The item to act on tonight is JFrog Artifactory, and not for the reason the wire makes it look like. CVE-2026-82329 is a 9.8 authentication bypass that watchTowr says attackers were already using to mint themselves administrator tokens by September 1. What makes it the day’s top story is the arithmetic underneath it. A different Artifactory flaw, CVE-2026-66384, carries a federal remediation deadline of September 10, and the builds that satisfy that deadline — 7.146.35 and 7.161.16 — sit below the builds that fix the new one, 7.146.38 and 7.161.20. An administrator who works the deadline correctly ends up compliant and exploitable at once. That outranks louder items on the page because it is the only story today where doing the prescribed thing produces the wrong outcome. It comes with a real caveat: the exploitation claim rests on one firm, JFrog has not confirmed it, and the CVE is not in the KEV catalog, which is why the story is filed as developing.
There is a thread today, and it is narrower than the usual complaint about incomplete records. Six of today’s eleven stories fail at the same field: which version fixes it. HPE published 81 CVE records for Aruba AOS-CX and Fabric Composer inside one hour, every one naming the last affected version rather than the fixed one, and the page that would name the fix does not render without JavaScript. Langflow’s record names no fix at all. Cobham Satcom’s maritime VSAT router has a public exploit, no fixed firmware, and a record stating the vendor never replied. WPLP Cookie Consent shipped a fix for unauthenticated file upload reaching code execution and called it “improved validation” in its release notes. And Nokri’s job board theme accepts an empty password-reset token again, eighteen months after the version that was supposed to have settled it.
After Artifactory, work the clock. CISA put both PaperCut zero-days in the KEV catalog on August 31 with a September 14 deadline, then rewrote its own exploitation assessment of them from “none” to “active” that same afternoon — and the two records disagree on two of the four variables that drive a federal deadline while landing on the same date. Langflow is next and is not a patching problem: VulnCheck’s decoys logged more than 360 attempts in two days, the payloads read straight for OpenAI and AWS keys, and there is nothing to install, so the answer is to take it off the internet. The HPE batch is a scoping job before it is a patching job. Cobham is a fleet you cannot patch and have to compensate for, and the two WordPress items are a same-day update if you run either.
The rest is record-keeping, which on this site is not a demotion. Kyverno picked up six CVEs in 38 seconds from a third-party CNA, one of them scored 3.7 and 9.3 on the same record, while the project’s own advisories still say “No known CVE.” Forescout moved a five-year-old Siemens Nucleus overflow onto a second WAGO controller for $535.74 and eight and a half hours of AI-assisted work, then bricked the device — the cost line is the finding, and so is the brick. Two 8-Ks went in the same day from opposite directions: Park Dental Partners used Item 1.05, the item reserved for material incidents, and then said it has found no material impact, while NovoCure filed over 1,400 exposed patient records under Item 8.01 and wrote its own 1.05 trigger into the text.
Open going into tomorrow: JFrog has not confirmed exploitation or answered press questions, and CVE-2026-82329 has no KEV entry, so the September 10 trap is currently documented by one security firm and a version comparison. Langflow’s published advisory list still does not contain the CVE being exploited against it. Cobham has not replied to the researcher. And two federal deadlines are now live in a two-week window — September 10 for Artifactory, September 14 for PaperCut — with the first of them, on today’s evidence, pointing at a build that does not close the door.
