<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PatchDay Alert</title><description>Daily CVE digests and sysadmin security guides.</description><link>https://patchdayalert.com/</link><language>en-us</language><item><title>Chrome sandbox escape chain, a WattBox sticker-to-root bug, and a dead Apache project</title><link>https://patchdayalert.com/digest/2026-04-29/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-29/</guid><description>Two Chrome use-after-free bugs (CVE-2026-7343 + CVE-2026-7341, both CVSS 9.8) chain renderer compromise to full sandbox escape on Windows. Snap One WattBox 800/820 PDUs authenticate diagnostics endpoints with the MAC address printed on the label. Apache Pony Mail (Lua) has a 9.8 account takeover with no fix coming because the project is retired.</description><pubDate>Wed, 29 Apr 2026 11:00:00 GMT</pubDate></item><item><title>Five 9.8s on SOHO routers: Totolink and D-Link firmware is Swiss cheese</title><link>https://patchdayalert.com/digest/2026-04-28/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-28/</guid><description>Four public command injection exploits hit the Totolink A8000RU and one buffer overflow nails the D-Link DI-8100. All CVSS 9.8, all pre-auth, all with public exploit code. If either device is in your stack, pull it off the internet now.</description><pubDate>Tue, 28 Apr 2026 11:00:00 GMT</pubDate></item><item><title>What patching looks like when you support the whole mess: endpoints, M365, identity, browsers, VPN, and line-of-business tools</title><link>https://patchdayalert.com/blog/patching-the-whole-mess/</link><guid isPermaLink="true">https://patchdayalert.com/blog/patching-the-whole-mess/</guid><description>Patching isn&apos;t Windows Updates anymore. A tour of the six surfaces a real shop patches every week.</description><pubDate>Tue, 28 Apr 2026 11:00:00 GMT</pubDate></item><item><title>Patch now, patch later, ignore for now: the triage model real IT teams actually need</title><link>https://patchdayalert.com/blog/patch-now-patch-later-ignore-for-now/</link><guid isPermaLink="true">https://patchdayalert.com/blog/patch-now-patch-later-ignore-for-now/</guid><description>A three-bucket triage model for sysadmins who don&apos;t own a vulnerability scanner and aren&apos;t going to buy one.</description><pubDate>Tue, 28 Apr 2026 10:00:00 GMT</pubDate></item><item><title>Why most patch summaries fail the people who actually have to do the work</title><link>https://patchdayalert.com/blog/why-most-patch-summaries-fail-operators/</link><guid isPermaLink="true">https://patchdayalert.com/blog/why-most-patch-summaries-fail-operators/</guid><description>Vendor advisories are written for completeness. They&apos;re not written for the operator triaging a CISA KEV ticket before lunch.</description><pubDate>Tue, 28 Apr 2026 09:00:00 GMT</pubDate></item><item><title>5 bugs at CVSS 9.8: Apache MINA&apos;s filter bypassed twice, WordPress plugin to admin in one click</title><link>https://patchdayalert.com/digest/2026-04-27/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-27/</guid><description>Two deserialization bypasses in Apache MINA let attackers slip past the allowlist for RCE, a WordPress privilege escalation hands out admin roles, and a pair of Totolink router command injections have public exploits. All 9.8, none exploited in the wild yet.</description><pubDate>Mon, 27 Apr 2026 11:00:00 GMT</pubDate></item><item><title>Two perfect 10s: Entra ID SSRF and Bing RCE, both unauth, both wide open</title><link>https://patchdayalert.com/digest/2026-04-24/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-24/</guid><description>Microsoft Entra ID Entitlement Management has a CVSS 10.0 SSRF that needs no login, and Bing has a CVSS 10.0 deserialization RCE in the same boat. Hackage-server adds two 9.9 stored XSS bugs, plus a 9.8 crasher in Delta Electronics NAS gear.</description><pubDate>Fri, 24 Apr 2026 11:00:00 GMT</pubDate></item><item><title>Paperclip CVSS 10.0 unauth RCE, plus a 9.9 in FunnelFormsPro and Froxlor</title><link>https://patchdayalert.com/digest/2026-04-23/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-23/</guid><description>Six API calls and no credentials give attackers full control of default Paperclip installs. FunnelFormsPro (WordPress) and Froxlor both carry 9.9 code execution bugs, and Borg SPM 2007 has two 9.8s that will never be patched.</description><pubDate>Thu, 23 Apr 2026 11:00:00 GMT</pubDate></item><item><title>AVideo CVSS 10: one WebSocket message owns every viewer, no click needed</title><link>https://patchdayalert.com/digest/2026-04-22/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-22/</guid><description>A perfect-score stored XSS in AVideo&apos;s YPTSocket hits all connected browsers instantly. Also: Flowise command injection (9.9), ElectricSQL SQL injection that gives full PostgreSQL read/write (9.9), an unauth WordPress SMTP hijack via Sendmachine (9.8), and a Firefox DOM security bypass (9.8).</description><pubDate>Wed, 22 Apr 2026 11:00:00 GMT</pubDate></item><item><title>Four perfect 10s and a 9.9 sandbox escape: Spinnaker, Perl, and OpenClaw all need attention</title><link>https://patchdayalert.com/digest/2026-04-21/</link><guid isPermaLink="true">https://patchdayalert.com/digest/2026-04-21/</guid><description>Two Spinnaker RCEs (CVE-2026-32613, CVE-2026-32604) let attackers run code through pipeline expressions and gitrepo artifact injection. A 9.9 OpenClaw sandbox escape (CVE-2026-41329) bypasses privilege boundaries. Perl&apos;s Storable and Net::Dropbear round out the list with legacy crypto and deserialization bugs, both CVSS 10.0. None are exploited in the wild yet.</description><pubDate>Tue, 21 Apr 2026 11:00:00 GMT</pubDate></item></channel></rss>