v vanemmerik.ai / SUPPLY-CHAIN · ARCHIVE

Every watch, in order.

120 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.

WED 16 SEP 2026

Supply Chain Watch · 2026-09-16 — Late escalation: djust's auth-boundary collapse grew from eight CVEs to twelve after First Watch locked the day's shape, the worst a WebSocket/SSE mount path that lets an unauthenticated client force the server to import and run any Python module by name — RCE-by-proxy — while rmcp, the Rust MCP SDK, separately disclosed an unauthenticated session-leak DoS and an OAuth flaw that lets a malicious MCP server steal access tokens.

Late escalation: djust's auth-boundary collapse grew from eight CVEs to twelve after First Watch locked the day's shape, the worst a WebSocket/SSE mount path that lets an unauthenticated client force the server to import and run any Python module by name — RCE-by-proxy — while rmcp, the Rust MCP SDK, separately disclosed an unauthenticated session-leak DoS and an OAuth flaw that lets a malicious MCP server steal access tokens.

9 critical 24 high 9 medium 1 context
TUE 15 SEP 2026

Supply Chain Watch · 2026-09-15 — A same-day GHSA publish run hit two very different corners of the stack at once: an MCP server used for agent-assisted GitLab access got a token-stealing SSRF pair, and http4s's Ember backend took its second HTTP-smuggling/DoS batch in three weeks.

A same-day GHSA publish run hit two very different corners of the stack at once: an MCP server used for agent-assisted GitLab access got a token-stealing SSRF pair, and http4s's Ember backend took its second HTTP-smuggling/DoS batch in three weeks.

4 critical 1 high 1 medium 1 context
MON 14 SEP 2026

Supply Chain Watch · 2026-09-14 — Authentication, not package registries, was today's weak link: CISA gave Cisco's Secure Email Gateway a three-day patch deadline while ESPHome's dashboard silently lost its login on upgrade and ZITADEL shipped two identity-platform fixes of its own.

Authentication, not package registries, was today's weak link: CISA gave Cisco's Secure Email Gateway a three-day patch deadline while ESPHome's dashboard silently lost its login on upgrade and ZITADEL shipped two identity-platform fixes of its own.

2 critical 1 high 1 medium 6 context
SUN 13 SEP 2026

Supply Chain Watch · 2026-09-13 — A genuinely quiet evening — the only two items are a Microsoft disclosure about trusted-infrastructure phishing and a CVE catching up to an already-known China-linked backdoor campaign, with nothing new hitting npm, PyPI, or CISA's KEV list today.

A genuinely quiet evening — the only two items are a Microsoft disclosure about trusted-infrastructure phishing and a CVE catching up to an already-known China-linked backdoor campaign, with nothing new hitting npm, PyPI, or CISA's KEV list today.

0 critical 0 high 0 medium 2 context
SAT 12 SEP 2026

Supply Chain Watch · 2026-09-12 — An active Artifactory-to-backdoor campaign and a fresh Chromium KEV entry set today's operational bar, while Shopper's “fixed” authorization bug keeps spawning siblings and RubyGems' spring campaign turns out to have been run by an AI agent swarm.

An active Artifactory-to-backdoor campaign and a fresh Chromium KEV entry set today's operational bar, while Shopper's “fixed” authorization bug keeps spawning siblings and RubyGems' spring campaign turns out to have been run by an AI agent swarm.

2 critical 5 high 4 medium 0 context
FRI 11 SEP 2026

Supply Chain Watch · 2026-09-11 — CISA confirms the JFrog Artifactory campaign and adds ConnectWise ScreenConnect and GitLab CE/EE to KEV, a CVSS-10 MCP server bug and a hardcoded Central Dogma secret round out the evening, and a late CVSS-9.1 prototype-pollution bug in npm's yayson pushes the day past bedtime.

CISA confirms the JFrog Artifactory campaign and adds ConnectWise ScreenConnect and GitLab CE/EE to KEV, a CVSS-10 MCP server bug and a hardcoded Central Dogma secret round out the evening, and a late CVSS-9.1 prototype-pollution bug in npm's yayson pushes the day past bedtime.

7 critical 3 high 1 medium 1 context
WED 09 SEP 2026

Supply Chain Watch · 2026-09-09 — CISA's twin KEV adds for Citrix NetScaler and Cisco's firewall manager — both under three-day patch clocks — remain tonight's top priority, even after a late-evening batch of nine high-severity GHSA disclosures, including an MCP-server RCE and a LAN-exposed ESPHome dashboard, pushed the day's high count past every other evening this series has logged.

