PatchDayAlert
01

Source-linked

Every verdict links to a primary source.

NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.

02

Human-reviewed

A working sysadmin edits before it ships.

Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.

03

Editorial verdicts

One call per CVE. Four minutes total.

Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.

The four-verdict model

Every CVE gets one of these four calls.

No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.

  1. Patch now

    Exploited in the wild, or exposed and trivially exploitable. Today’s change window.

  2. Patch this week

    Real risk, no active exploitation yet. Slot it into your next maintenance window.

  3. Track

    Worth knowing about. No action needed today; check back if the advisory changes.

  4. Doesn't apply

    Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.

The archive

Recent digests.

Full archive
Nº081 AUG 17

HPC Pack 9.8 deserialization RCE, KVM guest-to-host escape, and Teams XSS

Microsoft HPC Pack 2019 has a no-auth remote code execution bug via serialized payloads (CVE-2026-59124, CVSS 9.8). Also: a KVM nested-virt flaw lets AMD guests DoS the host (8.2), XSS in Teams for Android (8.8) and Azure Storage Explorer (8.8), plus a local PowerShell command injection (7.8). Nothing exploited in the wild yet, but that HPC Pack attack surface is trivial.

5 CVEs
1 Crit
0 KEV
4 min
Nº080 AUG 15

Edge heap overflow, a 9.8 SQLi with full PoC, and a PowerShell privesc

CVE-2026-72970 hits Edge with unauthenticated remote code execution (CVSS 8.3), Metacat's REST API is wide open to unauthenticated SQL injection with public exploits (CVSS 9.8), and a PowerShell command injection gives local attackers an easy privilege escalation path (CVSS 7.8). WordPress and AllData bugs round it out.

5 CVEs
1 Crit
0 KEV
4 min
Nº079 AUG 14

ManageEngine auth bypass hands attackers the keys to your vault

CVE-2026-12263 (CVSS 8.8) lets unauthenticated attackers walk past SAML validation in Password Manager Pro and PAM360. Also: SQL injection in Hongjing e-HR, a KVM s390 host memory corruption bug, an IBM i privilege escalation, and a cross-tenant boundary break in Multicluster Engine.

5 CVEs
0 Crit
0 KEV
4 min
Nº078 AUG 13

FortiWeb auth bypass, two 9.9 Kubernetes privescs, and a zero-auth Android takeover

FortiWeb lets anyone log in with any credentials (CVE-2026-26035, CVSS 9.8). Two CVSS 9.9 bugs in Red Hat MCE and RHACM let namespace-scoped users escalate to full cluster compromise. Microsoft's UFO framework exposes unauthenticated device control on two open ports.

5 CVEs
5 Crit
0 KEV
4 min

Get the cheat sheet and the digest

CVE triage for sysadmins in five minutes.

What to patch now. What can wait. What you can ignore.

  1. 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
  2. 02 The weekly digest, one email every Wednesday, around four minutes to read.

Free. Unsubscribe anytime.