This morning's JFrog Artifactory active-exploitation report from Wiz got government confirmation today: CISA added both underlying CVEs to KEV and catalogued two more products in the same update — ConnectWise ScreenConnect and GitLab CE/EE, both due September 14. The day's other disclosures were narrower but sharp — Prowler shipped a CVSS 9.6 SAML bug letting one tenant assert another's email domain and pivot into their cloud audit data, complete with a working PoC and a same-day fix, while LINE's Central Dogma fell back to a hardcoded ZooKeeper secret ('ch4n63m3') whenever replication.secret is left unset, and a MySQL MCP server shipped with the MCP SDK's DNS-rebinding protection silently disabled — a flat CVSS 10.0.
Late escalation at 21:00 ET: a CVSS 9.1 prototype-pollution bug in yayson, a small JSON:API deserialization library, landed just before bed — a document with type: "__proto__" pollutes Object.prototype for the life of the process, and the poisoned key can arrive through an included relationship, bypassing a naive type allow-list. It arrived alongside a wave of narrower but still-serious disclosures within the same hour: an unauthenticated, CORS-wildcarded admin API in Mockoon, an SSRF-fix bypass in FrontMCP's OpenAPI adapter, and six authorization bugs patched at once in the Shopper e-commerce framework — all patched, none known exploited yet, but five serious disclosures inside one hour is not a coincidence worth ignoring.
→ Operational priority for the night patch ConnectWise ScreenConnect and GitLab CE/EE ahead of Sunday's KEV deadline, and if yayson is anywhere in your JSON:API stack, pin to 4.3.0 before Monday — prototype-pollution bugs are exactly the kind that get rediscovered as an RCE gadget once someone goes looking.