A vulnerability identified as CVE-2017-20284 was reportedly exploited in the wild on the same day it was publicly disclosed, September 18, 2026. This rapid exploitation occurred without a discernible patch window, as the vulnerability was reserved, published, and first listed as exploited on the same date.
The claim of active exploitation is primarily supported by a listing in the VulnCheck KEV (Known Exploited Vulnerabilities) catalog, which recorded it on September 18, 2026. This information was mirrored by the CIRCL aggregator, though CIRCL is not considered an independent corroborating source. Neither the CISA KEV (US federal) nor the EUVD (ENISA, European Union) catalogs currently list CVE-2017-20284 as exploited.
Public exploitation evidence was cited from two reports collected by VulnCheck and CIRCL, both dated September 18, 2026. These reports link to external sources, specifically previdian.com and cve.org, which are stated to have reported the exploitation. The accuracy of these external reports has not been independently verified.
The vulnerability's CVSS severity score is not specified, but its EPSS (Exploit Prediction Scoring System) percentile is 60.0%, with an EPSS score of 0.96%. The rapid exploitation timeline, with no gap between disclosure and observed exploitation, highlights the immediate threat posed by such vulnerabilities.
The last recorded sighting of exploitation for CVE-2017-20284 was also on September 18, 2026, coinciding with its initial disclosure and exploitation reports. This incident underscores the challenges in providing timely patches and defenses against vulnerabilities that are immediately leveraged by attackers upon public release.






