Risky Business · Tuesday, September 29, 2026
HD Moore argued that vulnerabilities without CVEs are the most dangerous because they indicate active exploitation in the wild that is likely unknown to defenders. He noted that many exploited bugs do not have CVEs and that vendors are slow to accept or patch disclosed vulnerabilities.
“I can tell you, we did a disclosure process for Open BMC, which is kind of the underpinnings of all modern BMC implementations these days.”
“So you go from zero to root on every device that's running this BMC stack, that is now the most popular stack in the world for managing every server out there, including the hyper scalars.”
“And if you're seeing exploitation out there, and you're not seeing a CVE associated with it, that's the thing that should scare you. That's the thing that should make you wake up.”