PatchDayAlert
01

Source-linked

Every verdict links to a primary source.

NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.

02

Human-reviewed

A working sysadmin edits before it ships.

Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.

03

Editorial verdicts

One call per CVE. Four minutes total.

Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.

The four-verdict model

Every CVE gets one of these four calls.

No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.

  1. Patch now

    Exploited in the wild, or exposed and trivially exploitable. Today’s change window.

  2. Patch this week

    Real risk, no active exploitation yet. Slot it into your next maintenance window.

  3. Track

    Worth knowing about. No action needed today; check back if the advisory changes.

  4. Doesn't apply

    Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.

The archive

Recent digests.

Full archive
Nº107 SEP 15

Cisco email gateway RCE at 9.8, two Office buffer overflows, and a hardcoded JWT key

CVE-2026-76461 lets an unauthenticated attacker land root on Cisco Secure Email Gateway with a single poisoned email. PraisonAI ships a default JWT secret that hands over full impersonation. Microsoft Office and Windows Graphics both carry 8.8 heap/stack overflows. Firefox 156 fixes a DevTools sandbox escape.

5 CVEs
2 Crit
0 KEV
4 min
Nº106 SEP 14

PraisonAI's wide-open API lets attackers run OS commands, no auth required

CVE-2026-57125 (CVSS 9.8) is an unauth RCE in PraisonAI's Jobs API via crafted YAML. Also: two Zscaler Client Connector bugs on Android/ChromeOS (CVSS 8.1 each) and two GIMP heap overflows in PSP and ICO file loaders (CVSS 7.8).

5 CVEs
1 Crit
0 KEV
4 min
Nº105 SEP 13

IDM's kernel driver hands out SYSTEM, Orion Visor's hardcoded key leaks every credential

CVE-2026-90493 (CVSS 8.8) is a privilege escalation in Internet Download Manager's idmwfp.sys driver with a public exploit and no vendor response. CVE-2026-90510 (CVSS 8.3) exposes all stored host credentials in Orion Visor through a hardcoded encryption key. Plus unpatched SQLi in Feng Office and a certificate validation failure in Kalkitech ICS gear.

5 CVEs
0 Crit
0 KEV
4 min
Nº104 SEP 12

GitLab CVSS 10.0 file read, Fortinet hardcoded creds, and an Edge use-after-free

An unauthenticated path traversal in GitLab exposes any file on disk (CVE-2026-85706, CVSS 10.0). Fortinet FortiMonitorOnSight ships hardcoded credentials reachable without auth (CVE-2026-84390, CVSS 9.8). Edge gets a Chromium use-after-free at CVSS 8.5, plus MongoDB and MoguBlog fixes.

5 CVEs
2 Crit
0 KEV
4 min

Get the cheat sheet and the digest

CVE triage for sysadmins in five minutes.

What to patch now. What can wait. What you can ignore.

  1. 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
  2. 02 The weekly digest, one email every Wednesday, around four minutes to read.

Free. Unsubscribe anytime.