The Deadlines Are Fixed. The Attackers Aren't.
# The Deadlines Are Fixed. The Attackers Aren't.
If you’re treating your patch queue as a chronological list, you're doing it wrong. Priority isn't about who screamed loudest in the advisory; it's about who is already inside the house.
Start with JFrog Artifactory. CVE-2026-82329 is the most serious story of the week because the window between disclosure and exploitation wasn't a window—it was a revolving door. Attackers are minting admin tokens just days after the fix was available. If you haven’t updated, you aren't just risking a server; you're risking your entire CI/CD pipeline. This is where the second-order effect hits: if an attacker controls Artifactory, they don't need to find another hole in your network. They can simply inject malicious code into the binaries you ship to your customers. Your clients become the victims of a breach they didn't even know you had.
Then there is Switchvox. CVE-2026-9586 hit the board today. It allows for reverse shells without credentials. In a world where "critical" is slapped onto every minor logic error, this actually earns the word. No password, no session token, just an immediate shell on the box. If your VOIP system is internet-facing, you are currently an open door.
PaperCut continues to be a nuisance. CISA added CVE-2026-82078 and CVE-2026-81578 to the KEV on 31 August. The federal patch deadline is 14 September. That gives you just under two weeks, but as we've seen with previous print server flaws, attackers don't wait for government deadlines. If you’re running NG/MF and it's exposed, stop reading this and update.
The AI tooling craze has brought its own set of disasters. Langflow is currently seeing activity across three different CVEs (CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027). It's the classic "move fast and break things" approach to security. The developers broke the authentication, and now the attackers are moving in.
Now, for the list of things that can actually wait until tomorrow—or next week.
CISA added a handful of older vulnerabilities this week that feel like archaeology rather than active threats. CVE-2015-3246 (Red Hat Libuser) and CVE-2015-5287 (Red Hat Automatic Bug Reporting Tool) are from over a decade ago. Even the Ajax.NET Professional flaw, CVE-2021-23758, is five years old. Why they're hitting the KEV now is likely due to some legacy environment in a government agency finally being targeted, but for most of us, these aren't urgent. If you're still running 2015-era Red Hat tools on an internet-facing box, you have bigger problems than this column.
The same goes for the Linux Kernel entries like CVE-2022-0995. Unless you are seeing active evidence of out-of-bounds writes in your specific kernel version, it's a lower priority than a credential-less reverse shell on your phone system.
Some might argue that any KEV addition should trigger an immediate emergency response. That’s a recipe for burnout and operational failure. The difference between a "Critical" label from a vendor and an active exploit in the wild is the difference between a weather report and a flood in your basement. One requires planning; the other requires a mop.
We're seeing a repeating pattern here: disclosure happens, a patch is released, and the exploitation window shrinks to almost zero before the average admin can even schedule a maintenance window. We are effectively betting that we can patch faster than an attacker can script a PoC based on a git diff.
It's a bet I'm not sure we're winning.
Keep an eye on whether JFrog issues a corrected timeline for CVE-2026-82329. If the admin token minting is as trivial as the early reports suggest, we'll be seeing "supply chain compromise" headlines across the board by Friday afternoon.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens BleepingComputer
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure The Hacker News
- Attackers Pounce on Critical Artifactory Flaw Following Disclosure Dark Reading
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials The Hacker News
- FBI Probes Service Selling 153M+ Drivers Licenses Krebs on Security
- PaperCut warns of active attacks targeting its print software - Escudo Digital Google News Security
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain The Hacker News
- Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency Dark Reading