This week's burn-down
10 fixes worth doing right now.
8 of these are being used in ransomware attacks as we speak, so they jump the line. Handle those first, then work down the rest. Newest at the top.
- CVE-2026-71362Patch second
Adobe Commerce and Magento Incorrect Authorization Vulnerability
- CVE-2026-76460Patch second
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Start here
What to patch first.
180 of these vulnerabilities are actively used in ransomware attacks. Start with these — they're the ones criminals are exploiting right now.
- Patch first180used in ransomware
- Patch second190critical, or high-severity on internet-facing gear
- Patch third417high-severity, or on internet-facing gear
- Patch fourth55everything else on the list
Every entry here is on CISA's Known Exploited Vulnerabilities list, and CISA's current directive, BOD 26-04, gives federal agencies 3 or 14 days to fix a listed vulnerability.
Treat all four groups as due inside that window and work through them in this order; a later place in the order is not permission to wait.
The order comes from CVSS severity and our guess at internet exposure from the kind of product. Neither is how CISA sets its deadlines: the directive looks at:
- Whether your system is actually reachable from the internet
- Whether the attack can be automated
- How much control it gives an attacker
Want just the ones that hit your gear? Check your stack to pick your vendors and see what's being exploited right now.
Insurance readiness
Your insurer will ask if this is patched.
Not sure where to start
You don't have to triage 842 vulnerabilities yourself.
We watch this list daily and tell you which ones touch the software you actually run. Free 30-minute briefing — share what you have, get a prioritized short list back, and we tell you when you don't need us.
