Join Senserva Watch
Free, and the alerts start right away. One email when something you follow changes, and the Patch Tuesday wire on release day.
Free. Unsubscribe by replying to any Watch message; your email is never sold or shared. By joining you agree to the EULA and privacy policy. No tenant data is collected by this form.
Senserva Watch: free Patch Tuesday, CISA KEV and CVE alerts by email
We follow your CVEs and patches, and the security news around them, so you do not have to. One email when something you watch changes, the Patch Tuesday wire on release day, and a note when a CVE you follow enters the CISA Known Exploited Vulnerabilities catalog. On a quiet week we send nothing.
Behind it is one of the largest free Microsoft security destinations on the web: the live Microsoft patch tracker, the exploited-CVE tracker, the hot ranking, the Patch Tuesday page, and more than 10,000 per-CVE and per-KB reference pages, refreshed twice a day from MSRC, NVD, CISA KEV and FIRST EPSS. Every alert we have ever sent is printed below, so you can judge the emails before you hand over your address.
Every alert we have sent
Judge the emails before you hand over your address. This is the full log of the mass alerts Senserva Watch has emailed members, added as each one goes out: the date, the CVEs and KBs it covered, and the exact text. What was sent, never to whom. We email when something actually moved, a KEV add, a critical security update, a revision to a CVE we cover, or Patch Tuesday, and on a quiet week we send nothing. The newest alert stays with members until the next one ships. The log also lives at every Watch alert we have sent and as a free JSON feed at api/watch-alerts.json.
BleepingComputer reports on 2026-09-16: "Google fixes actively exploited Android zero-day on Pixel devices".
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
It only matters if you manage the product named; if you do not, there is nothing to do here of course.
- CVE-2026-62721 KB5129195
** Not News, but FYI **
KB5129195 is an out-of-band update for Windows 11, released 2026-09-14 (26200.9457).
Microsoft ships an update outside the monthly cycle only when a fix cannot wait, so treat it as one to deploy this week rather than next month. It carries fixes for 1 CVE: CVE-2026-62721.
Microsoft lists a known issue on it: "USB Audio Class 1.0 devices with error Code 10 or no output".
Read the known-issues section before a wide rollout, and check whether a later update resolves it. Our page carries the builds it applies to, Microsoft's known-issues text, the CVEs it fixes and a PowerShell check for whether it is installed: https://senserva.com/kb/5129195.html Microsoft's article:
- CVE-2026-85046
** Not News, but important FYI **
Chromium: CVE-2026-85046 Type confusion in V8 (CVE-2026-85046) is the CVE to watch right now.
The Microsoft Chromium V8 flaw is rated High with a CVSS score of 8.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-04, which means it is being attacked in the wild, not just in theory.
If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-85046.html
- CVE-2026-81963 CVE-2026-85880 CVE-2024-43451 CVE-2024-49039 CVE-2026-75650 CVE-2026-86218 KB5122878 KB5124008 KB5122880 KB5046615
Microsoft's September 2026 Patch Tuesday shipped today: 1,169 CVEs across 60 updates, 118 rated Critical, and two Windows zero-days that CISA added to the KEV list the same day.
PATCH THESE FIRST, EVERYWHERE
- CVE-2026-81963, Windows Update Stack, elevation of privilege, CVSS 7.8, exploitation detected, on CISA KEV.
- CVE-2026-85880, Windows Advanced Local Procedure Call (ALPC), elevation of privilege, CVSS 7.8, exploitation detected, on CISA KEV.
Both landed on the KEV list on release day, which is faster than the usual few days. Federal agencies have until September 22. Everyone else should treat that as the deadline too.
Both are local: the machines people log into come first. The fixes ride in this month's cumulative updates. Each CVE page lists every update carrying it, by Windows version:
https://senserva.com/cve/CVE-2026-81963.html
https://senserva.com/cve/CVE-2026-85880.htmlTODAY'S 60 UPDATES, BY FAMILY
- Windows 10, Windows 11 and Windows Server cumulative updates, including KB5122878 (Windows 10 / Server 2019), KB5124008 and KB5122880 (Windows 11).
- 18 .NET updates, 10 SQL Server updates, 14 Office and SharePoint updates, and 8 others.
