PatchDayAlert
01

Source-linked

Every verdict links to a primary source.

NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.

02

Human-reviewed

A working sysadmin edits before it ships.

Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.

03

Editorial verdicts

One call per CVE. Four minutes total.

Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.

The four-verdict model

Every CVE gets one of these four calls.

No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.

  1. Patch now

    Exploited in the wild, or exposed and trivially exploitable. Today’s change window.

  2. Patch this week

    Real risk, no active exploitation yet. Slot it into your next maintenance window.

  3. Track

    Worth knowing about. No action needed today; check back if the advisory changes.

  4. Doesn't apply

    Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.

The archive

Recent digests.

Full archive
Nº040 JUN 17

Firefox sandbox escape, a Dell RCE, and a Pacemaker crasher walk into your queue

CVE-2026-12289 lets attackers break out of Firefox/Thunderbird's WebRender sandbox (CVSS 8.8). Dell OpenManage and Pacemaker CIB also carry 8.6+ bugs, plus a command injection in Galaxy NG and a TLS bypass between Harvester and Rancher.

5 CVEs
0 Crit
0 KEV
4 min
Nº039 JUN 16

WordPress RCE at 9.8 unauthed, Defender privesc unpatched, OpenSSL nonce fail

A PHP Object Injection in a Salesforce/CF7 WordPress plugin needs no login and scores CVSS 9.8. Microsoft Defender's Malware Protection Engine has a local-to-SYSTEM escalation (CVSS 7.8) with no fix shipped yet. OpenSSL silently ignores IVs in AES-OCB mode, breaking encryption guarantees.

5 CVEs
1 Crit
0 KEV
4 min
Nº038 JUN 15
Exploited

PeopleSoft takeover exploited in the wild, plus a 9.1 CMS forgery bug in OpenSSL

An unauthenticated PeopleSoft PeopleTools compromise (CVE-2026-35273) is already being exploited. Also: a CVSS 9.1 CMS AuthEnvelopedData forgery affecting OpenSSL, Node.js, and QEMU (CVE-2026-34182), a Zoom mobile privilege escalation, a public exploit for a Revo Uninstaller kernel driver, and a SQLite FTS5 heap overflow.

5 CVEs
1 Crit
1 KEV
4 min
Nº037 JUN 12

MariaDB Galera hits CVSS 10.0: unauthenticated RCE through a clustering feature

A shell injection in wsrep_notify_cmd gives attackers full code execution on MariaDB Galera clusters with no auth required. Also: a Chrome macOS use-after-free (8.8), a 389 Directory Server heap smash reachable by any domain user (7.6), and a MongoDB server-side JS memory leak (8.8).

5 CVEs
1 Crit
0 KEV
4 min

Get the cheat sheet and the digest

CVE triage for sysadmins in five minutes.

What to patch now. What can wait. What you can ignore.

  1. 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
  2. 02 The weekly digest, one email every Wednesday, around four minutes to read.

Free. Unsubscribe anytime.