PatchDayAlert
01

Source-linked

Every verdict links to a primary source.

NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.

02

Human-reviewed

A working sysadmin edits before it ships.

Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.

03

Editorial verdicts

One call per CVE. Four minutes total.

Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.

The four-verdict model

Every CVE gets one of these four calls.

No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.

  1. Patch now

    Exploited in the wild, or exposed and trivially exploitable. Today’s change window.

  2. Patch this week

    Real risk, no active exploitation yet. Slot it into your next maintenance window.

  3. Track

    Worth knowing about. No action needed today; check back if the advisory changes.

  4. Doesn't apply

    Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.

The archive

Recent digests.

Full archive
Nº098 SEP 5

AutoAgent's unauthenticated root shell and a SonicWall NSM command injection top a rough Saturday

CVE-2026-86124 (CVSS 9.8) gives any network attacker a root shell on AutoAgent with zero auth. CVE-2026-78327 (CVSS 9.1) lets SuperAdmins run OS commands on SonicWall NSM. Plus local privesc bugs in Acunetix and PassMark's kernel driver.

5 CVEs
2 Crit
0 KEV
4 min
Nº097 SEP 4

Two perfect 10.0s in Azure, a Chrome Android sandbox escape, and an Entra ID auth bypass

Azure AD B2C and Azure AI Language both score CVSS 10.0 with no auth required. Chrome on Android has a 9.6 WebGL sandbox escape, Entra ID has a 9.1 auth bypass, and Copilot Studio has a 9.3 signature verification failure.

5 CVEs
5 Crit
0 KEV
4 min
Nº096 SEP 3

Cisco Nexus 9000 unauthenticated root takeover tops a 5-CVE Thursday

A CVSS 9.8 no-auth RCE on Nexus 9000 switch ports 43210/43211 leads the list, followed by a 9.1 root-level command injection in Submariner's gateway nodes. Also: rpmbuild shell injection, a GStreamer RTSP crash, and a Cisco IP phone memory leak.

5 CVEs
2 Crit
0 KEV
4 min
Nº095 SEP 2

SQL injection in your password vault: ManageEngine PAM products at 8.8

ManageEngine Password Manager Pro, PAM360, and Access Manager Plus have an authenticated SQLi that could dump every stored credential. Also: Firefox sandbox escape via graphics memory corruption (8.8), Jolokia JNDI injection bypassing the denylist (8.1), SonicWall SMA1000 command injection (7.8), and an OpenShift OAuth DoS that blocks cluster auth (7.5).

5 CVEs
0 Crit
0 KEV
4 min

Get the cheat sheet and the digest

CVE triage for sysadmins in five minutes.

What to patch now. What can wait. What you can ignore.

  1. 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
  2. 02 The weekly digest, one email every Wednesday, around four minutes to read.

Free. Unsubscribe anytime.