CISA's twin KEV adds for Citrix NetScaler and Cisco's firewall manager — both under three-day patch clocks — remain tonight's top priority, even after a late-evening batch of nine high-severity GHSA disclosures, including an MCP-server RCE and a LAN-exposed ESPHome dashboard, pushed the day's high count past every other evening this series has logged.

4 critical 22 high 15 medium 0 context
TUE 08 SEP 2026

Supply Chain Watch · 2026-09-08 — Next.js and Astro's shared libheif AVIF RCE anchored the day, but CISA's evening KEV add of a pre-auth RCE in N-able N-central — MSP tooling with Kaseya-class blast radius — is the story that matters most before you log off.

Next.js and Astro's shared libheif AVIF RCE anchored the day, but CISA's evening KEV add of a pre-auth RCE in N-able N-central — MSP tooling with Kaseya-class blast radius — is the story that matters most before you log off.

9 critical 5 high 0 medium 1 context
SUN 06 SEP 2026

Supply Chain Watch · 2026-09-06 — A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.

A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.

0 critical 0 high 1 medium 1 context
FRI 04 SEP 2026

Supply Chain Watch · 2026-09-04 — A last-minute KEV add stole the night from the AI-agent story — CISA confirmed active exploitation of a Chromium V8 type-confusion bug just as GPT-6 Astra and eight CodeWhale approval-bypass CVEs showed agents landing on both sides of the supply chain today.

A last-minute KEV add stole the night from the AI-agent story — CISA confirmed active exploitation of a Chromium V8 type-confusion bug just as GPT-6 Astra and eight CodeWhale approval-bypass CVEs showed agents landing on both sides of the supply chain today.

3 critical 5 high 1 medium 0 context
WED 02 SEP 2026

Supply Chain Watch · 2026-09-02 — A late four-CVE OpenChoreo disclosure — headlined by an unauthenticated cluster-gateway bypass — landed alongside a second Omnigent guardrail failure, turning today's AI-agent execution-layer story into a platform-trust story before midnight.

A late four-CVE OpenChoreo disclosure — headlined by an unauthenticated cluster-gateway bypass — landed alongside a second Omnigent guardrail failure, turning today's AI-agent execution-layer story into a platform-trust story before midnight.

9 critical 39 high 36 medium 1 context
TUE 01 SEP 2026

Supply Chain Watch · 2026-09-01 — A grind of a disclosure day — pnpm, browserslist, MLflow, and Filament all shipped fixes for install- and load-time supply-chain primitives, but no new active campaign or CISA KEV entry landed to go with them.

A grind of a disclosure day — pnpm, browserslist, MLflow, and Filament all shipped fixes for install- and load-time supply-chain primitives, but no new active campaign or CISA KEV entry landed to go with them.

1 critical 11 high 7 medium 2 context
MON 31 AUG 2026

Supply Chain Watch · 2026-08-31 — A pre-auth PaperCut RCE chain still owns tonight's operational priority, but a Kirby CMS security release landing after First Watch — two high-severity fixes for an auth'd storage-exhaustion bug and an encoded-slash path traversal — escalated the day's disclosure count late.

A pre-auth PaperCut RCE chain still owns tonight's operational priority, but a Kirby CMS security release landing after First Watch — two high-severity fixes for an auth'd storage-exhaustion bug and an encoded-slash path traversal — escalated the day's disclosure count late.

1 critical 4 high 3 medium 2 context
FRI 28 AUG 2026

Supply Chain Watch · 2026-08-28 — Mini Shai-Hulud hits an npm codegen package with valid provenance, Pimcore ships a five-CVE editor-to-RCE chain, and a late GHSA batch adds a RestrictedPython sandbox bypass

A Shai-Hulud-style npm worm hit a widely-used TanStack Query codegen package with valid provenance attestations, Pimcore shipped five same-day advisories chaining editor access to server RCE, and a late GHSA batch added a RestrictedPython sandbox-guard bypass and a SeaweedFS bucket-isolation break.

2 critical 9 high 5 medium 5 context
SUN 02 AUG 2026

Supply Chain Watch · 2026-08-02 — A Completely Quiet Day

All three passes today came back empty — no new CISA KEV entries, no in-scope GHSA disclosures, and nothing from the active-campaign feeds — a hard stop after yesterday's ApostropheCMS authorization-bypass bug.

