Registries stayed relatively quiet today — the only active poisoning story is RubyGems' StubMaker campaign, which resurfaced with sixteen new typosquats after RubyGems pulled its first two accounts within hours, a genuinely fast takedown worth noting.
The bigger signal came from CISA: four unrelated products — Windows' IKE service, VMware vCenter, SharePoint, and macOS Screen Sharing — all landed on the Known Exploited Vulnerabilities catalog the same day, spanning Microsoft twice, Broadcom, and Apple. That's an unusually wide vendor spread for one KEV batch and reads as four separate active-exploitation events rather than one campaign; vCenter and SharePoint carry the highest stakes since both sit at the center of enterprise infrastructure. Composer also had a rough disclosure day — jmespath.php's compiler-mode code injection sits under aws-sdk-php's dependency tree, and Froxlor's credential-disclosure bug is a real account-takeover primitive for anyone self-hosting it.
Late escalation at 21:00 ET: LibreNMS shipped a same-release disclosure batch after First Watch locked. The sharpest is an SSRF-driven stored XSS — an admin pointing the Oxidized integration URL at an attacker's server gets persistent script execution against every user who opens a device's config tab — alongside a config-gated shell_exec RCE and a second stored XSS in the same 26.7.0 release. All three need an existing admin session to trigger, so this reads as disclosure volume rather than a new active-exploitation event; it doesn't displace vCenter/SharePoint as tonight's priority.
→ Operational priority for the night patch vCenter and SharePoint first — both are internet-facing management planes with a 2026-08-21 CISA due date — then work down the rest of the KEV list. LibreNMS admins should grab 26.7.0 before the weekend; the RubyGems and Composer items can wait for the morning pass.