v6.40.9 [bugfix] is released!

I agree that the way the patch notes were written made it look way more urgent than it was.
Compared to how the WinBox vulnerability was mentioned in v6.40.8 [bugfix], it makes it looks like the CVE vulnerabilities were much more important.

Changing the way you announce vulnerabilities in patch notes is ok, but you scared everyone by posting the suddenly very huge vulnerability warning with no information in the patch notes.
Writing something simple like you used to do is better. For example:
“!) Webfig: Fixed vulnerabilities allowing a logged in user (even read-only user) to crash the router.”

Then after the blog entry was posted, you could add the CVE id numbers and links to the blog entry in the opening post.