0 critical 0 high 0 medium 0 context
FRI 31 JUL 2026

Supply Chain Watch · 2026-07-31 — Adform ad-script crypto-clipper + Apostrophe's three-package trust-boundary failure

A live ad-script supply chain attack is siphoning cryptocurrency from every site running Adform's tags, landing the same day as five critical disclosures — a CMS, a low-code platform, a Kubernetes admission webhook, a game-hosting daemon, and AWS Amplify — plus a late-arriving second and third Apostrophe advisory showing the CMS's trust-boundary problem wasn't a one-off.

6 critical 6 high 6 medium 2 context
WED 29 JUL 2026

Supply Chain Watch · 2026-07-29 — The swagger-typescript-api Six

swagger-typescript-api became today's spec-to-RCE story: six advisories show a hostile OpenAPI document can inject code into its own generated client, echoing yesterday's datamodel-code-generator pile-up almost exactly one day later.

3 critical 12 high 7 medium 2 context
TUE 28 JUL 2026

Supply Chain Watch · 2026-07-28 — The datamodel-code-generator Dozen

The day's headline event stayed datamodel-code-generator's eleven-advisory pile-up, but a late batch after First Watch pushed goshs to five separate advisories in one day and added an unrelated critical SQL injection in @hypequery/clickhouse — 21:00 didn't mean the day was done.

7 critical 31 high 14 medium 5 context
THU 23 JUL 2026

Supply Chain Watch · 2026-07-23 · Two Auth.js Criticals, A Quiet Batch Behind Them

Two Auth.js advisories that can silently disable authentication anchor a day otherwise dominated by open redirects and memory-exhaustion bugs — React Router's four-advisory redirect-hardening batch, a paired pypdf infinite-loop fix, and a fresh PHPSpreadsheet SSRF bypass — with nothing yet confirmed under active attack.

2 critical 8 high 9 medium 2 context
WED 22 JUL 2026

Supply Chain Watch · 2026-07-22 · A four-wave Wednesday — Gitea, n8n twice, Netty, Next.js, Jetty, JupyterLab, LiteLLM — plus two KEV criticals

Late escalation at 21:00 ET: a fourth disclosure wave — 50 more advisories spanning a second n8n batch plus first-time appearances from Next.js, Eclipse Jetty, JupyterLab, and LiteLLM — landed within 75 minutes of the day's 18:00 synthesis, pushing the day's total past 135 items and its high-severity count past 55.

5 critical 56 high 62 medium 1 context
MON 20 JUL 2026

Supply Chain Watch · 2026-07-20 · A 90-advisory GHSA wave overshadows SleeperGem's RubyGems hijack

A same-day GHSA wave that ran from 6pm to past 9pm ET eventually reached 90 advisories, overshadowing SleeperGem's quiet RubyGems hijack — headlined by a critical node-tar bug reachable through every npm install, a Composer bug that lets a malicious transitive dependency write files outside vendor/, and a second, equally large round of Pillow, Axios, and .NET disclosures that landed after First Watch had already gone to print.

4 critical 38 high 44 medium 7 context
TUE 14 JUL 2026

Supply Chain Watch · 2026-07-14

A pile-up day: four new FacturaScripts advisories, three same-root-cause Anyquery RCE-class bugs, and three separate MCP-server disclosures landed alongside two live GitHub/npm impersonation campaigns and four newly-confirmed CISA KEV exploits.

12 critical 22 high 17 medium 0 context
MON 13 JUL 2026

Supply Chain Watch · 2026-07-13 — A late Kimai Docker-secret account takeover and a brute-forceable FacturaScripts 2FA bypass escalate the day to five criticals

A late 21:00 ET wave adds two more confirmed-exploitable criticals — a hardcoded Docker default secret enabling Kimai account takeover and a brute-forceable FacturaScripts 2FA bypass — on top of a day that already carried a newly-exploited legacy Cisco IOS bug, DIRAC's double eval()-to-RCE disclosure, and day three of the unresolved jscrambler npm infostealer.

5 critical 4 high 2 medium 8 context
FRI 10 JUL 2026

Supply Chain Watch · 2026-07-10 — SiYuan answers YesWiki's 13-advisory morning with 7 of its own, three RCE chains deep, while a compromised Injective Labs repo ships a wallet-stealing npm package

A second coordinated multi-CVE batch — seven SiYuan advisories with three independent RCE chains — landed hours after this morning's YesWiki disclosure, while a compromised Injective Labs GitHub repo pushed a wallet-draining npm package into the wild.