Also this month: CVSS 10.0 entries in Azure AI Language and Azure AD B2C, a 9.9 in Entra ID, and a 9.8 remote code execution in Skype for Business Server.
Every update, worst first: https://senserva.com/patch-tuesday-2026-09.html#updatesHOT KBs RIGHT NOW
The hottest Microsoft updates on the Senserva Ranking today are still the November 2024 cumulative updates, KB5046615 and its siblings for Windows 10 1809, Server 2019 and Server 2022: two of their CVEs (CVE-2024-43451, CVE-2024-49039) are on the CISA KEV list with ransomware use, CVSS 9.8, EPSS 0.84, and they are what people are searching for this week. Any machine on those builds that never took them is exposed today; this month's cumulative update carries the same fixes.
The full list: https://senserva.com/whats-hot-cve-kb.htmlThe same CISA alert also added CVE-2026-75650 in Adobe Commerce and Magento, and CVE-2026-86218 in N-able N-central. Not Microsoft, but if you run either, they belong in this week's queue.
The release, ranked by risk: https://senserva.com/patch-tuesday.html
The write-up: https://senserva.com/blog/september-2026-patch-tuesday - CVE-2026-82329 CVE-2026-66384
CISA added CVE-2026-82329 to the Known Exploited Vulnerabilities catalog on
2026-09-02 and gave federal agencies until 2026-09-05 to remediate it. Three
days again, and for the same reason: exploitation is confirmed in the wild, not
predicted. JFrog shipped the patch on August 28. Attackers were on it by
September 1.The flaw is in JFrog Artifactory, the artifact repository that holds your
binaries, containers, packages, and models. Senserva records a CVSS score of
9.8, the v3.1 base score from the National Vulnerability Database. No
v4 score has been published. Earlier this week FIRST still had the 30 day exploitation
probability under half a percent, which is the one signal here pointing the
other way. While a predictive score is useful, the confirmed exploitation bumps
up the priority.Two things make it worse than a normal authentication bug. It is the default
configuration that is vulnerable, so there is no misconfiguration to point at
and no hardening step anyone skipped. Artifactory is a control plane, not an
application. Administrative access there reaches repository configuration, the
identities and tokens stored alongside it, and the distribution paths that feed
your build and production systems.What attackers actually did matters for your response. WatchTowr observed them
minting administrator tokens, then enumerating users, groups, credential sets,
and federated access relationships. In a smaller number of cases they created
backdoor users. That is persistence that survives the patch, so make sure to
audit as well after applying the update.What to do this week. Upgrade self-hosted Artifactory to 7.161.20, 7.146.38,
7.133.29, 7.125.20, 7.117.28, or 7.111.21, whichever matches your branch. JFrog
has already patched cloud instances, so this is a self-managed problem. Then
assess, because patching alone does not close it: review the admin user list for
accounts nobody created, audit access tokens and revoke ones you cannot account
for, and rotate the credentials and integration secrets that Artifactory held.
Check your CI/CD service accounts and any federated trust Artifactory brokers to
other systems. If the upgrade has to wait for a change window, take the instance
off any network path that does not need it.Worth noting that this is the second Artifactory entry in KEV in a week.
CVE-2026-66384 was added on August 27. If you are only tracking one, you are
tracking half the problem.The full record, with every change we have tracked since it was listed:
https://senserva.com/cve/CVE-2026-82329.htmlEverything CISA has added beyond Microsoft this month:
https://senserva.com/non-microsoft-cve-tracker.html Siemserva by Senserva now includes a browser-based Interactive UI. Download the latest release and work with your results in the browser: every missing patch ranked by real attacks, all 600+ security checks across Microsoft 365, Intune, Defender, and Entra ID, and full reports. Setup takes minutes, and your data stays local, in a results database only you hold.
The download is open to everyone, so pass it along: anyone can install Siemserva and explore the Interactive UI on the built-in demo data, no key needed.
As a Senserva Watch member, you get more. Your personalized key unlocks your Three Free Unlimited Audits of your own tenant: one to Find it, one to Fix it, one to Prove it. All users, all settings, all patches, all tenants, no time limit. Each audit includes the complete Senserva MCP server for Claude, so you can ask your own questions of the results. Included in this message is a reminder of your personalized key.
