Severity Daily

IT and AI security incidents, checked against the primary source

In five of today’s nine stories, the version field is the part that’s wrong

DAILY RECAP — In five of today’s nine stories, the version field is the part that’s wrong

Written by

in

Patch Cisco Secure Email Gateway first, and do it before Thursday. Cisco’s advisory, published Monday at 11:00 a.m. Central, describes an unauthenticated flaw that runs arbitrary commands as root, reached by sending the appliance an email — the one input a mail gateway cannot decline. Cisco says it became aware of active exploitation this month, and that there are no workarounds. CISA put the CVE on the federal catalog the same afternoon with a September 17 deadline and a forensic-triage obligation, meaning agencies must not only remediate but also determine whether the box has already been used. Three days, an appliance that sits at the edge, and no mitigation short of the upgrade.

That outranks the story with the bigger name on it. CenterPoint Energy told the SEC on Monday evening that an unauthorized third party took customer personal information from an external-facing system, then gave no count, no date, no system name, and no data types — filed under Item 8.01 rather than the breach item. It is the day’s most consequential story for the people whose information is in that file and the least actionable one on the site tonight. There is nothing in it to patch, block, or notify against.

The thread runs through most of the rest: in five of today’s nine stories, the field you would patch from is the field that is wrong. Froxlor’s CVE says the flaw was fixed in 2.2.5; the newline check first appears in 2.3.8, twelve releases and 19 months later. CVE-2026-57127’s machine-readable range stops ten releases short of the version its own description names, one of sixteen PraisonAI records published Monday against fixes that shipped in June. Three SIPp buffer overflows are fixed on master and in no release at all, because there has not been one since 3.7.7. Strapi’s June fix never reaches the 4.x branch, which went end-of-life in April and still ships the flaw. And the Cisco record’s own version list stops short of one of the three release trains Cisco says is affected. A scanner reading those five records gets five different wrong answers about what to install.

Apache Storm is the same failure one layer up: fourteen CVEs published Monday with almost no severity data, backfilled by CISA’s data publisher five hours later, and on the one record Apache had scored itself the two numbers are 10.0 and 6.5. MISP is the day’s clean one and the next thing to do after Cisco — an empty password accepted as a valid login through the LDAP and LinOTP plugins, fixed in 2.5.46, with the CVE four days behind the release. And Langflow’s component scanner ran the code it was checking and reported “validated: true”; the fix reached PyPI on June 23 and the CVE record arrived Monday evening, 83 days later.

Still open. Cisco’s deadline is Thursday and the CVE record still lists no fixed 16.5 build, so anyone on that train has to work from the advisory rather than the record. Froxlor’s advisory and its CVE both still name 2.2.5, and neither has been corrected. Apache Storm’s CVE-2026-82434 carries a 10.0 and a 6.5 from two publishers, and neither has been withdrawn. SIPp and Strapi both have code that fixes the flaw and no release a 4.x or packaged user can install. And CenterPoint has still not said how many people are in the file.