The 5-minute patch brief for the person who actually has to patch stuff.
Jul 1, 2026
•
3 min read
Developer tooling, URL parsing, libzypp repos, Chrome, Keycloak, Flowise, and a long WordPress tail.
Jun 24, 2026
2 min read
Ivanti Sentry, Splunk, Ubiquiti, and Cisco SD-WAN are all under active attack. The patch order, plus this week's KEV additions.
Jun 18, 2026
5 min read
Firefox sandbox escape (CVSS 8.8), Dell OpenManage RCE, and Pacemaker vulnerabilities disclosed. Galaxy NG command injection and Harvester-Rancher TLS bypass also exposed. Patch immediately.
Jun 16, 2026
WordPress RCE 9.8 unauthenticated, Microsoft Defender unpatched privesc (7.8), OpenSSL AES-OCB nonce vulnerability. Critical patches urgent—three zero-days exposed.
Jun 15, 2026
PeopleSoft takeover exploited in wild (CVE-2026-35273), Chrome 9.6 sandbox escape, Zoom mobile privesc flaw. Critical vulnerabilities—patch now.
Jun 12, 2026
MariaDB Galera CVSS 10.0 unauthenticated RCE via wsrep_notify_cmd shell injection. Plus Chrome macOS use-after-free, 389 Directory Server heap overflow, MongoDB memory leak. Critical patches urgent.