Severity Daily

IT and AI security incidents, checked against the primary source

Tag: UNFI

  • Two 10.0s drew a Friday federal deadline, and in half of today’s stories the vendor contradicts its own record

    Two 10.0s drew a Friday federal deadline, and in half of today’s stories the vendor contradicts its own record

    The most important thing today is a date: Friday, September 11, 2026. CISA added two flaws scoring 10.0 to the Known Exploited Vulnerabilities catalog on September 8 and put the same three-day due date on both. Adobe Commerce is exploited in the wild by Adobe’s own statement, needs no authentication, and affects every supported branch of Commerce, B2B, and Magento Open Source. N-able N-central is pre-authentication remote code execution in the platform managed service providers point at their clients’ networks.

    The biggest-sounding story of the day is neither of them. Veradigm told the SEC that an attacker took credentials from a third-party vendor, used them against a Veradigm API, and downloaded patient data including Social Security numbers. For the people in that file it is the worst thing on the page. For anyone deciding what to do before Friday it is inert: the filing names no vendor, no date, and no count. The two KEV entries come with a deadline inside the week and something to install. That is why they lead.

    The thread

    Six of today’s twelve stories — exactly half — are a vendor’s own record disagreeing with itself. N-able’s status page says there are no confirmations of exploitation while its blog says the opposite, on the CVE CISA has now listed as exploited. Microsoft marks both of today’s Windows zero-days exploited, then ships a temporal vector on one of them reading E:U, exploit code unproven. SAP scores a flaw its record describes as a crash at 10.0 and one describing a rogue application server at 9.8, and the entire gap is one scope metric. Siemens splits one broken session token in the Reyrolle 7SR5 into three CVEs, and its own v3.1 and v4.0 vectors disagree on how hard one of them is to attack. Ivanti published three ITSM records with byte-identical descriptions and the same weakness class, two scored 8.8 and the third 9.9. Adobe stamps its ColdFusion bulletin Priority 1 and says in the same document that it is aware of no exploits.

    The score, the severity label, and the exploitation status are produced by different processes inside the same organization, and today six of them shipped out of step. The consequence is the same every time: the number you sort your queue on is not the number that tells you what to do.

    The rest, in the order it deserves attention

    Behind Friday, the same Microsoft release carries two Windows local privilege escalations at 7.8 with a September 22 federal deadline. The ColdFusion bulletin covers nine CVEs across both shipping releases. Ivanti Neurons for ITSM shipped eight CVEs, two of them unauthenticated deserialization at 9.8. Snowflake’s drivers attached a cloud workload-identity token to the login request before checking the host was Snowflake, across eight driver lines. Siemens Siveillance Control fixes a root-level file upload in which each of four editions has a different build number meaning “fixed.” On the filings side, Boston Scientific escalated to Item 1.05 and named the 2026 guidance it will miss, and United Natural Foods booked its June 2025 attack as a $21 million credit, because $45 million of insurance arrived a fiscal year after the costs it covers.

    Still open

    Adobe’s remediation for the Commerce 10.0 is a composer patch, and the bulletin’s solution column still carries no version number: agencies have until Friday to apply something they cannot cite by version. N-able has not reconciled its two live statements, and NVD’s affected list includes Hotfix 3, the build N-able told on-premises customers on September 5 to install immediately. Fourteen days after the attack, Boston Scientific still has not said whether anything was taken. Veradigm has not named the vendor whose credentials were stolen, or how many people are in the file.

    Sourcing note: this page adds no facts to the stories it links; each carries its own primary source. The September 11 and September 22 deadlines were re-confirmed tonight against NVD, which republishes CISA’s cisaExploitAdd and cisaActionDue verbatim. NVD was inconsistent while that was done: within one hour the same API returned a stale copy of CVE-2026-75650 with no CISA fields and then the current record at lastModified 2026-09-08T19:29:17.803 carrying them, and returned totalResults of 0 for both Windows CVE IDs on two query forms before returning the full records on a third. All four deadlines are confirmed. The lesson for anyone checking these dates themselves is that a single empty NVD response is not evidence of anything — query again before concluding a record is missing. cisa.gov blocks automated fetching directly.

