Today's disclosures cluster on identity and authentication rather than the registries. CISA added a new KEV entry, two more GHSA advisories landed on ZITADEL's identity platform, and a silent regression reopened an already-fixed hole in ESPHome's device dashboard.
CVE-2026-76461 carries the sharpest edge: an unauthenticated SQL injection in Cisco Secure Email Gateway's AsyncOS hands a remote attacker root on the underlying OS, and CISA's three-day BOD 26-04 deadline is itself a signal this is being actively exploited. ESPHome's dashboard container tells a quieter but equally serious story — a well-intentioned env-var rename (CVE-2026-59178, CVSS 9.8) dropped the old $USERNAME/$PASSWORD fallback with no changelog warning, so any operator who set a password the old way silently lost authentication on their next upgrade. ZITADEL adds two more identity-platform bugs to the pile — an OAuth2 token-exchange flaw that lets a low-privilege client trade up to an admin-scoped token (CVE-2026-56668), and a role-cleanup race that can leave revoked permissions in place on shared projects (CVE-2026-76081) — while October CMS fully closed out its Safe Mode-gated patch batch in a single release.
→ Operational priority for the night patch internet-facing Cisco Secure Email Gateway appliances before Thursday's KEV deadline, and check any ESPHome dashboard container you haven't touched since the 2026.6.0 upgrade for the "WITHOUT AUTHENTICATION" startup banner.