A newly disclosed vulnerability, CVE-2026-84434, was reportedly exploited in the wild at least one day before its official publication date, leaving no window for affected parties to patch systems prior to active attacks. The CVE was reserved on September 1, 2026, and officially published on September 19, 2026. However, evidence of exploitation first appeared on September 18, 2026, according to a commercial vulnerability intelligence platform.
The vulnerability's exploitation was noted in a single catalogue, VulnCheck KEV, which listed it on September 18, 2026. This claim is mirrored by the CIRCL aggregator, though CIRCL itself does not independently verify exploitation. As of the latest information, neither the CISA KEV (US federal) nor the EUVD (ENISA, European Union) catalogues have listed CVE-2026-84434 as actively exploited.
Public evidence of exploitation was reported on September 18, 2026, with a specific reference to a vulnerability within the Gravity Forms WordPress plugin, as documented on patchstack.com. This public report was collected by VulnCheck and CIRCL. The nature and extent of these reported exploits have not been independently verified by all sources.
The vulnerability has an EPSS (Exploit Prediction Scoring System) score of 0.70%, placing it in the 51.6th percentile, indicating a moderate likelihood of exploitation. No CVSS severity score has been assigned to CVE-2026-84434 at this time.
The timeline of the vulnerability shows a rapid progression from its first reported exploitation to its public disclosure. With the first KEV listing occurring on September 18, 2026, and the CVE being published on September 19, 2026, organizations had no opportunity to implement patches or mitigations before the vulnerability was actively targeted. The last reported sighting of exploitation also occurred on September 18, 2026.





