Full Look Back: the trigger the advisory describes that does not exist in the code, why Red Hat rated it Low, and the second fix in the same commit that no advisory mentions: https://t.co/DP9AAXtANT
LOOK BACK: In 2020, Authlib added two lines letting a JWT header supply the key used to verify that same JWT. A 2022 fix narrowed the condition. In Feb 2026 it was finally deleted. CVE-2026-27962, CVSS 9.1, and six months on nobody has been seen exploiting it.
DEEP DIVE: CVE-2026-58704 is a zero-click permission bypass in the Pixel cellular modem, exploited in targeted attacks. Check one string: adb shell getprop https://t.co/c8ZcgH9HxE_patch. Below 2026-09-05 you are exposed, and the September 1 patch level is not enough.
DEEP DIVE: CVE-2026-76460 is a CVSS 10.0 auth bypass in Cisco ISE, KEV-listed the day it was disclosed. Patches shipped that same day: 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4. The 3.0 train gets no fix at all. Check yours: show application version ise
Full Look Back: three severity scores from one submission, an affected-version range no scanner can read, and why the agreed PR:L predicted the outcome better than the 9.9 did: https://t.co/aTnx9Xh2Aw
LOOK BACK: A CVSS 9.9 RCE on Veeam backup servers, in a product with four ransomware-linked entries in CISA KEV. Six months on, CVE-2026-21666 has no KEV listing, no PoC and no exploitation. The best-documented thing about it turned out to be its paperwork.
DEEP DIVE: CVE-2026-76461 is an unauthenticated SQL injection in Cisco Secure Email Gateway that reaches root by email. No HTTP request, no login, no user click: just a crafted message the gateway exists to accept. KEV-listed the day Cisco published. No workaround.
LOOK BACK: CVE-2026-3381 shows as 9.8 CRITICAL. The CNA that assigned it supplied no score at all. A Perl module bundles its own copy of zlib, and zlib had a medium-severity infinite loop in a CRC helper. Six months on: no exploitation, not in KEV, EPSS 0.55%.