“Reachability Watch” for September 4 – 10, 2026: Four different CVEs, but they have the same shape! 0 ▲ Global Nerdy 2 hours ago · Tech · hide · 0 comments The latest edition of NetFoundry’s regular Reachability Watch articles, covering September 4 – 10, 2026 and written by Mark Jaffe, our Chief Strategy and Marketing Officer, is up: https://netfoundry.io/ai/reachability-watch-cve-kev-tracker-2026-09-11/ And with this edition, a new “back of the envelope” drawing by Yours Truly, which shows the “env var” pattern behind two of the CVEs in this report. In this edition: 906 new network-exploitable CVEs 96 clearing the CVSS 8.6+ bar 5 at a perfect 10.0 Microsoft shipped 15 critical network CVEs in a single release, 14 of them at 9.8, across DNS, DHCP Server, RPC Runtime, USB Mass Storage, and Telnet Client. The most notable part of this Reachability Watch is this set of CVEs: CVE-2026-86124 (9.8): AutoAgent’s inter-agent TCP server executes whatever you send it, as root, with no authentication in the request path at all CVE-2026-86121 (9.8): Same outcome in Cua’s computer-server, gated on CONTAINER_NAME being set CVE-2026-85661 (9.8):… No comments yet. Log in to reply on the Fediverse. Comments will appear here.