This week's burn-down
3 new fixes landed this week.
None are ransomware-linked yet, but they're worth clearing before they get there. Newest at the top.
- CVE-2026-33824Patch this week
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- CVE-2026-55040Patch this week
Microsoft SharePoint Weak Authentication Vulnerability
- CVE-2026-65400Patch this week
Apple macOS Improper Authentication Vulnerability
- CVE-2026-20349Patch this week
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Start here
What to patch first.
175 of these vulnerabilities are actively used in ransomware attacks. Start with these — they're the ones criminals are exploiting right now.
- Patch now175used in ransomware
- Patch this week183critical, or high-severity on internet-facing gear
- Plan to patch414the working backlog
- Monitor55low urgency, fix on next maintenance
Want just the ones that hit your gear? Check your stack to pick your vendors and see what's being exploited right now.
Insurance readiness
Your insurer will ask if this is patched.
Unpatched entries on CISA's Known Exploited Vulnerabilities list are exactly what cyber-insurance carrier questionnaires probe for, and knowing which controls they check is how you keep a renewal from stalling.
Get the free carrier questionnaire →Microsoft updates
One Windows Update run clears all of these.
Windows updates are cumulative: the newest one includes every fix that came before it. Run Windows Update on your machines and everything below is covered. The KB numbers are the receipts, not a to-do list.
Not sure where to start
You don't have to triage 827 vulnerabilities yourself.
We watch this list daily and tell you which ones touch the software you actually run. Free 30-minute briefing — share what you have, get a prioritized short list back, and we tell you when you don't need us.
