This Week in Change Risk — Week of Aug 31, 2026
Your weekly digest for change and risk managers. Written from primary sources, with a named limitation on every vendor and tool mentioned. This is operational context, not legal or compliance advice. Some outbound links may be affiliate links.
KEV additions this week
CISA added nine CVEs to the Known Exploited Vulnerabilities catalog during the week of August 31. Two PaperCut NG/MF flaws landed on August 31: CVE-2026-82078 (unsafe reflection) and CVE-2026-81578 (missing authentication for a critical function), both with a September 14 due date. The September 2 batch was the notable one — seven CVEs, four of them in AI/ML infrastructure. CVE-2026-49869 in Kestra OSS carries a CVSS 10.0 for OS command injection; CVE-2026-82329 in JFrog Artifactory is a 9.8 improper-authentication flaw; CVE-2026-59822 in BerriAI LiteLLM is an 8.8 improper-authentication issue; and CVE-2026-48710 in the Starlette ASGI framework (which underpins FastAPI, vLLM, and many MCP servers) is a request-smuggling flaw. Rounding out the batch: two SonicWall SMA1000 appliance flaws and a Sangoma Switchvox SQL injection. The Kestra, JFrog, SonicWall, and Switchvox entries all carried a September 5 federal deadline, a three-day clock from the date added.
Cloud incidents worth noting
This was a quiet week for hyperscaler P1s, which is worth stating plainly rather than manufacturing drama. The Cloudflare status history and GitHub status showed no sustained platform-wide outage across the AWS, Azure, GCP, Cloudflare, or GitHub surfaces during the window. That does not mean nothing happened — regional degradations and individual-service blips are routine — but none rose to the change-freeze-triggering, multi-region level that belongs in this section. For change managers, a quiet week is the signal to work the backlog you deferred during the last incident, not to assume the pattern holds. The absence of a headline outage is exactly when planned maintenance windows should be claimed, because the next one is a matter of when, not whether, as our AWS us-east-1 outage timeline shows across five years of history.
Vendor moves
The most useful vendor signal this week came not from a release but from a defender advisory. Microsoft’s security team published guidance on securing AI gateways and control points, arguing that AI infrastructure — the gateways, proxies, and orchestration layers that route model traffic — has become a first-class attack target rather than an experimental side system (Microsoft Security blog). The timing, days before four AI-infrastructure CVEs hit the KEV catalog, makes the point concrete. The weakness in vendor guidance of this kind is that it is inevitably framed around the vendor’s own control plane, so a shop running open-source gateways like LiteLLM or orchestration like Kestra has to translate the advice rather than apply it directly. The actionable read for a CAB: add your AI gateways and pipeline orchestrators to the asset inventory and the emergency-change scope now, before the next KEV entry forces the conversation under a three-day deadline.
Compliance and regulatory
The regulatory thread of the week is the widening gap between EU frameworks. DORA has applied to financial entities since January 2025, but analysts continue to stress that DORA compliance does not discharge obligations under the incoming Cyber Resilience Act, whose reporting duties reach manufacturers of products with digital elements (DORA regulatory updates). For change managers at any organization selling software or connected products into the EU, the practical consequence is that “we passed our DORA assessment” is not a defense against CRA vulnerability-handling and reporting requirements. The two regimes overlap in spirit — both want demonstrable control over software risk — but differ in scope and timeline, and treating them as one program is the mistake to avoid. Map which of your change and vulnerability-management controls satisfy each regime separately, and note the assumptions, because an auditor for one will not accept evidence framed for the other.
Change-management community
The community item this week is the sysadmin backlash over PaperCut’s patch cadence, where administrators vented about the churn of emergency releases and the operational cost of repeatedly patching a print-management server that few teams ever tiered as critical — frustration that tracked the wave of emergency patches PaperCut shipped as threat actors chained its flaws (Cybersecurity Dive). Strip out the frustration and there is a real change-management lesson: the assets that generate emergency changes are often the “boring” utilities nobody scored as high-criticality, precisely because they were assumed to be low-risk. A print server with a pre-authentication remote-code-execution flaw and internet exposure is not low-risk. The thread is a reminder to run the criticality-scoring exercise on the unglamorous systems, not just the obvious crown jewels, because attackers do not share your sense of what is important.
Chart of the week
We pulled the CISA KEV catalog directly and counted additions by ISO week for the last nine weeks. The picture is a catalog running hot: after two quiet weeks (W31 and W33 at three additions each), the last three weeks have posted 9, 11, and 9, well above the nine-week average of 7.0.

The composition matters more than the count. This week’s nine were unusually concentrated in the software supply chain and AI infrastructure rather than the usual mix of edge appliances and end-user software. That shifts the change-management burden toward teams that may not have treated their CI/CD and model-serving stack as production infrastructure with an emergency-patch obligation. If your KEV triage still routes everything to the endpoint and network teams, this week is the argument for adding the platform and MLOps teams to the distribution list.
The takeaway for change teams
The connective tissue this week is asset scope. AI gateways, pipeline orchestrators, and artifact repositories are now KEV-eligible attack surface with the same three-day clocks as firewalls, and the “boring” utility servers keep generating emergency changes. Both point at the same fix: a current, reconciled asset inventory that scores criticality by exposure and blast radius, not by how important the system felt when it was installed.
Subscribe to the newsletter to get this digest in your inbox every Friday — one email, primary sources, no fluff.
Recommended reading from this week:
- Asset Exposure Discovery Tools Compared: 4 Approaches
- Asset Inventory Reconciliation: The Quarterly Change
- How to Read a CISA KEV Entry
Sources
- CISA — Known Exploited Vulnerabilities Catalog
- Cloudflare — System status history
- GitHub — System status
- Microsoft Security — When AI infrastructure becomes the target
- DORA — Regulation news and updates
- Cybersecurity Dive — PaperCut emergency patches as threat actors chain vulnerabilities
- NVD — CVE-2026-49869 (Kestra OSS, CVSS 10.0)
Published September 4, 2026.