The vulnerability, CVE-2026-1731, is a pre-authentication remote code execution flaw that can be exploited through low-complexity attacks requiring no user interaction.
The paper reveals that only 32% of vulnerabilities in the CISA KEV catalog are immediately exploitable for initial access, challenging the common misconception that it lists the most severe flaws.