IT News W40/2026: CUDA 13 becomes the floor, Nginx Proxy Manager without a fix, and the wrong 60 per cent
This edition covers Monday and Tuesday of week 40, measured on 29 September 2026. The weekend and everything up to Sunday night is in the week 39 edition as always, including the SharePoint correction worked in there. Seven posts appeared across these two days, all dated Tuesday; three of the systems we write about we measured ourselves today: the inference engine, Nginx Proxy Manager and the mail server.
Deep dive: CUDA 13 becomes the floor
vLLM v0.30.0 of 22 September builds against CUDA 13.0 by default, llama.cpp v0.5.0 of 23 September ships CUDA-13.4 builds and moves the RPC protocol to major v7. For operations that means: measure the driver before pulling the image, and update llama.cpp across all hosts in one round, mixed states no longer speak on the RPC path. Measured on ours on 29 September: the fallback lane reports 0.30.0 on port 8080, the host sits on driver 610.57.04, the CUDA-13 build runs clean. The second inference host reports a nightly state (0.1.dev20073+g8e685d198) comparable to no release line. Good news for consumer-card owners: this week's NVFP4 success story applies only to SM100 and SM103, the RTX 5090 is SM120 and stays on Marlin. The full text with the breaking points, the two new memory tricks (weight-cache daemon, KV paging into host RAM) and the numbers: CUDA 13 becomes the floor.
Assessment: No drama, but a plan-day. Anyone pulling vLLM images without knowing the driver gets the crash loop after the pull instead of before it.
Deep dive: Two advisories for Nginx Proxy Manager, no fixed version
On 29 September at 00:31 UTC two security advisories for Nginx Proxy Manager went out: GHSA-pm9h-p429-j8c5 (critical, the token endpoints around /api/tokens without a rate limit, so token brute force) and GHSA-886j-w36h-wmx2 (high, injection of nginx directives through the advanced_config fields, on the standard image that means code execution in the container). Both name "through 2.16.0" as the affected range, and 2.16.0 is the last release in the repo. There is no version to update to right now, so the lever sits on the network side: console reachability, length of the admin list, visibility on the token endpoints. Measured on ours: our own estate stands on 2.16.0, inside the affected range. Whether the console would be reachable from outside, we tested from our external vantage: the usual DNS candidates under our four domains all run into NXDOMAIN, the console hangs on the internal address. The post with the checklist for the day a release does arrive: Nginx Proxy Manager without a fix.
Assessment: The more unpleasant of the week's news, because "pull the update" falls away as an answer. For a front-door proxy many setups have run unchanged for years, the reach is large.
Digest: Other important news
Security and reports
- Plugin4Shell is the report of the week for anyone running coding agents with plugin access: the pin to a commit hash formalises the guard, but if your own git host allows branch names in hash form, the name beats the object. Claude Code patched from 2.1.179, Codex from 0.146.0, Copilot without fix, Gemini CLI no longer patched by Google, no CVE, no in-the-wild exploitation, version numbers from a press report rather than advisories. Sorted, with the four moves you can verify without believing: Plugin4Shell.
- The annual ENISA threat report, published 22 September on the basis of 2025 incidents. The coverage circulates the figure that 60 per cent of unauthorised access ran through known vulnerabilities; ENISA itself says: of the 5 per cent of incidents with an identified vector, 60 per cent used a vulnerability, and for 95 per cent the entry route stayed unknown. The correct reading is the more unpleasant one, especially for your inventory. Public administration most targeted, transport behind it, 73 per cent of entities NIS2-relevant. For us that is the NISG reference, and it has been law for two days: reading the annual report right.
- MikroTik MikroTrick (CVE-2026-20129, in the KEV since Friday, active exploitation reported): cert.pl published the campaign's indicators, an account named
opsand two IP addresses (82.192.72.4,103.102.31.18). If you run no MikroTik gear, you need none of the rest; if you do, check the account list first. For the hunt: CISA KEV. - Stalwart: on Monday still measured as "the straggler not in yet", read off today: the mail host runs 0.16.24, container
pmg-stalwart, state of 29 September. The silent message loss from 0.16.23 and the DANE-stop fix are done with that, as are the two 0.16.24 entries (JMAP keyword set with IMAP id 0, rule imports that never arrived).
Lifecycle and deadlines
- Beyond Windows 11 24H2 (13 October, already here last week), 13 October 2026 is also the end of support for Office 2021 and Office LTSC 2021; anyone running those locally needs a plan by then. The blueprint of what goes wrong at such an end is KB5002907 right now: an optional repair update for outdated Microsoft 365 installations that switched off the activation of purchased perpetual Office 2016 and 2019 licences and even removed installations, whereupon Microsoft stopped the rollout; the confirmation page at Microsoft describes the investigation, a fix does not exist. Lifecycle overview at Microsoft.
- Google set the ChromeOS support ends to mid-2034 and Googlebook management to H2/2027, the lists sit at Google.
- NISG: our registration post was corrected today, the deadline in the USP wording literally reads "initial by 1 January 2027", the WKO runs the window to 31 December 2026, NISG registration.
AI and operations
- llama.cpp builds daily on past the major release, beyond b11240 there is also a fix to KV-cache reuse in there, the builds.
From the blog
Seven posts since Monday, each with a source list:
-
Anthropic's IPO prospectus: a 42 billion dollar loss on 4.6 billion dollars of revenue
-
Claude Sonnet 5.5: Anthropic says 30% cheaper per task, independent measurement says 50% dearer
-
Holo4: open computer-use models, and the best of them is non-commercial
-
Two advisories for Nginx Proxy Manager: 2.16.0 affected, no patch
-
Plugin4Shell: the commit-hash pin fails when the branch looks like a hash
Sources of this edition
Every address was reachable again on 29 September 2026. The host measurements (vLLM version and driver on the fallback lane, Stalwart version on the mail host, DNS probe of the NPM console) are from today and stand with timestamp in the text.
- vLLM releases, llama.cpp v0.5.0, llama.cpp daily builds
- GHSA-pm9h-p429-j8c5, GHSA-886j-w36h-wmx2, jc21/nginx-proxy-manager
- The Hacker News on Plugin4Shell, weekly recap
- ENISA press release of 22 September 2026, ENISA Threat Landscape 2026
- CISA KEV, Microsoft lifecycle, ComputerBase on KB5002907 with Microsoft's confirmation page, Google ChromeOS support ends, Stalwart releases
Compiled on Tuesday, 29 September 2026. This edition opens week 40; what arrives from Wednesday on is covered by the week 41 edition next Monday. Measurements on GPU host .180.3 were possible only via the API (version), its driver level stayed open.
senn-tech