    Correction, September 8, 2026: an earlier version of this sourcing note, live for roughly three minutes after publication, said NVD “returned no record at all for either Windows CVE at the time of writing.” That described two failed queries, not the state of the catalog. Both records were retrieved in full on a retry and carry a cisaActionDue of 2026-09-22. The note above has been rewritten.

  • United Natural Foods books its cyberattack as a $21 million credit — insurance recoveries beat costs, and the two-year total is $5 million

    United Natural Foods books its cyberattack as a $21 million credit — insurance recoveries beat costs, and the two-year total is $5 million

    The June 2025 attack that halted a $31 billion food distributor now shows up in its annual results as a negative adjustment, because $45 million of insurance arrived in a later fiscal year than the costs it covers.

    What happened

    United Natural Foods, Inc. filed a Form 8-K under Items 2.02, 8.01, and 9.01 on Tuesday, September 8, 2026, accession number 0001020859-26-000022, accepted by EDGAR at 7:02:12 a.m. ET. The Item 8.01 is a $200 million share repurchase authorization and has nothing to do with security. The security content is in the Item 2.02 exhibit: the fourth-quarter and full-year earnings release for the fiscal year ended August 1, 2026.

    UNFI is the largest publicly traded grocery wholesaler in North America and reported full-year net sales of $31,152 million. It disclosed a cybersecurity incident in June 2025, in the fourth quarter of its fiscal 2025, that disrupted ordering and distribution across its network. Today’s release carries the first full fiscal year of that incident’s accounting tail, and the shape of it is worth reading closely.

    In the reconciliation from net income to Adjusted EBITDA, the line is labeled “Cybersecurity incident.” For fiscal 2025 it carried $26 million, all of it in the fourth quarter. For fiscal 2026 it carries $(3) million in the fourth quarter and $(21) million for the full year, shown in parentheses. The sign is not a typo. Footnote 5 explains it, and the wording is the story:

    “Fiscal 2026 includes $45 million of insurance recoveries, which are included within Operating expenses in the Consolidated Statements of Operations, partially offset by $24 million of costs and charges related to the June 2025 cybersecurity incident, of which $20 million is included within Gross profit and $4 million is included within Operating expenses in the Consolidated Statements of Operations. Fiscal 2025 includes costs and charges related to the cybersecurity incident, of which $15 million is included within Gross profit and $11 million is included within Operating expenses in the Consolidated Statements of Operations.”

    So: $26 million added back in fiscal 2025, $21 million subtracted out in fiscal 2026. Across the two fiscal years the “Cybersecurity incident” line nets to roughly $5 million. Full-year Adjusted EBITDA was $701 million in fiscal 2026 against $552 million in fiscal 2025, and GAAP net income was $84 million.

    On sales, the release says only this: “Sales in the fourth quarter of fiscal 2025 were impacted by the previously disclosed cybersecurity incident experienced in the fourth quarter of fiscal 2025,” and elsewhere refers to “lapping last year’s cybersecurity event.” No dollar figure is attached to that impact anywhere in the document. Fourth-quarter fiscal 2026 net sales were $7,642 million, down 0.7 percent against the quarter the incident depressed. The release states no cumulative cost of the incident, and the fiscal 2027 outlook does not mention it.

    Why it matters

    Severity Daily reported yesterday on Ardent Health’s ransomware carve-out, where a 2023 incident’s financial consequence surfaced thirty-four months later inside a non-GAAP definition. UNFI is the same mechanism running faster, and it exposes the part that a single-year read gets wrong: the sign.

    Anyone who pulls UNFI’s fiscal 2026 results and looks for the cyber line finds a negative number. Read alone, that number says the incident helped. Anyone who pulled fiscal 2025 found $26 million of pure cost. Neither year is the answer, and neither year is wrong — they are two halves of one event separated by an accounting boundary, because insurance claims settle on a slower clock than the costs they reimburse. A screen, a model, or a peer comparison that samples one fiscal year of a multi-year incident will get a number whose sign depends entirely on which year it sampled. That is not a UNFI problem. It is the structural shape of every cyber incident large enough to trigger a material insurance claim.

