PatchDayAlert
01

Source-linked

Every verdict links to a primary source.

NVD, CISA KEV, MSRC, GHSA, or a vendor PSIRT. Skeptical readers can click through to verify in place.

02

Human-reviewed

A working sysadmin edits before it ships.

Issues are reviewed and edited before they go out, not auto-published from a feed. CVEs that aren’t actionable before standup don’t make the cut.

03

Editorial verdicts

One call per CVE. Four minutes total.

Patch now, patch this week, track, or doesn’t apply. These reviews are editorial and unpaid.

The four-verdict model

Every CVE gets one of these four calls.

No CVSS-jargon dump, no “threat actor postulated to leverage” sentences. You read the verdict, then the one-line action, then move on.

  1. Patch now

    Exploited in the wild, or exposed and trivially exploitable. Today’s change window.

  2. Patch this week

    Real risk, no active exploitation yet. Slot it into your next maintenance window.

  3. Track

    Worth knowing about. No action needed today; check back if the advisory changes.

  4. Doesn't apply

    Affected versions you don’t run, or a vendor branch you’ll never see. Skip with confidence.

The archive

Recent digests.

Full archive
Nº048 JUN 28

A 9.8 kernel memory corruption, a libssh2 buffer overwrite, and broken TLS in Node.js undici

batman-adv mesh networking has a remotely exploitable fragment-nesting bug (CVE-2026-52916, CVSS 9.8). libssh2 and Node.js undici also need patches, plus a Vim code execution trick and a QEMU guest escape retry.

5 CVEs
1 Crit
0 KEV
4 min
Nº047 JUN 27

KubeVirt live migration opens an unauth backdoor, plus plaintext OAuth tokens in OpenProject

A disabled-TLS footgun in KubeVirt (CVSS 8.5) lets any pod on the cluster network send raw libvirt commands to another tenant's VM. OpenProject stores SharePoint/OneDrive OAuth tokens in plaintext in Rails.cache (CVSS 8.2). Also: a GPU shader compiler OOB write, an Envoy zstd decompression bomb, and a Budibase account-linking CSRF.

5 CVEs
0 Crit
0 KEV
4 min
Nº046 JUN 26

Keycloak token forgery, KubeVirt auth bypass, and a 9.1 Perl heap read

Keycloak's JWT algorithm confusion lets attackers impersonate any federated user (CVE-2026-11800, CVSS 8.1). KubeVirt's disableTLS flag silently strips all migration auth, exposing raw libvirt RPC to the pod network (CVE-2026-13325, CVSS 8.5). Apicurio Registry has two SSRF bugs, and Perl's Socket module has a 9.1 heap read with near-zero exploit probability.

5 CVEs
1 Crit
0 KEV
4 min
Nº045 JUN 25

Flowise leaks your OAuth secrets unauthenticated, n8n hides SQL injection in column names

5 CVEs today. Flowise exposes SSO client secrets (including Azure and GitHub) to any anonymous GET request (CVSS 7.5). n8n's database nodes let authenticated users inject SQL through table and column identifiers (CVSS 8.2). Also: a Keras path traversal at CVSS 8.1, a Warp terminal command injection under WSL, and a Linux kernel nftables offset bug.

5 CVEs
0 Crit
0 KEV
4 min

Get the cheat sheet and the digest

CVE triage for sysadmins in five minutes.

What to patch now. What can wait. What you can ignore.

  1. 01 The CVE triage cheat sheet, a one-page printable decision tree, in the welcome email.
  2. 02 The weekly digest, one email every Wednesday, around four minutes to read.

Free. Unsubscribe anytime.