([github.com](https://github.com/advisories/GHSA-2vh9-42vm-xmv2), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2025-66455))
Affected: LMDeploy versions >= 0.9.2 and < 0.16.0. ([github.com](https://github.com/advisories/GHSA-2vh9-42vm-xmv2))
Fix: LMDeploy 0.16.0. ([github.com](https://github.com/advisories/GHSA-2vh9-42vm-xmv2))
Action: Map CVE-2025-66455 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-2vh9-42vm-xmv2)
Finding 09 — Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
What changed: GitHub Advisory Database published GHSA-xcw4-53cc-hv32 for CVE-2026-59163 (Mnemosyne): Improper Verification of Cryptographic Signature, CVSS v3.1 9.1; affected: All versions exposing the sync server endpoint, up to and including v3.10.0.
Technical evidence: CVE-2026-59163; CVSS v3.1 9.1; weakness CWE-347; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict network access to the sync server endpoint to trusted clients using a firewall, reverse proxy with mTLS, or a localhost bind with an SSH tunnel. The GitHub advisory provides reproduction code that forges a JWT for any user without a secret. ([github.com](https://github.com/advisories/GHSA-xcw4-53cc-hv32))
Affected: All versions exposing the sync server endpoint, up to and including v3.10.0. ([github.com](https://github.com/advisories/GHSA-xcw4-53cc-hv32))
Fix: v3.10.1. ([github.com](https://github.com/advisories/GHSA-xcw4-53cc-hv32))
Action: Map CVE-2026-59163 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-xcw4-53cc-hv32)
Finding 10 — AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
What changed: GitHub Advisory Database published GHSA-82r6-8w77-94w6 for CVE-2026-63374 (AnyIO): Improper Certificate Validation, CVSS v4.0 9.3; affected: AnyIO versions earlier than 4.14.2.
Technical evidence: CVE-2026-63374; CVSS v4.0 9.3; weakness CWE-295, CWE-297; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Encode host names with the idna package before connecting. ([github.com](https://github.com/advisories/GHSA-82r6-8w77-94w6))
Affected: AnyIO versions earlier than 4.14.2. ([github.com](https://github.com/advisories/GHSA-82r6-8w77-94w6))
Fix: AnyIO 4.14.2. ([github.com](https://github.com/advisories/GHSA-82r6-8w77-94w6))
Action: Map CVE-2026-63374 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-82r6-8w77-94w6)
Finding 11 — Acronis Backup Incorrect Default Permissions Vulnerability
What changed: CISA added CVE-2026-87886 (Acronis Backup) to the Known Exploited Vulnerabilities catalogue: Incorrect Default Permissions, CVSS v3.0 7.8; affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021; Acronis Backup extension for Plesk (Linux) before build 1.8.11.638.
Technical evidence: CVE-2026-87886; CVSS v3.0 7.8; weakness CWE-276; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Until patching is possible, restrict local access to affected servers and limit shell access for untrusted accounts; isolate backup infrastructure from standard hosting workloads where possible. Monitor privileged activity, unexpected privilege changes, suspicious elevated processes, Acronis-related file changes, authentication logs, web-shell detections, control-panel activity and backup access records. ([security-advisory.acronis.com](https://security-advisory.acronis.com/advisories/SEC-10986), [cybersecuritynews.com](https://cybersecuritynews.com/acronis-plugin-vulnerability-exploited/))
Affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021; Acronis Backup extension for Plesk (Linux) before build 1.8.11.638. ([security-advisory.acronis.com](https://security-advisory.acronis.com/advisories/SEC-10986))
Fix: Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3; Acronis Backup extension for Plesk version 1.8.11; Acronis Backup plugin for DirectAdmin version 1.2.3. ([security-advisory.acronis.com](https://security-advisory.acronis.com/advisories/SEC-10986))
Action: Map CVE-2026-87886 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-87886)
Finding 12 — vim/vim: Heap-based Buffer Overflow
What changed: NVD records CVE-2023-4738: Heap-based Buffer Overflow, CVSS v3.1 7.8; affected: Huntr reproduced the issue on Vim v9.0.1429.