15 critical 25 high 26 medium 2 context
THU 09 JUL 2026

Supply Chain Watch · 2026-07-09 — Wallet and payment SDKs hit across three ecosystems, YesWiki takes a 13-advisory teardown, then a late Elixir HTTP-client batch lands after bed-check

Late escalation at 21:00 ET: a fresh GHSA batch lands three more high-severity disclosures — header-leak and memory-exhaustion bugs across Elixir's two workhorse HTTP clients, Tesla and Mint — on top of a day already shaped by a three-ecosystem wallet/payment-credential wave and a 13-advisory YesWiki teardown.

6 critical 13 high 14 medium 0 context
WED 08 JUL 2026

Supply Chain Watch · 2026-07-08 — Agentic tooling's authless-API problem

Five unrelated AI-agent and MCP-adjacent tools — Langflow, Open WebUI, ha-mcp, ckan-mcp-server, and Serena — disclosed authorization or authentication gaps on the same day, the clearest sign yet that agentic tooling is shipping with the auth debt web frameworks paid off a decade ago.

8 critical 9 high 13 medium 3 context
SAT 04 JUL 2026

PolinRider Keeps Scaling, and Little Else Broke

The DPRK-linked PolinRider campaign is now up to 108 malicious packages and browser extensions across four ecosystems, and it's the only story of the day — KEV, GHSA, and the rest of the RSS feeds stayed quiet.

1 critical 0 high 0 medium 0 context
FRI 03 JUL 2026

Six Projects, One Coordinated-Disclosure Day

Six unrelated open-source projects each shipped a coordinated multi-CVE batch today, from Steeltoe's seven advisories to Zebra's twelve, while the MCP-gateway trust-boundary bug count for the week climbed to four.

9 critical 15 high 2 medium 1 context
THU 25 JUN 2026

golang.org/x/crypto/ssh breaks open late on a Go-heavy day

A late coordinated disclosure cracks the golang.org/x/crypto/ssh stack open — a CVSS-10 public-key auth bypass and five more critical SSH/agent flaws — onto a day already defined by Shai-Hulud crossing into Go and OpenAM's five-way collapse.

7 critical 9 high 3 medium 4 context
TUE 23 JUN 2026

Supply Chain Watch · 2026-06-23 — Identity takes the brunt; late Snipe-IT tenancy batch

Identity infrastructure took the brunt — pre-auth RCE in OpenDJ, pre-auth XSS and LDAP injection in OpenAM, and LastPass breached through stolen OAuth tokens — while npm typosquats dropped a Windows RAT, CISA logged four exploited appliance flaws, and a late Snipe-IT disclosure batch added a cross-tenant data injection after the bell.

4 critical 7 high 2 medium 1 context
MON 22 JUN 2026

Supply Chain Watch · 2026-06-22 · The trusted update channel was the attack

The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.

3 critical 4 high 0 medium 1 context
SUN 21 JUN 2026

Supply Chain Watch · 2026-06-21 — A quiet Sunday on the registries

A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.

0 critical 0 high 1 medium 0 context
SAT 20 JUN 2026

Supply Chain Watch · 2026-06-20 — A state actor claims the Mastra compromise

Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.

2 critical 7 high 10 medium 4 context
FRI 19 JUN 2026

Supply Chain Watch · 2026-06-19 — The agentic toolchain audits itself in public

The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.

5 critical 21 high 14 medium 0 context
THU 18 JUN 2026

Supply Chain Watch · The agent ecosystem's bad day

AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.

15 critical 13 high 39 medium 2 context
TUE 16 JUN 2026

Supply Chain Watch · 2026-06-16 — AI-stack mass disclosure escalates after dark: Rclone unauth RCE, LiteLLM auth bypass, n8n CVSS-10 browser hole & cross-tenant cred takeover, Gitea/Gogs token-scope bypasses

The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.

10 critical 22 high 5 medium 4 context
SUN 14 JUN 2026

A quiet registry day, and a decade-long auth-stack hijack

A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.

0 critical 0 high 0 medium 1 context
SAT 13 JUN 2026

File Browser empties its disclosure queue

The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.

0 critical 12 high 22 medium 1 context
FRI 29 MAY 2026

Supply Chain Watch · 2026-05-29

Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.

3 critical 9 high 8 medium 2 context