The day started with yesterday's Magento zero-day finally getting a patch, and closed with a reminder that shared dependencies mean shared blast radius: Next.js and Astro both shipped unauthenticated RCE advisories for the exact same libheif-via-sharp AVIF decode bug within the same hour, because both frameworks hand untrusted image bytes to the same native decoder underneath sharp. sharp itself, Predis, CakePHP, and a CVSS-10 zero-click sanitizer bypass in MapLibre GL JS rounded out an unusually heavy critical batch from GHSA this evening.
The other thread worth naming is repetition: xmldom shipped 11 same-day advisories built on the identical shape as this morning's NLTK batch, where a guard exists in the code but doesn't enforce what its name promises. Aikido's catch of XCSSET live inside a compromised Flutter package on pub.dev is today's bright spot only in the sense that it was caught fast. Late escalation at 21:00 ET: CISA added three fresh KEV entries after First Watch locked the day's shape, and the one that matters is a pre-authentication remote-code-execution bug in N-able's N-central RMM platform (CVE-2026-86218) — the same MSP-tooling blast-radius class as Kaseya VSA — carrying a three-day federal remediation deadline. Two Windows local-privilege-escalation KEV adds (Update Stack link-following, ALPC heap overflow) round out the late batch on the standard 14-day clock.
→ Operational priority for the night patch N-able N-central to 2026.3 hotfix 4 immediately if you run it anywhere in your MSP or monitoring stack — CISA's deadline is September 11 — then patch sharp to 0.35.4 across every service that touches it directly or through Next.js/Astro, and audit any pub.dev-sourced Flutter dependency pulled in the last month before trusting your next iOS/macOS CI build.