PatchDayAlert
01

Source-linked

Every verdict links to a primary source.

NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.

02

Human-reviewed

A working sysadmin edits before it ships.

Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.

03

Editorial verdicts

One call per CVE. Four minutes total.

Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.

The four-verdict model

Every CVE gets one of these four calls.

No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.

  1. Patch now

    Exploited in the wild, or exposed and trivially exploitable. Today’s change window.

  2. Patch this week

    Real risk, no active exploitation yet. Slot it into your next maintenance window.

  3. Track

    Worth knowing about. No action needed today; check back if the advisory changes.

  4. Doesn't apply

    Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.

The archive

Recent digests.

Full archive
Nº060 JUL 23

Three command injections in Ansible Lightspeed, plus MongoDB RBAC bypass

CVE-2026-44189/44190/44191 all hit CVSS 7.8: opening a malicious project in VS Code gives an attacker shell access. MongoDB also has an 8.1 RBAC bypass (CVE-2026-13059) that lets low-privilege users read and write across tenant boundaries.

5 CVEs
0 Crit
0 KEV
4 min
Nº059 JUL 22
Exploited

FortiSandbox, SharePoint, and WordPress RCE all exploited in the wild

Five actively exploited bugs today. Unauthenticated command execution on FortiSandbox (EPSS 0.84), a CVSS 9.8 WordPress REST API chain hitting 6.9.x and 7.0.x, unauth deserialization RCE in on-prem SharePoint, a DD-WRT UPnP overflow, and remote code execution in Langflow.

5 CVEs
1 Crit
5 KEV
4 min
Nº058 JUL 10

Langroid scores a perfect 10 RCE, plus two Juniper DoS bugs that crash your firewall

Langroid's broken eval() sandbox gives attackers full code execution (CVE-2026-54769, CVSS 10.0). A guardrails-detectors SSRF can steal cloud credentials (CVSS 9.3). Two Juniper SRX/MX flaws let a single packet crash flowd if SIP ALG or TCP proxy is active.

5 CVEs
2 Crit
0 KEV
4 min
Nº057 JUL 9

CoreWCF auth bypass scores a perfect 10, Chrome sandbox escape close behind

A broken SAML token check in CoreWCF (CVE-2026-54782, CVSS 10.0) lets anyone forge tokens and impersonate users. Chrome on Android has a 9.6 use-after-free sandbox escape via Autofill, plus a NATS Server auth skip (8.8), a GStreamer DTLS stack overflow (7.5), and a Dynamics 365 XSS (9.3).

5 CVEs
3 Crit
0 KEV
4 min

Get the cheat sheet and the digest

CVE triage for sysadmins in five minutes.

What to patch now. What can wait. What you can ignore.

  1. 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
  2. 02 The weekly digest, one email every Wednesday, around four minutes to read.

Free. Unsubscribe anytime.