The most important thing published today is not the day’s highest score. HAProxy CVE-2026-90678 is a 7.5, against a 9.8 for sngrep’s stack overflow. HAProxy outranks it on where it sits and on what a reader can do about it. A remote, unauthenticated HTTP/3 client can desynchronize reused backend connections, slip requests past a frontend deny rule, and swallow other users’ Authorization headers — at the edge, in front of everything behind it. And the fix is a commit, not a release: 3.3.14 and 3.4.4 are the newest builds on their maintained branches and both sit inside the affected range, which makes “update to the latest version,” the advice most coverage will give, wrong. sngrep’s 9.8 is real, but it is a terminal SIP viewer an operator points at traffic by hand, the blast radius is one workstation, and its fix is likewise a commit on master that no tagged release and no Debian package carries.
There is a thread, and it is the day’s actual story. In seven of the nine stories published today, a fix exists somewhere other than in something you can install. HAProxy’s and sngrep’s are commits. snappy-java’s 7.5 out-of-bounds write has no fix at all — the newest artifact on Maven Central was published in July 2025 and is the top of the affected range. LangBot 4.10.11 generates its new recovery key only when none exists, so upgrading leaves an existing installation holding the 24-bit secret the release was cut to replace. ESPnet’s patched release raises an error below PyTorch 2.6 while its own metadata still declares torch>=2.3.1, so an install that satisfies the declared dependencies gets a fixed path that throws and unfixed paths that run. Nodemailer’s denial of service was introduced by the security fix in 9.1.0 and repaired only in 10.x, so a 9.x user has to cross a major version to escape it. And Really Simple Security’s fix has been auto-updating to three million sites since September 1 under a changelog line that reads like a display bug: the code arrived, the reason to care did not.
Order of business behind HAProxy. LangBot next, because the reset endpoint is unauthenticated and the remedy is a key rotation by hand that the upgrade will not perform for you. Then ESPnet and Nodemailer, both dependency audits rather than emergencies. Really Simple Security mostly needs confirmation that auto-update ran. snappy-java is availability-only and lands on the one decompression call that makes the caller size its own output buffer. Two records close the day: Flowise’s cross-workspace credential flaw, patched in July and given CVE IDs on Friday, six weeks later and by a third-party CNA rather than the vendor; and Internet Download Manager’s kernel driver, where a public proof of concept turns idmwfp.sys into an arbitrary registry write for any logged-in user and the vendor, by the CVE record’s account, has not responded.
Still open at the end of the day. Two federal deadlines come due tomorrow: NVD’s records for ConnectWise ScreenConnect CVE-2026-84869 and GitLab CVE-2026-85706 both carry a cisaActionDue of 2026-09-14, Monday, September 14, 2026. Tonec has said nothing about the IDM driver, so there is no patch to wait for. snappy-java has shipped no release in more than a year. And Flowise is the day’s inverse case, worth keeping in view: the code was fixed on time, and the record took six weeks to say so.
