Today's GHSA feed fired two unrelated but equally operational batches within about an hour of each other, plus a CISA KEV add that's a clean, unambiguous perimeter fix. Cisco's Secure Email Gateway got an unauthenticated SQL injection that ends in root command execution — no exploitation confirmed yet, but KEV adds get scanned fast, and a mail gateway is exactly the kind of appliance that sits exposed at the edge.
The more interesting split is between the two batches. @zereight/mcp-gitlab — an MCP server that puts an LLM agent in front of your GitLab — picked up an SSRF and a DNS-rebinding hole that both end in token theft, plus a set of read-only bypasses that defeat the safety controls the package exists to provide; if you've wired an agent up to GitLab through this server, the controls you thought you had aren't there yet. Separately, http4s's Ember backend took its second major batch in three weeks — a CL.TE smuggling primitive plus eleven siblings — on top of the HPACK-bomb DoS it got on August 26, which makes Ember's HTTP/1.1 parser look less like bad luck and more like a stack that needs a from-scratch conformance pass. On the brighter side, the day's only confirmed active-exploitation item, the WooCommerce Wholesale Lead Capture backdoor from this afternoon, is a seven-month-old bug with a known fix — patching coverage, not a new hole, is the gap.
→ Operational priority for the night if you run @zereight/mcp-gitlab for agent access to GitLab, disable ENABLE_DYNAMIC_API_URL and pull the Streamable HTTP transport off any browser-reachable network before you do anything else — that's live token exposure, not a theoretical one.