    The second thing to hold onto is what the line is and is not. It is incremental costs and charges, net of insurance recoveries. It is not the cost of the incident. Three categories sit outside it and are visible nowhere in this document. Lost sales, which the company says occurred and does not quantify. Security spending that became ordinary course after the incident and therefore stopped being an adjustment. And customer and contract effects that show up, if at all, in the top line rather than in an add-back. The fourth-quarter number makes the point: net sales fell 0.7 percent against a quarter the company itself describes as depressed by the attack. That is a comparison flattered by a weak base and still down, and no line in the reconciliation captures whatever explains it.

    Third, the disclosure is complete on its own terms and thin on the one number a reader most wants. UNFI names the incident, names its month, splits the costs between gross profit and operating expenses, and states the insurance figure. That is more granularity than most registrants give. It still does not say what the incident cost in total, and because the two fiscal years point in opposite directions, the cumulative figure is the only one that means anything — and the reader has to build it themselves from two documents filed a year apart. There is no rule requiring a cumulative disclosure, which is precisely why the absence is worth naming.

    Finally, the insurance number deserves its own attention: $45 million recovered against $24 million of same-year costs and $26 million the year before. Recoveries of that size, arriving roughly a year after the event, are the strongest public evidence to date on what a large cyber policy actually pays and when. It is one data point, and the policy terms, retention, and sublimits are not public. But it is a real number attached to a named incident at a named company, which is rarer in this field than it should be, and it is a better input to a cyber-insurance conversation than any vendor survey.

    What to do

    If you model or benchmark cyber incident costs, take the cumulative, never the annual. For UNFI that is $26 million in fiscal 2025 less $21 million in fiscal 2026, or about $5 million net, and it is net of $45 million in insurance rather than gross of it. Any benchmark built from single-year add-backs is measuring the timing of insurance settlements, not the severity of incidents.

    If you are building a business case for cyber insurance, this is a usable data point. A distribution-halting incident at a $31 billion wholesaler produced $45 million in recoveries booked in the following fiscal year. Note the lag as carefully as the amount: the costs hit one year and the recoveries the next, so the cash-flow and covenant picture in the incident year is the gross number, not the net.

    If you sit in finance or FP&A at a company that has had an incident, decide now how you will present year two. The reversal in year two is arithmetically correct and reads badly if it arrives without explanation. A single sentence giving the cumulative figure costs nothing and removes the ambiguity that this filing leaves open.

    If you are a UNFI customer or supplier, the operational story is over and the disclosure story is not. There is nothing to patch and nothing to act on defensively here. The open item is what the incident actually cost, which remains unstated and is not derivable from any single filing.

    Sourcing note

    Checked. United Natural Foods’ Form 8-K, accession number 0001020859-26-000022, read from SEC EDGAR; the acceptance timestamp of 7:02:12 a.m. ET and the item designations come from the filing index and directory. All quoted language and every figure above come from the exhibit filed with it, the fourth-quarter and fiscal-year 2026 earnings release, including footnote 5 to the non-GAAP reconciliation, quoted in full. Fiscal 2026 is the 52 weeks ended August 1, 2026; fiscal 2025 is the 52 weeks ended August 2, 2025. The Item 8.01 in this filing concerns a $200 million share repurchase authorization and is unrelated to the incident.

    Could not reach. cisa.gov returns HTTP 403 to automated fetching. No agency advisory relates to this filing and none was sought beyond that.

    Unresolved. The total cost of the June 2025 incident, which the company has not stated and which cannot be derived from this release alone. The dollar value of sales lost in fiscal 2025, which the release says occurred and does not quantify. The terms, retention, and limits of the insurance that produced the $45 million recovery. Whether further recoveries are expected. And whether the 0.7 percent fourth-quarter sales decline against a cyber-depressed prior-year quarter reflects any residual effect of the incident — the release does not say, and this page does not assert that it does. The $5 million two-year net figure above is arithmetic performed by this publication on the company’s two reported annual figures, not a number the company has published.