Logo
Log in
Subscribe
Logo
Oliver Buchannon
Colten A

Colten runs PatchDayAlert, a daily CVE brief for IT admins and MSPs. Built out of frustration with triaging NVD at 7am. Reads every reply.

Weekly PatchDayAlert Queue · July 1, 2026

Jul 1, 2026

•

3 min read

Weekly PatchDayAlert Queue · July 1, 2026

Developer tooling, URL parsing, libzypp repos, Chrome, Keycloak, Flowise, and a long WordPress tail.

Colten A
Colten A
Five exploited edge bugs in one week. Patch these first.

Jun 24, 2026

•

2 min read

Five exploited edge bugs in one week. Patch these first.

Ivanti Sentry, Splunk, Ubiquiti, and Cisco SD-WAN are all under active attack. The patch order, plus this week's KEV additions.

Colten A
Colten A
Firefox Sandbox Escape 8.8 + Dell RCE, 4 More Critical Vulns

Jun 18, 2026

•

5 min read

Firefox Sandbox Escape 8.8 + Dell RCE, 4 More Critical Vulns

Firefox sandbox escape (CVSS 8.8), Dell OpenManage RCE, and Pacemaker vulnerabilities disclosed. Galaxy NG command injection and Harvester-Rancher TLS bypass also exposed. Patch immediately.

Colten A
Colten A
WordPress RCE 9.8 Unauthed + Defender Privesc + OpenSSL Flaw

Jun 16, 2026

•

5 min read

WordPress RCE 9.8 Unauthed + Defender Privesc + OpenSSL Flaw

WordPress RCE 9.8 unauthenticated, Microsoft Defender unpatched privesc (7.8), OpenSSL AES-OCB nonce vulnerability. Critical patches urgent—three zero-days exposed.

Colten A
Colten A
PeopleSoft Takeover Exploited, Chrome 9.6 RCE, Zoom Privesc

Jun 15, 2026

•

5 min read

PeopleSoft Takeover Exploited, Chrome 9.6 RCE, Zoom Privesc

PeopleSoft takeover exploited in wild (CVE-2026-35273), Chrome 9.6 sandbox escape, Zoom mobile privesc flaw. Critical vulnerabilities—patch now.

Colten A
Colten A
MariaDB Galera CVSS 10.0 RCE + Chrome, MongoDB, 389 Server Vulns

Jun 12, 2026

•

5 min read

MariaDB Galera CVSS 10.0 RCE + Chrome, MongoDB, 389 Server Vulns

MariaDB Galera CVSS 10.0 unauthenticated RCE via wsrep_notify_cmd shell injection. Plus Chrome macOS use-after-free, 389 Directory Server heap overflow, MongoDB memory leak. Critical patches urgent.

Colten A
Colten A
Splunk 9.8 File-Write RCE + SQL Injection, 4 More Critical Vulns

Jun 11, 2026

•

5 min read

Splunk 9.8 File-Write RCE + SQL Injection, 4 More Critical Vulns

Splunk's 9.8 file-write vulnerability (CVE-2026-20253), SQL injection via RVTools .xlsx imports (9.6), and Apache mod_ldap use-after-free (8.6). Critical patches required—patch immediately.

Colten A
Colten A
Patch Tuesday June 2026: Ivanti Sentry scores a perfect 10, Chrome V8 bug exploited in the wild

Jun 10, 2026

•

5 min read

Patch Tuesday June 2026: Ivanti Sentry scores a perfect 10, Chrome V8 bug exploited in the wild

Ivanti Sentry CVSS 10.0 RCE, Chrome V8 exploited in the wild, HTTP.sys (9.8), Windows DHCP Client (9.8), and FortiSandbox flaws. Three CVEs actively exploited—critical patches urgent.

Colten A
Colten A
Chrome sandbox escape at 9.6, a VPN auth bypass at 9.3, and Apache httpd going down easy

Jun 9, 2026

•

5 min read

Chrome sandbox escape at 9.6, a VPN auth bypass at 9.3, and Apache httpd going down easy

Chrome sandbox escape (CVSS 9.6), VPN auth bypass (9.3), and Apache httpd DoS vulnerability exposed. Critical patches needed—plus Claude AI security governance updates.

Colten A
Colten A
SolarWinds Serv-U DoS exploited in the wild, plus a one-packet Comodo BSOD

Jun 8, 2026

•

5 min read

SolarWinds Serv-U DoS exploited in the wild, plus a one-packet Comodo BSOD

SolarWinds Serv-U DoS exploited in the wild (CVE-2026-28318), Comodo BSOD IPv6 flaw, Go MIME CPU bomb, and FRRouting BGP crashes. Critical threats actively exploited—patch now.

