The most consequential thing on the site today is not the 10.0. It is a three-day federal clock that runs out on Sunday. CISA added two of the three exploited MikroTik RouterOS flaws to the Known Exploited Vulnerabilities catalog on September 10, due September 13, and left off the SSH authentication bypass that CERT Polska puts first in the chain. Exploitation is confirmed by a national CERT, all three flaws are closed by the same RouterOS releases, and Shadowserver counts at least 122,500 MikroTik devices with SSH reachable per 24-hour scan window. An agency that upgrades is fine. An agency that works the catalog as a queue — patch what is listed, ticket what carries a due date — finishes Sunday compliant and still reachable through the door the catalog does not name.
The biggest-sounding story is GitLab’s, and it ranks second. An unauthenticated arbitrary file read in the repository commits API, scored 10.0, is as bad as a number gets, and the research published on September 11 describes reaching configuration files, credentials, tokens, and SSH keys. But nobody has confirmed exploitation — watchTowr reports probes, and probing is not exploitation — and the 10.0 is GitLab’s own, with NVD returning no record at all as of early this morning. Recompute the vector without the integrity impact the advisory’s own description does not describe, and it is an 8.6. What is not in dispute is the work: self-managed operators have a critical to install, and some of them cannot.
That last clause is the day’s thread, and it runs through three of the eight stories. GitLab names installations from 18.7 as affected and ships no 18.x build in the release, so a shop sitting on 18.7 through 18.11 is inside the affected range and outside the branch that got the fix — a major-version migration, not a patch. CISA put two more JFrog Artifactory flaws on KEV with a September 25 deadline, and on the 7.133 branch their fixes are seventeen patch releases apart: an administrator who took 7.133.11 in July to close CVE-2026-42016 is still exposed to CVE-2026-42018 today, and a version check that stops at 7.133.11 reports the box clean. And CISA’s MikroTik entries cover two links of a three-link chain. In each case the fix on offer covers less than the flaw does, and in each case you see it only by reading two documents side by side.
The other four are disclosure stories, and what they share is an absence. Florida’s motor vehicle agency confirmed that DAVID, its law enforcement driver database, was breached through credentials a Plant City police employee stored on a personal device, and named no number; every figure in circulation — 200,000 records, Social Security numbers, and dates of birth — belongs to ShinyHunters. Nutex Health’s stolen data has been published online, and the company filed that under Item 8.01 with its materiality assessment unchanged, no count and no dates. Conduent settled the class action over its January 2025 breach with no dollar figure, also under Item 8.01, having filed the incident itself under Item 1.05. Greenberg Traurig told Vermont and California regulators that Social Security numbers were in scope on September 8 and September 9, then publicly called the exposure limited on September 10. Furthest from an action item, Anthropic’s misuse report describes one actor working through roughly thirty AI companies in about four days, swapping in each victim’s own API keys as it went — a billing and attribution problem as much as a security one.
Open tonight. CVE-2026-67276, the MikroTik bypass, still carries no exploit-add date and may yet be added; worth re-checking before Sunday. CISA’s alert for September 11 is titled as one catalog addition while two records carry that day’s exploit-add date, and cisa.gov returns 403 to automated fetching, so the count could not be reconciled. GitLab has said nothing about the 18.x case. The distillation claim circulating in coverage of the Anthropic report — seven named Chinese labs, industrial scale — does not appear in the document we read. And four organizations described a breach today without producing a number. Nutex says its review will take several weeks.
