The lead today is an 8.8, and it outranks two 10.0s. Chrome’s V8 type confusion bug is the only thing published today that pairs confirmed exploitation with an exact build and an exact date: CISA added it to the Known Exploited Vulnerabilities catalog on September 4 and set federal remediation for September 18. Microsoft’s eight cloud CVEs, two of them scored 10.0, are the larger number and the smaller job: not one carries an affected version, because the fixes went in service-side. There is nothing to deploy and no way to establish from the record whether you were ever exposed. One of these two items creates work on Monday; the other creates a note in a file. Read the Chrome entry’s scope carefully, though — CISA filed it under Chromium rather than Chrome, which is a much wider surface than the browser on your standard image.
That contrast is the day’s thread, and it runs through most of it. Seven of today’s eleven stories end without a version number you could hand to a patch queue. Microsoft names no affected version. goose’s new CVE names no fixed version, and the affected range runs through a build that shipped yesterday. The fix for the unauthenticated message bus in MOOS is an unmerged pull request. Postgres MCP Pro has no fix at all. python-jose is an incomplete fix for a 2024 CVE, which means the version you already installed was not one. IXON’s root-level VPN client flaw was cut off cloud-side 30 days before the record landed, and the record does not mention it. And IBM named two different Langflow fix versions in one day. This is not a scoring problem. It is a record that has stopped answering the only question a patch queue asks.
After Chrome, the order is roughly by how much of it is yours to fix. Lightstar’s SmartIT Desktop Manager ships agent credentials in source code across four CVEs, two of them 9.8, in a product that by design holds privileged reach into every endpoint it manages; the remediation is a major version upgrade, not a patch, so it is a project rather than a change ticket. IBM Langflow is next and messier: nine records arrived this morning, seven days after the bulletins that fixed them, and eight more followed in the afternoon pointing at a different fix version. If you run Langflow, verify which version you are actually being told to install before scheduling anything. Then the Postgres MCP pair, where two servers lost read-only enforcement on the same day and AWS’s answer was a longer denylist — worth knowing if an agent has a database connection you believe is read-only. Google’s Agent Development Kit read any file for an unauthenticated caller and the record landed 239 days after the code was fixed, so exposure here depends entirely on when you last updated. goose, python-jose, and the 33-CVE MOOS batch round it out; MOOS is narrow unless you operate marine autonomy, and python-jose is the one to grep your dependency manifests for.
Still open: IBM has two bulletin identifiers with no CVE record at all, and two fix versions on the record that need reconciling. Postgres MCP Pro has no patched release. The goose issue behind today’s CVE was filed on July 8 and is still open eight releases later. The MOOS pull request is still unmerged. And the Chrome deadline is September 18, which is a two-week clock on a bug that is already being used.
