Weekly CVE triage for IT teams
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
New subscribers get the CVE triage cheat sheet, a one-page printable, in the welcome email. The weekly digest lands every Wednesday. Free, unsubscribe anytime.
Source-linked. Human-reviewed. Wednesday mornings.
A sample of the latest issue
SEP 5 · Nº098An authenticated attacker with SuperAdmin access to SonicWall NSM's on-prem management interface can inject OS commands that run directly on the underlying host.
The call: Apply the latest SonicWall NSM on-prem update from SonicWall's advisory, and audit SuperAdmin accounts for unauthorized access.
Plus 4 more calls in the latest issue. See the whole thing
Source-linked
Every verdict links to a primary source.
NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.
Human-reviewed
A working sysadmin edits before it ships.
Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.
Editorial verdicts
One call per CVE. Four minutes total.
Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.
Today's digest, in full
The other 4 calls for Saturday, September 5.
The four-verdict model
Every CVE gets one of these four calls.
No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.
- Patch now
Exploited in the wild, or exposed and trivially exploitable. Today’s change window.
- Patch this week
Real risk, no active exploitation yet. Slot it into your next maintenance window.
- Track
Worth knowing about. No action needed today; check back if the advisory changes.
- Doesn't apply
Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.
Who reads this
Built for IT teams who do their own patching.
For sysadmins
The lone admin running fifty servers.
You don’t have time to read three feeds and a Discord. One email, one verdict per CVE, before standup.
Built for thisFor MSPs
Twenty clients, twenty stacks.
Each CVE is tagged by vendor and product, so a quick scan picks out what matters to your fleet. Forward the digest to whoever’s on rotation.
Built for thisFor IT managers
Brief leadership in one paragraph.
The intro summarizes what shipped, what’s on fire, and what to ignore. Forwardable in one click to whoever signs off on the change window.
Built for thisFor lean IT teams
No Tenable, no Qualys, no full-time analyst.
The digest is the triage layer you don’t have to staff.
Built for thisThe archive
Recent digests.
AutoAgent's unauthenticated root shell and a SonicWall NSM command injection top a rough Saturday
CVE-2026-86124 (CVSS 9.8) gives any network attacker a root shell on AutoAgent with zero auth. CVE-2026-78327 (CVSS 9.1) lets SuperAdmins run OS commands on SonicWall NSM. Plus local privesc bugs in Acunetix and PassMark's kernel driver.
Two perfect 10.0s in Azure, a Chrome Android sandbox escape, and an Entra ID auth bypass
Azure AD B2C and Azure AI Language both score CVSS 10.0 with no auth required. Chrome on Android has a 9.6 WebGL sandbox escape, Entra ID has a 9.1 auth bypass, and Copilot Studio has a 9.3 signature verification failure.
Cisco Nexus 9000 unauthenticated root takeover tops a 5-CVE Thursday
A CVSS 9.8 no-auth RCE on Nexus 9000 switch ports 43210/43211 leads the list, followed by a 9.1 root-level command injection in Submariner's gateway nodes. Also: rpmbuild shell injection, a GStreamer RTSP crash, and a Cisco IP phone memory leak.
SQL injection in your password vault: ManageEngine PAM products at 8.8
ManageEngine Password Manager Pro, PAM360, and Access Manager Plus have an authenticated SQLi that could dump every stored credential. Also: Firefox sandbox escape via graphics memory corruption (8.8), Jolokia JNDI injection bypassing the denylist (8.1), SonicWall SMA1000 command injection (7.8), and an OpenShift OAuth DoS that blocks cluster auth (7.5).
From the blog
Playbooks the digest can't fit.
Close the gap between your declared policy and what the box is actually running
A one-off registry edit closes a ticket and never makes it back into the GPO. Here's the three-surface audit that catches the drift, plus the one decision that actually closes the loop.
ReadAudit your suppression graveyard before a live page dies in it
Silences, downtimes, and maintenance windows get created for good reasons and never revisited. Here are the enumeration commands and three cleanup flags that find the ones that have quietly gone bad.
ReadFive checks for Intune driver update policy coverage
Windows Autopatch manages your OS updates. Your kernel-level drivers are on their own unless you built a separate driver update policy. Here is how to tell if yours is missing and how to fix it.
ReadStart here
The ones worth reading first.
- CISA just gave the Conficker bug a 2026 deadline
- Five critical Fortinet CVEs in 28 months is not a streak of bad luck
- CitrixBleed: the patch closed the leak but left the stolen keys working
- Jenkins CVE-2024-23897: from 'limited file read' to your secret key
- The other half of the ScreenConnect chain just got a 2026 deadline
- Nine PowerShell checks before you trust a Windows host
- Does this CVE actually apply to you? Three filters before you patch
- A defensible software inventory you can build with the tools you already have
- When breaking the maintenance window is cheaper than waiting
- A 30-minute Patch Tuesday triage you can actually run
Get the cheat sheet and the digest
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
- 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
- 02 The weekly digest, one email every Wednesday, around four minutes to read.
Free. Unsubscribe anytime.