PatchDayAlert

Free · Wednesday mornings

The weekly digest. Straight to your inbox.

Written for sysadmins. Not security researchers. Not CISOs. You: the person who just got 12 CISA tickets assigned with zero context and is expected to triage them by lunch.

One issue, every Wednesday. The week Microsoft ships Patch Tuesday, it's in the same issue.

New subscribers get the CVE triage cheat sheet, a printable one-pager for triaging fresh CVEs, in the welcome email.


What you get

  1. 01

    Plain-English CVE summaries

    If you can't read a CVE writeup cold and know what to do, the digest is for you. No CVSS jargon dumps.

  2. 02

    Patch urgency in one line

    Patch today, patch this week, or safe to skip. Every entry. No ambiguity about what the ticket needs.

  3. 03

    Exploited-in-the-wild front and center

    CISA KEV catches things NVD-severity alone misses. Anything actively exploited gets flagged before anything else.

  4. 04

    Rare alerts when it can't wait

    Most weeks, Wednesday is soon enough. When something is actively exploited and a fix exists, you get a separate heads-up. Only when it matters, never for filler.


Latest sample issue

Sep 15, 2026 · Subject: Cisco Email Gateway RCE (9.8) + Office heap overflow

Cisco email gateway RCE at 9.8, two Office buffer overflows, and a hardcoded JWT key

Two CVSS 9.8s and a trio of 8.8s landed today, none exploited in the wild yet, but don't let that make you comfortable. The headliner is CVE-2026-76461: unauthenticated root-level code execution on Cisco Secure Email Gateway via a poisoned email. No creds, no clicks, just a crafted message passing through your gateway. If you run Cisco SEG, bump this to the top of your queue right now.

One item / urgency verdict

Patch this week

CVE-2026-78517

An attacker can send a malicious Word document that triggers a heap buffer overflow, giving them code execution on the victim's machine over the network.

Apply the latest Microsoft Office security update via Windows Update or the Microsoft 365 admin center.