Tonight's operational story hasn't moved since First Watch: Citrix NetScaler and Cisco's Firewall Management Center/Security Cloud Control both picked up near-identical alternate-path authentication bypasses on CISA's KEV list today, each under an aggressive three-day patch clock. A Fortinet heap overflow and a Chromium V8 sandbox escape round out the day's four KEV adds; none of that changed in the last three hours.
Late escalation at 21:00 ET: nine more high-severity GHSA disclosures landed between First Watch and this check-in, the largest single after-hours batch this series has logged. functype-mcp-server's set_functype_version tool interpolates a caller-supplied version string directly into a pnpm install specifier with no validation, and pnpm/npm alias syntax turns that into remote code execution — audit anything that wires an MCP tools/call endpoint to a package manager. ESPHome Device Builder's Home Assistant add-on bound its ingress dashboard to every LAN interface instead of loopback, so any device on the local network gets the full unauthenticated dashboard; the rest of the batch — an Identrail cross-tenant IDOR, a Komari CSRF, unauthenticated task execution in @yeger/turbo-graph, an API-key leak in nuxt-ollama, two more Open WebUI DoS bugs, a GeoNetwork SSRF, and a webhookd header-injection — is real but narrower: single-package, no confirmed exploitation, patch on your normal cadence.
→ Operational priority for the night NetScaler and Cisco FMC/SCC against the September 12 KEV deadline still come first; after that, check whether functype-mcp-server or ESPHome Device Builder are anywhere in your stack, since both are unauthenticated-exposure bugs with patches already out.