First Watch locked in a day that opened with two critical Orval import-time RCEs and a four-bug fast-uri SSRF cluster, then escalated at 18:00 ET when CISA confirmed active exploitation of an AI-agent MCP auth bypass the same day three new Omnigent agent-bundle CVEs landed — the AI-agent execution layer became a live target, not a hypothetical one.
Late escalation at 21:00 ET: a four-CVE OpenChoreo disclosure closed out the evening, headlined by an unauthenticated bypass that lets anyone reach the cluster-gateway's externally published listener, proxy the Kubernetes data plane, and exec into workload pods with zero authentication. A second Omnigent Guardrail bug landed in the same window: the shared shell-command parser fails open, so any command it doesn't recognize is silently allowed — defeating both of the product's core safety guarantees for confined agents, and extending tonight's trust question from the agent bundle straight into the policy engine meant to contain it. Two more OpenChoreo bugs — cross-project exec/log access from a single project grant, and an unauthenticated webhook-signature bypass — round out what reads as one coordinated multi-CVE disclosure rather than four unrelated bugs; the rest of the late batch (Mailpit, SeaweedFS, Scrapy, Handlebars.java, Plate, Hurl, DiceBear, Mail) is routine parser and transport hardening, not a second active campaign.
→ Operational priority for the night if you run OpenChoreo's multi-cluster topology, confirm the cluster-gateway listener isn't published externally before your next standup — that single check closes the worst of tonight's four bugs — and if you run Omnigent-gated agents, treat every allowlist as advisory until the shell-parser fix lands, re-verifying against the disclosed bypass classes (bash -lc wrappers, timeout/nice/setsid, git worktree escapes).