Technical evidence: CVE-2023-4738; CVSS v3.1 7.8; weakness CWE-122; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Prevent users and automation from running untrusted files in Vim script mode. CISA ADP Vulnrichment records proof-of-concept exploitation. ([access.redhat.com](https://access.redhat.com/security/cve/cve-2023-4738), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2023-4738), [huntr.dev](https://huntr.dev/bounties/9fc7dced-a7bb-4479-9718-f956df20f612), +1 more)
Affected: Huntr reproduced the issue on Vim v9.0.1429. ([huntr.dev](https://huntr.dev/bounties/9fc7dced-a7bb-4479-9718-f956df20f612))
Fix: Debian 11 bullseye: 2:8.2.2434-3+deb11u3. ([lists.debian.org](https://lists.debian.org/debian-lts-announce/2025/03/msg00023.html))
Action: Map CVE-2023-4738 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2023-4738)
Finding 13 — ToolHive: containerized MCP servers: Improper Access Control
What changed: GitHub Advisory Database published GHSA-qg2g-g9w3-m5h8 for CVE-2026-58197 (ToolHive): Improper Access Control, CVSS v3.1 8.8; affected: ToolHive CLI versions before 0.30.1 and ToolHive Studio versions before 0.38.0.
Technical evidence: CVE-2026-58197; CVSS v3.1 8.8; weakness CWE-284, CWE-306; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Block host.docker.internal and a private address (the Docker gateway) from container networking. Isolate each MCP server in its own Docker network without access to the Docker bridge gateway. CISA ADP Vulnrichment reports the exploitation status as 'poc'. ([github.com](https://github.com/stacklok/toolhive/security/advisories/GHSA-qg2g-g9w3-m5h8), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58197.json))
Affected: ToolHive CLI versions before 0.30.1 and ToolHive Studio versions before 0.38.0. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58197.json))
Fix: ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0. ([raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58197.json))
Action: Map CVE-2026-58197 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-qg2g-g9w3-m5h8)
Finding 14 — Multiple vulnerabilities in Capsule
What changed: CVE coverage: CVE-2026-61795, CVE-2026-61672, CVE-2026-61794. The cited advisories disclose: hostnameRegexHandler.OnUpdate validates stale Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation; Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement; Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic.
Technical evidence: CVE-2026-61672; CVSS v3.1 7.1; weakness CWE-697, CWE-863; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patched, restrict Tenant configuration updates to trusted administrators and reject updates when AllowedHostnames.Regex or ForbiddenAnnotations.Regex does not compile. Keep forbidden metadata exact-match lists uniformly lowercase. ([github.com](https://github.com/advisories/GHSA-f94q-w3w8-cj67), [github.com](https://github.com/advisories/GHSA-gjw4-3v3v-rqxg), [github.com](https://github.com/advisories/GHSA-gxjc-74v5-3vx3))
Affected: CVE-2026-61795 and CVE-2026-61794: >= 0.13.0, < 0.13.7; CVE-2026-61672: <= 0.13.6. ([github.com](https://github.com/advisories/GHSA-f94q-w3w8-cj67), [github.com](https://github.com/advisories/GHSA-gjw4-3v3v-rqxg), [github.com](https://github.com/advisories/GHSA-gxjc-74v5-3vx3))
Fix: 0.13.7 for all three CVEs. ([github.com](https://github.com/advisories/GHSA-f94q-w3w8-cj67), [github.com](https://github.com/advisories/GHSA-gjw4-3v3v-rqxg), [github.com](https://github.com/advisories/GHSA-gxjc-74v5-3vx3))
Action: Map CVE-2026-61672 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-f94q-w3w8-cj67)
Finding 15 — Drupal core: Third-party libraries vulnerability (SA-CORE-2026-013)
What changed: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits:** grounded severity unavailable
exploitation reported by the source, not independently corroborated
fixed version or patch state unknown
[Evidence source: drupal.org](https://www.drupal.org/sa-core-2026-013)