Weekly CVE triage for IT teams
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
New subscribers get the CVE triage cheat sheet, a one-page printable, in the welcome email. The weekly digest lands every Wednesday. Free, unsubscribe anytime.
Source-linked. Human-reviewed. Wednesday mornings.
A sample of the latest issue
AUG 17 · Nº081An attacker can send malicious serialized data to Microsoft HPC Pack 2019 over the network and get code execution, no authentication required.
The call: Apply the latest Microsoft security update for HPC Pack 2019 and verify your HPC head nodes are not exposed to the internet.
Plus 4 more calls in the latest issue. See the whole thing
Source-linked
Every verdict links to a primary source.
NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.
Human-reviewed
A working sysadmin edits before it ships.
Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.
Editorial verdicts
One call per CVE. Four minutes total.
Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.
Today's digest, in full
The other 4 calls for Monday, August 17.
The four-verdict model
Every CVE gets one of these four calls.
No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.
- Patch now
Exploited in the wild, or exposed and trivially exploitable. Today’s change window.
- Patch this week
Real risk, no active exploitation yet. Slot it into your next maintenance window.
- Track
Worth knowing about. No action needed today; check back if the advisory changes.
- Doesn't apply
Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.
Who reads this
Built for IT teams who do their own patching.
For sysadmins
The lone admin running fifty servers.
You don’t have time to read three feeds and a Discord. One email, one verdict per CVE, before standup.
Built for thisFor MSPs
Twenty clients, twenty stacks.
Each CVE is tagged by vendor and product, so a quick scan picks out what matters to your fleet. Forward the digest to whoever’s on rotation.
Built for thisFor IT managers
Brief leadership in one paragraph.
The intro summarizes what shipped, what’s on fire, and what to ignore. Forwardable in one click to whoever signs off on the change window.
Built for thisFor lean IT teams
No Tenable, no Qualys, no full-time analyst.
The digest is the triage layer you don’t have to staff.
Built for thisThe archive
Recent digests.
HPC Pack 9.8 deserialization RCE, KVM guest-to-host escape, and Teams XSS
Microsoft HPC Pack 2019 has a no-auth remote code execution bug via serialized payloads (CVE-2026-59124, CVSS 9.8). Also: a KVM nested-virt flaw lets AMD guests DoS the host (8.2), XSS in Teams for Android (8.8) and Azure Storage Explorer (8.8), plus a local PowerShell command injection (7.8). Nothing exploited in the wild yet, but that HPC Pack attack surface is trivial.
Edge heap overflow, a 9.8 SQLi with full PoC, and a PowerShell privesc
CVE-2026-72970 hits Edge with unauthenticated remote code execution (CVSS 8.3), Metacat's REST API is wide open to unauthenticated SQL injection with public exploits (CVSS 9.8), and a PowerShell command injection gives local attackers an easy privilege escalation path (CVSS 7.8). WordPress and AllData bugs round it out.
ManageEngine auth bypass hands attackers the keys to your vault
CVE-2026-12263 (CVSS 8.8) lets unauthenticated attackers walk past SAML validation in Password Manager Pro and PAM360. Also: SQL injection in Hongjing e-HR, a KVM s390 host memory corruption bug, an IBM i privilege escalation, and a cross-tenant boundary break in Multicluster Engine.
FortiWeb auth bypass, two 9.9 Kubernetes privescs, and a zero-auth Android takeover
FortiWeb lets anyone log in with any credentials (CVE-2026-26035, CVSS 9.8). Two CVSS 9.9 bugs in Red Hat MCE and RHACM let namespace-scoped users escalate to full cluster compromise. Microsoft's UFO framework exposes unauthenticated device control on two open ports.
From the blog
Playbooks the digest can't fit.
Close the gap between your declared policy and what the box is actually running
A one-off registry edit closes a ticket and never makes it back into the GPO. Here's the three-surface audit that catches the drift, plus the one decision that actually closes the loop.
ReadAudit your suppression graveyard before a live page dies in it
Silences, downtimes, and maintenance windows get created for good reasons and never revisited. Here are the enumeration commands and three cleanup flags that find the ones that have quietly gone bad.
ReadFive checks for Intune driver update policy coverage
Windows Autopatch manages your OS updates. Your kernel-level drivers are on their own unless you built a separate driver update policy. Here is how to tell if yours is missing and how to fix it.
ReadStart here
The ones worth reading first.
- CISA just gave the Conficker bug a 2026 deadline
- Five critical Fortinet CVEs in 28 months is not a streak of bad luck
- CitrixBleed: the patch closed the leak but left the stolen keys working
- Jenkins CVE-2024-23897: from 'limited file read' to your secret key
- The other half of the ScreenConnect chain just got a 2026 deadline
- Nine PowerShell checks before you trust a Windows host
- Does this CVE actually apply to you? Three filters before you patch
- A defensible software inventory you can build with the tools you already have
- When breaking the maintenance window is cheaper than waiting
- A 30-minute Patch Tuesday triage you can actually run
Get the cheat sheet and the digest
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
- 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
- 02 The weekly digest, one email every Wednesday, around four minutes to read.
Free. Unsubscribe anytime.