Microsoft fixed 751 CVEs across 67 updates in August 2026, 108 rated Critical, and one is already being exploited. What to patch first, and why.
Adobe ColdFusion path traversal CVE-2026-48282, CVSS 10 and CISA KEV listed, has EPSS 0.99. Plus SharePoint, Exchange, and a Zimbra campaign to check.
Microsoft SharePoint RCE CVE-2026-50522 (CVSS 9.8) is on the CISA KEV list alongside Adobe ColdFusion CVE-2026-48282 and two Exchange flaws. Patch these first.
Russian actors are exploiting an unpatched Zimbra zero-day against US and Ukraine targets while Adobe ColdFusion CVE-2026-48282 sits on CISA KEV at CVSS 10.
CISA added Check Point SmartConsole flaw CVE-2026-16232 (CVSS 9.1) to KEV after in-the-wild exploitation, alongside a SharePoint deserialization bug.
CISA added two WordPress Core flaws (CVE-2026-63030, CVE-2026-60137) to KEV on July 21 as wp2shell attacks install webshells.
Run 650+ Microsoft 365, Intune, Defender, Entra ID, and Purview security checks against a free demo tenant, no cost, no agents.
Get startedPatching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.
Deep security commentary and research notes on Microsoft 365, Intune, Defender, Entra ID (logs included), patch state, CVEs, and Purview, plus behind-the-scenes posts on Senserva Trustworthy AI. Longer articles live on Substack: Senserva on Substack and Mark Shavlik's Substack.