Weekly CVE triage for IT teams
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
New subscribers get the CVE triage cheat sheet, a one-page printable, in the welcome email. The weekly digest lands every Wednesday. Free, unsubscribe anytime.
Source-linked. Human-reviewed. Wednesday mornings.
A sample of the latest issue
JUL 23 · Nº060An attacker can inject shell commands through the Ansible Lightspeed VS Code extension's container and volume mount settings.
The call: Update the Ansible Lightspeed VS Code extension to the latest patched version from the VS Code marketplace.
Plus 4 more calls in the latest issue. See the whole thing
Source-linked
Every verdict links to a primary source.
NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.
Human-reviewed
A working sysadmin edits before it ships.
Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.
Editorial verdicts
One call per CVE. Four minutes total.
Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.
Today's digest, in full
The other 4 calls for Thursday, July 23.
The four-verdict model
Every CVE gets one of these four calls.
No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.
- Patch now
Exploited in the wild, or exposed and trivially exploitable. Today’s change window.
- Patch this week
Real risk, no active exploitation yet. Slot it into your next maintenance window.
- Track
Worth knowing about. No action needed today; check back if the advisory changes.
- Doesn't apply
Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.
Who reads this
Built for IT teams who do their own patching.
For sysadmins
The lone admin running fifty servers.
You don’t have time to read three feeds and a Discord. One email, one verdict per CVE, before standup.
Built for thisFor MSPs
Twenty clients, twenty stacks.
Each CVE is tagged by vendor and product, so a quick scan picks out what matters to your fleet. Forward the digest to whoever’s on rotation.
Built for thisFor IT managers
Brief leadership in one paragraph.
The intro summarizes what shipped, what’s on fire, and what to ignore. Forwardable in one click to whoever signs off on the change window.
Built for thisFor lean IT teams
No Tenable, no Qualys, no full-time analyst.
The digest is the triage layer you don’t have to staff.
Built for thisThe archive
Recent digests.
Three command injections in Ansible Lightspeed, plus MongoDB RBAC bypass
CVE-2026-44189/44190/44191 all hit CVSS 7.8: opening a malicious project in VS Code gives an attacker shell access. MongoDB also has an 8.1 RBAC bypass (CVE-2026-13059) that lets low-privilege users read and write across tenant boundaries.
FortiSandbox, SharePoint, and WordPress RCE all exploited in the wild
Five actively exploited bugs today. Unauthenticated command execution on FortiSandbox (EPSS 0.84), a CVSS 9.8 WordPress REST API chain hitting 6.9.x and 7.0.x, unauth deserialization RCE in on-prem SharePoint, a DD-WRT UPnP overflow, and remote code execution in Langflow.
Langroid scores a perfect 10 RCE, plus two Juniper DoS bugs that crash your firewall
Langroid's broken eval() sandbox gives attackers full code execution (CVE-2026-54769, CVSS 10.0). A guardrails-detectors SSRF can steal cloud credentials (CVSS 9.3). Two Juniper SRX/MX flaws let a single packet crash flowd if SIP ALG or TCP proxy is active.
CoreWCF auth bypass scores a perfect 10, Chrome sandbox escape close behind
A broken SAML token check in CoreWCF (CVE-2026-54782, CVSS 10.0) lets anyone forge tokens and impersonate users. Chrome on Android has a 9.6 use-after-free sandbox escape via Autofill, plus a NATS Server auth skip (8.8), a GStreamer DTLS stack overflow (7.5), and a Dynamics 365 XSS (9.3).
From the blog
Playbooks the digest can't fit.
Close the gap between your declared policy and what the box is actually running
A one-off registry edit closes a ticket and never makes it back into the GPO. Here's the three-surface audit that catches the drift, plus the one decision that actually closes the loop.
ReadAudit your suppression graveyard before a live page dies in it
Silences, downtimes, and maintenance windows get created for good reasons and never revisited. Here are the enumeration commands and three cleanup flags that find the ones that have quietly gone bad.
ReadFive checks for Intune driver update policy coverage
Windows Autopatch manages your OS updates. Your kernel-level drivers are on their own unless you built a separate driver update policy. Here is how to tell if yours is missing and how to fix it.
ReadStart here
The ones worth reading first.
- CISA just gave the Conficker bug a 2026 deadline
- Five critical Fortinet CVEs in 28 months is not a streak of bad luck
- CitrixBleed: the patch closed the leak but left the stolen keys working
- Jenkins CVE-2024-23897: from 'limited file read' to your secret key
- The other half of the ScreenConnect chain just got a 2026 deadline
- Nine PowerShell checks before you trust a Windows host
- Does this CVE actually apply to you? Three filters before you patch
- A defensible software inventory you can build with the tools you already have
- When breaking the maintenance window is cheaper than waiting
- A 30-minute Patch Tuesday triage you can actually run
Get the cheat sheet and the digest
CVE triage for sysadmins in five minutes.
What to patch now. What can wait. What you can ignore.
- 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
- 02 The weekly digest, one email every Wednesday, around four minutes to read.
Free. Unsubscribe anytime.