Weekly CVE triage for IT teams
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
New subscribers get the CVE triage cheat sheet, a one-page printable, in the welcome email. The weekly digest lands every Wednesday. Free, unsubscribe anytime.
Source-linked. Human-reviewed. Wednesday mornings.
A sample of the latest issue
SEP 15 · Nº107An attacker can send a malicious Word document that triggers a heap buffer overflow, giving them code execution on the victim's machine over the network.
The call: Apply the latest Microsoft Office security update via Windows Update or the Microsoft 365 admin center.
Plus 4 more calls in the latest issue. See the whole thing
Source-linked
Every verdict links to a primary source.
NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.
Human-reviewed
A working sysadmin edits before it ships.
Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.
Editorial verdicts
One call per CVE. Four minutes total.
Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.
Today's digest, in full
The other 4 calls for Tuesday, September 15.
The four-verdict model
Every CVE gets one of these four calls.
No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.
- Patch now
Exploited in the wild, or exposed and trivially exploitable. Today’s change window.
- Patch this week
Real risk, no active exploitation yet. Slot it into your next maintenance window.
- Track
Worth knowing about. No action needed today; check back if the advisory changes.
- Doesn't apply
Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.
Who reads this
Built for IT teams who do their own patching.
For sysadmins
The lone admin running fifty servers.
You don’t have time to read three feeds and a Discord. One email, one verdict per CVE, before standup.
Built for thisFor MSPs
Twenty clients, twenty stacks.
Each CVE is tagged by vendor and product, so a quick scan picks out what matters to your fleet. Forward the digest to whoever’s on rotation.
Built for thisFor IT managers
Brief leadership in one paragraph.
The intro summarizes what shipped, what’s on fire, and what to ignore. Forwardable in one click to whoever signs off on the change window.
Built for thisFor lean IT teams
No Tenable, no Qualys, no full-time analyst.
The digest is the triage layer you don’t have to staff.
Built for thisThe archive
Recent digests.
Cisco email gateway RCE at 9.8, two Office buffer overflows, and a hardcoded JWT key
CVE-2026-76461 lets an unauthenticated attacker land root on Cisco Secure Email Gateway with a single poisoned email. PraisonAI ships a default JWT secret that hands over full impersonation. Microsoft Office and Windows Graphics both carry 8.8 heap/stack overflows. Firefox 156 fixes a DevTools sandbox escape.
PraisonAI's wide-open API lets attackers run OS commands, no auth required
CVE-2026-57125 (CVSS 9.8) is an unauth RCE in PraisonAI's Jobs API via crafted YAML. Also: two Zscaler Client Connector bugs on Android/ChromeOS (CVSS 8.1 each) and two GIMP heap overflows in PSP and ICO file loaders (CVSS 7.8).
IDM's kernel driver hands out SYSTEM, Orion Visor's hardcoded key leaks every credential
CVE-2026-90493 (CVSS 8.8) is a privilege escalation in Internet Download Manager's idmwfp.sys driver with a public exploit and no vendor response. CVE-2026-90510 (CVSS 8.3) exposes all stored host credentials in Orion Visor through a hardcoded encryption key. Plus unpatched SQLi in Feng Office and a certificate validation failure in Kalkitech ICS gear.
GitLab CVSS 10.0 file read, Fortinet hardcoded creds, and an Edge use-after-free
An unauthenticated path traversal in GitLab exposes any file on disk (CVE-2026-85706, CVSS 10.0). Fortinet FortiMonitorOnSight ships hardcoded credentials reachable without auth (CVE-2026-84390, CVSS 9.8). Edge gets a Chromium use-after-free at CVSS 8.5, plus MongoDB and MoguBlog fixes.
From the blog
Playbooks the digest can't fit.
Close the gap between your declared policy and what the box is actually running
A one-off registry edit closes a ticket and never makes it back into the GPO. Here's the three-surface audit that catches the drift, plus the one decision that actually closes the loop.
ReadAudit your suppression graveyard before a live page dies in it
Silences, downtimes, and maintenance windows get created for good reasons and never revisited. Here are the enumeration commands and three cleanup flags that find the ones that have quietly gone bad.
ReadFive checks for Intune driver update policy coverage
Windows Autopatch manages your OS updates. Your kernel-level drivers are on their own unless you built a separate driver update policy. Here is how to tell if yours is missing and how to fix it.
ReadStart here
The ones worth reading first.
- CISA just gave the Conficker bug a 2026 deadline
- Five critical Fortinet CVEs in 28 months is not a streak of bad luck
- CitrixBleed: the patch closed the leak but left the stolen keys working
- Jenkins CVE-2024-23897: from 'limited file read' to your secret key
- The other half of the ScreenConnect chain just got a 2026 deadline
- Nine PowerShell checks before you trust a Windows host
- Does this CVE actually apply to you? Three filters before you patch
- A defensible software inventory you can build with the tools you already have
- When breaking the maintenance window is cheaper than waiting
- A 30-minute Patch Tuesday triage you can actually run
Get the cheat sheet and the digest
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
- 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
- 02 The weekly digest, one email every Wednesday, around four minutes to read.
Free. Unsubscribe anytime.