Colten A
Colten A
A perfect 10 in Azure HorizonDB and a Copilot RCE you shouldn't ignore

Jun 5, 2026

•

5 min read

A perfect 10 in Azure HorizonDB and a Copilot RCE you shouldn't ignore

CVE-2026-48567 is a CVSS 10.0 unauthenticated auth bypass in Azure HorizonDB. Also today: authenticated RCE in Microsoft Copilot (7.7), a Chrome sandbox escape via ImageCapture (7.5), a WordPress site-takeover in Hybrid Composer (9.8), and a DLL-loading trick in SQLite's sqldiff on Windows (9.8).

Colten A
Colten A
OpenShift ClusterRole blows wide open, Cisco UCM goes from SSRF to root

Jun 4, 2026

•

5 min read

OpenShift ClusterRole blows wide open, Cisco UCM goes from SSRF to root

OpenShift ClusterRole CVSS 9.6 privilege escalation grants authenticated users secret access. Plus Cisco UCM SSRF-to-root (8.6) and AWS IAM flaws. Critical patches urgent.

Colten A
Colten A
A 9.8 WordPress site takeover, a healthcare RCE, and two NI driver bugs

Jun 3, 2026

•

5 min read

A 9.8 WordPress site takeover, a healthcare RCE, and two NI driver bugs

ARMember Premium lets unauthenticated attackers reset any admin password (CVSS 9.8). Spacelabs Sentinel has a file-write-to-webshell path on port 8989 (CVSS 9.8). NI-PAL driver flaws give local users a privesc and a blue-screen. LibreChat lets any logged-in user hijack another user's API keys.

Colten A
Colten A
SharePoint deser RCE, OpenShift HAProxy injection, and a WordPress SQLi from 2018

Jun 2, 2026

•

5 min read

SharePoint deser RCE, OpenShift HAProxy injection, and a WordPress SQLi from 2018

CVE-2026-47294 lets any authenticated SharePoint user run code on your server (CVSS 8.0). CVE-2026-1784 turns OpenShift Route objects into HAProxy config injection (CVSS 8.8). Plus an ancient unauthenticated SQLi in WP AutoSuggest finally gets a CVE.

Colten A
Colten A
PAN-OS auth bypass exploited in the wild, plus a 9.8 in Redshift and a Chrome sandbox escape

Jun 1, 2026

•

5 min read

PAN-OS auth bypass exploited in the wild, plus a 9.8 in Redshift and a Chrome sandbox escape

Attackers are tunneling into Palo Alto firewalls without credentials (CVE-2026-0257). Also: a CVSS 9.8 RCE in Amazon's Redshift Python driver via eval(), a CVSS 9.6 Chrome WebGPU sandbox escape, and a GitHub CLI token leak.

Colten A
Colten A
UniFi OS scores a perfect 10.0 RCE, ConnectWise Automate agents can't verify their own updates

May 22, 2026

•

3 min read

UniFi OS scores a perfect 10.0 RCE, ConnectWise Automate agents can't verify their own updates

Unauthenticated command injection on UniFi OS devices, a supply-chain plugin verification bypass in ConnectWise Automate (CVSS 8.8), a privilege escalation in LiteLLM, and RCE in three ManageEngine products.

Colten A
Colten A
Cisco Secure Workload scores a perfect 10.0: unauth cross-tenant takeover

May 21, 2026

•

3 min read

Cisco Secure Workload scores a perfect 10.0: unauth cross-tenant takeover

Also: a use-after-free in Chrome's DOM engine (CVSS 8.8), a no-click heap overflow in Microsoft Defender's scan engine (CVSS 8.1), an Azure privesc via symlink, and a Splunk session cookie leak.

Colten A
Colten A
Keycloak session fixation, a DoS-in-a-packet for 389 DS, and a chroot that does nothing

May 20, 2026

•

3 min read

Keycloak session fixation, a DoS-in-a-packet for 389 DS, and a chroot that does nothing

Five fixes today: Keycloak SSO hijack (CVE-2026-7507, CVSS 7.5), 389 Directory Server DoS via oversized LDAP controls (CVE-2026-9064, CVSS 7.5), Firefox/Thunderbird privesc (CVE-2026-8970, CVSS 7.3), and two local privilege bugs in PluginScript and haveged where security checks exist but never enforce. None exploited in the wild yet.

