CISA's PaperCut NG/MF KEV entry, added this morning, remains the day's most consequential story — a complete pre-auth chain (missing-auth admin action plus unsafe reflection into arbitrary bytecode) against a print-server product that's a well-worn ransomware entry point, and PaperCut shipping a second emergency patch this week signals the first fix didn't fully hold.
The afternoon brought a cluster of four unrelated GHSA disclosures rather than any active-campaign signal — Socket, Phylum, and Aikido all came back empty, a genuinely quiet registry day. The standout was an elFinder SSRF that beats its own DNS-rebinding guard via the cURL-less fsockopen fallback, non-blind and capable of reading internal secrets back through the upload; a Socket.IO/Engine.IO WebTransport DoS and a TYPO3 upload-filter bug rounded out the disclosed-CVE side, while a Hono OAuth library shipped with a state check that silently no-ops on state-less callbacks. Reporting on the DPRK IT-worker fraud scheme also showed it broadening past engineering roles into healthcare and sales.
Late escalation at 21:00 ET: Kirby CMS shipped 5.5.2 (with a 4.9.5 backport) closing two high-severity issues that landed after First Watch. An authenticated user with API access but no upload permission can flood the chunked-upload temp directory for 24 hours, and a path-traversal bug in the media/thumbnail handler lets encoded-slash-tolerant servers — nginx, PHP's built-in server, misconfigured Apache — probe for arbitrary .json files and pull thumbnails from outside the intended media root. Neither is under active exploitation and both need authentication or a non-default server config, but two high-severity disclosures in one package in one release is worth a same-week upgrade rather than the normal cadence. A medium-severity decode-uri-component ReDoS rounded out the late batch — low urgency alone, but the package sits transitively under enough URL-parsing dependencies to be worth a lockfile grep.
→ Operational priority for the night confirm PaperCut NG/MF is patched to the release that closes both CVE-2026-81578 and CVE-2026-82078 before end of shift; queue the Kirby 5.5.2 upgrade for tomorrow's first patch window if you run getkirby/cms, and treat elFinder, Hono OAuth, and decode-uri-component as normal-cadence items.