The biggest-sounding item today is F5’s, and it is not the one to deal with first. F5 published seven records at once, led by an access-control module that lets the request through when its own code throws an exception. But those flaws became public and became fixable on the same afternoon. That window opens now and closes as fast as you patch.
The two worth handling first are months older than that. Team Password Manager’s unauthenticated password-reset bypass was fixed on March 10 and announced five days later as the third bullet in a post about a Chrome extension release, under the heading “Security improvements,” as “Fixes for vulnerabilities in the user password reset functionality.” The record calling it a 9.1 unauthenticated account takeover in a credential store arrived 176 days later, at 1:17 a.m. UTC this morning. Amelia’s WordPress booking plugin shipped its fix on July 7, in a release whose entire security note was eight words the vendor has now used in six releases this year; the 9.8 record describing an anonymous path to WordPress administrator landed today. In both cases the exposed population is defined by not having applied a patch that has been available for months, and today is the day an attacker got a working description of it. The defenders never got a signal at all.
That distance is the day’s thread, and it runs in both directions through six of the eight stories. Proxmox is the extreme case: a July 2023 refactor closed an unauthenticated login bypass in VE 7, and the advisory published Tuesday says plainly that “the rework was not a security fix, and the issue had neither been found internally nor reported.” The patch worked for three years without anyone knowing what it was. Running the other way, Red Hat’s submariner record carries a 9.1 and no fixed version for anything, three new rpm command-injection records carry mitigations and no confirmed errata, and four of the seven AI coding agents that run attacker code out of a repository’s .git/config still have no fix at all.
After those two, order the rest by exposure. F5 next: njs 1.0.1 closes the fail-open access check, a pre-authentication heap write reachable through the nginx-saml reference implementation, and a worker crash — and the BIG-IP record in the same batch, where an authenticated user of any role can create administrative accounts, has no workaround. Then the rpm batch, because the “user interaction required” in all three vectors is satisfied by a build pipeline running on schedule, and RHEL 7 through 10 are in scope for one of them. Then the .git/config class, which is a one-line grep across your developers’ checkout directories tonight. Jolokia 2.6.2 is an upgrade with a behavior change attached — proxy targets are denied by default afterward — so read the release note before you ship it. Submariner is one field in one custom resource: if IPSecCertAuthMode is false, you are out of scope. Proxmox VE 7 has been end-of-life since July 2024 and the fix has existed since 2023; if you are still running it, that is the finding.
What is still open. Red Hat named Advanced Cluster Management 2 affected by the submariner flaw twelve days after its own stated public date, with no errata, no fixed package, and no per-product state — not even “will not fix.” Fixed versions for the three new rpm records could not be confirmed; Red Hat’s machine-readable endpoint returned 404 for all three. Amelia has published no advisory for a 9.8, and Team Password Manager none for a 9.1 — whose record is still “Received” at NVD, so scanners matching on CPE will not flag an affected install until analysis completes. Manifold Security says six attempts to reach the Hermes Agent maintainers produced no triage, and the VulnCheck identifier for that finding is assigned but unpublished. Nothing today is in CISA’s Known Exploited Vulnerabilities catalog, and no federal remediation deadline attaches to any of it.