Colten A
Colten A
Apache Thrift 9.4 RCE headlines a quiet five-patch day

May 19, 2026

•

3 min read

Apache Thrift 9.4 RCE headlines a quiet five-patch day

A critical unauthenticated bug in Thrift's Node.js server, a Linux kernel USB gadget privesc, curl SMB connection reuse, a Go panic-crash on Windows, and an FRRouting BGP daemon crasher. Nothing exploited in the wild yet.

Colten A
Colten A
PostgreSQL buffer overflow, NGINX rewrite bypass, and a Linux SMB handle hijack

May 18, 2026

•

4 min read

PostgreSQL buffer overflow, NGINX rewrite bypass, and a Linux SMB handle hijack

Three 8.1+ CVSS bugs hit core infrastructure: PostgreSQL's refint module (CVE-2026-6637, 8.8), NGINX's rewrite module (CVE-2026-42945, 8.1), and Linux ksmbd's durable handle reconnect (CVE-2026-31717, 8.8). None exploited in the wild yet, but all are network-reachable.

Colten A
Colten A
Cisco SD-WAN scores a perfect 10.0, plus dnsmasq and Go HTTP/2 DoS bugs

May 15, 2026

•

3 min read

Cisco SD-WAN scores a perfect 10.0, plus dnsmasq and Go HTTP/2 DoS bugs

CVE-2026-20182 lets unauthenticated attackers hijack your entire SD-WAN fabric through vSmart/vManage. Also on the list: a CVSS 8.4 dnsmasq bug with sparse details, a Go net/http2 infinite loop, a GnuTLS auth bypass, and a Twisted DNS crash.

Colten A
Colten A
OpenTelemetry's Azure auth extension doesn't actually check your tokens

May 14, 2026

•

3 min read

OpenTelemetry's Azure auth extension doesn't actually check your tokens

A CVSS 8.1 bypass in azureauthextension lets any valid Azure token past your OTel collector. Also: two SOGo SQL injection bugs (PostgreSQL, MariaDB), a busted IPv6 allow-list in Auth Proxy, and a Zoom Rooms installer DLL hijack on Windows.

Colten A
Colten A
Patch Tuesday May 2026: DNS and Netlogon RCEs hit 9.8, Hyper-V guest escape, plus 2 Dynamics 9.9s

May 13, 2026

•

6 min read

Patch Tuesday May 2026: DNS and Netlogon RCEs hit 9.8, Hyper-V guest escape, plus 2 Dynamics 9.9s

Two unauthenticated Windows server bugs (DNS heap overflow, Netlogon stack overflow) top the list at CVSS 9.8. A Hyper-V use-after-free scores 9.3 and likely enables guest-to-host escape. Dynamics 365 on-prem has a pair of critical RCEs (9.9 and 9.1), Azure Entra ID leaks tokens at 9.3, and FortiSandbox takes unauthenticated code execution at 9.8. Nothing exploited in the wild yet, but the DNS and Netlogon bugs won't stay quiet long.

Colten A
Colten A
A 9.9 SSRF-to-cred-theft in FireFighter's Jira bot, plus PgBouncer pre-auth overflow

May 12, 2026

•

10 min read

A 9.9 SSRF-to-cred-theft in FireFighter's Jira bot, plus PgBouncer pre-auth overflow

FireFighter's unauthenticated Jira bot endpoint hands attackers your AWS IAM creds on IMDSv1 clusters (CVE-2026-42864, CVSS 9.9). Also: a pre-auth buffer overflow in PgBouncer SCRAM handling (CVE-2026-6665, CVSS 8.1), a Go checksum bypass that poisons builds (CVE-2026-42501, CVSS 7.5), and a Linux kernel rxrpc privesc (CVE-2026-43500, CVSS 7.8).

Colten A
Colten A
Linux ksmbd RCE at 9.8, Azure Cloud Shell injection at 9.6, and a Thrift TLS bypass

May 8, 2026

•

11 min read

Linux ksmbd RCE at 9.8, Azure Cloud Shell injection at 9.6, and a Thrift TLS bypass

Two critical, no-auth bugs top the list: a use-after-free in Linux's in-kernel SMB server (CVE-2026-31718, CVSS 9.8) and command injection in Azure Cloud Shell (CVE-2026-35428, CVSS 9.6). Also covers a hostname verification skip in Apache Thrift's Java TLS transport and an info leak in Edge Copilot Chat.

Colten A
Colten A
Load more

PatchDayAlert

The 5-minute patch brief for the person who actually has to patch stuff.

© 2026 PatchDayAlert.
beehiivPowered by beehiiv