The Federal Government Is Now Officially Behind Schedule
# The Federal Government Is Now Officially Behind Schedule
CISA sets deadlines like they actually believe bureaucracy works fast. They added a few things to this week's Known Exploited Vulnerabilities list and gave federal agencies until September 5 to fix them. It's Monday evening, September 7 now. In the world of regulatory compliance, those forty eight hours since Friday aren't just a weekend. They're a hole in the record.
Are you an admin for a US federal agency? If your Sangoma Switchvox or JFrog Artifactory isn't patched yet, you aren't just open to attack, and you've officially missed the mark on compliance. There's something almost cozy about a deadline that's already gone while attackers are still knocking on the door; it makes the office politics easier. You don't have to argue why the work matters anymore. You just have to admit you're late.
Let us rank these priorities as people actually handle them, rather than how the marketing brochures for "risk management" suggest.
First up is what I call the Immediate Panic tier, and these are the flaws sitting right on the internet that hackers are already using. Look at the Sangoma Switchvox SQL injection (CVE-2026-9586) or the JFrog Artifactory authentication flaw (CVE-2026-82329), and they aren't just critical on paper. People are actively using them to kick in your front door. When a bug is internet-facing and shows up in the KEV, the CVSS score doesn't matter. The only number that counts is how many minutes you take to fix it.
The fallout from this is where things get ugly. Take JFrog Artifactory. It isn't just some server. It's a repository for binaries and dependencies. If an attacker gets in via improper authentication, they aren't just stealing data. They can poison the well for every piece of software that company sends out, and the vendor is the victim, sure, but so is every customer who trusts their update server.
Then you have things that are Urgent but Managed, and google Chromium V8 type confusion (CVE-2026-85046) fits here. It's a zero-day, and the press always makes a theater out of those, but it needs user interaction. A hacker can't just wish themselves into your machine. You have to visit a bad site first. Does it need fixing? Yes. But it isn't as mindless as the SonicWall SMA1000 flaws (CVE-2026-83548 and 83549); those allow command injection and server-side request forgery without asking for permission.
Some attackers just like targeting schools. The PaperCut NG/MF vulnerabilities (CVE-2026-81578 and 82078) have been hitting universities and schools to steal credentials; it's like stealing the keys to the staff room. Once they have those, they can move across a network that is usually wide open and lacks segmentation.
Now, let us talk about what can wait.
Stop treating every CVE like a building fire. It isn't one. If you're choosing between patching an internet-facing SonicWall or an internal BerriAI LiteLLM instance (CVE-2026-59822), the internal one can wait until Tuesday. The Kludex Starlette smuggling flaw (CVE-2026-48710) is a cool technical puzzle, sure, but unless it's on your edge, it doesn't jump to the front of the line.
Most companies treat patching as a yes or no switch. Everything is critical or nothing is. That's why they fail. They'll waste four hours arguing over a Medium severity patch for some internal tool while their edge gateway has been screaming since Friday.
Budget people, not server people, usually complain that you can't just ignore flagged vulnerabilities because of a compliance checklist. Look at the KEV instead, and CISA isn't offering suggestions; they are telling you what criminals actually use. Prioritizing based on active exploitation isn't skipping security; it is the only kind of security that accepts how attackers work.
Want to be pedantic about paperwork? Look at Trezor. Their data breach hit 81,000 customers, and it isn't a patching issue exactly, but it shows how fragile the promise of hardware is. People say hardware wallets remove risk, yet the human part, like the email and identity, stays soft.
The only metric that matters this week isn't your total patch count, and who's still missing the 5 September deadline? Auditors should start there with their questions; CISOs should start there with their apologies.
I bet we'll see more of these expired deadlines as the quarter ends and agencies scramble to clean up spreadsheets before auditors fly in from Washington or Oslo. Fixing a breach costs way more than filing a report on time.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Adobe Commerce Zero-Day Exploited to Backdoor Online Stores SecurityWeek
- N-able patches max severity N-central flaw amid ongoing attacks BleepingComputer
- Mathspace Data Breach Exposes Info of Over 1 Million Students, Parents, Staff - kobaran.com Google News Security
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw The Hacker News
- Breached! Tutoring platform Mathspace says 1m-plus Aussies implicated by data breach - Cyber Daily Google News Security
- More than 1 million users affected in Mathspace data breach across Australia and New Zealand - ABC News & Headlines – Australian Broadcasting Corporation Google News Security
- Mathspace data breach: Million-plus students, adults, lose data in major hack - Nine.com.au Google News Security
- More than 1 million users affected in Mathspace data breach across Australia and New Zealand - RNZ Google News Security