Direct downloads:
Windows (x64), signed executable:
Windows (x64), ZIP:
macOS (Apple Silicon):
Latest release:
Thank you for being part of Senserva Watch,
The Senserva team- CVE-2026-8452 CVE-2026-8451 CVE-2026-19490
CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on
2026-08-26 and gave federal agencies until 2026-08-29 to remediate it. Three
days again, and the same reason as last time: exploitation is confirmed, not
predicted.The flaw is in Citrix NetScaler ADC and NetScaler Gateway, the appliances that
terminate SSL VPN, ICA proxy, clientless VPN, and RDP proxy sessions at the
edge. Senserva records a CVSS score of 8.8, the version 4 base score Citrix
assigned in advisory CTX696604 on June 30. Credit for the original report goes
to Michael Tucker of the JPMorgan Chase XOR team.Read the vendor description carefully, because it is the weak point in this one.
Citrix calls it a memory overflow leading to unpredictable or erroneous behavior
and denial of service, and CISA's KEV entry repeats the denial of service
framing. watchTowr Labs published the root cause and carried the same bug
through to a webshell. Bishop Fox reproduced the memory corruption in a lab on a
build the public proof of concept was not written for. Scoping your response to
the vendor's wording would understate this.The mechanism is worth one sentence because it explains the scoping. Before
NetScaler verifies the signature on an inbound SAML message, it first rewrites
the signed content into canonical form, and one attacker-supplied field in that
step, the PrefixList, gets copied into a fixed-size buffer without a length
check. The rewrite happens before any authentication, so a single unsigned
POST from a stranger reaches the vulnerable code.That means the unit of work is the virtual server, not the appliance. Citrix
names Gateway and AAA virtual servers without mentioning SAML, but Bishop Fox
found the vulnerable endpoints exist only where SAML is actually configured and
a policy is attached. An appliance with three virtual servers can be vulnerable
on one and unreachable on the other two. Standby HA nodes count, since an
unpatched secondary is fully exposed the moment it takes over.Senserva Watch leans Microsoft. This one is not, and it is in your inbox because
exploitation is confirmed and the clock is three days.What to do this week. Upgrade to at least 13.1-63.18 or 14.1-72.61, which are
the minimum builds carrying the fix, and go past them to the latest on your
branch. FIPS and NDcPP fleets run their own cadence: 14.1-72.61 FIPS, or
13.1-37.272 for 13.1-FIPS and 13.1-NDcPP. Nothing is coming for 12.1 or 13.0, so
those need migration rather than patching. Inventory with
"show ns runningConfig | grep -i saml" to find where SAML policies are actually
bound, then confirm the installed build with "show ns version" on active and
standby nodes both.Then assess, because the patch does not tell you whether someone already came
through. Look for unexpected files under /var/vpn/theme/, nsppe crashes in
ns.log with pitboss reporting the process died, and fresh NSPPE-* core files
under /var/core. One correction to the intuition here: a reboot does not
distinguish a failed attempt from a successful one, so triage on what is in the
file system.While you have the inventory open, two siblings share the same exposure.
CVE-2026-8451 is a memory disclosure bug in the same SAML feature and is also
under active exploitation. CVE-2026-19490, from the August 19 bulletin, is a
different bug that needs the same SAML configuration on current builds. One pass
covers all three.The full record, with every change we have tracked since it was listed:
https://senserva.com/cve/CVE-2026-8452.htmlEverything CISA has added beyond Microsoft this month:
https://senserva.com/non-microsoft-cve-tracker.html - CVE-2026-55040
Microsoft SharePoint Server Security Feature Bypass Vulnerability (CVE-2026-55040) is the CVE to watch right now. The Microsoft SharePoint flaw is rated Critical with a CVSS score of 9.1. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18, which means it is being attacked in the wild, not just in theory. Rapid7 covered it on 2026-08-11: "Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)".
If it is in your environment, patch it now.
Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-55040.html
- CVE-2025-62593
CISA added CVE-2025-62593 to the Known Exploited Vulnerabilities catalog on
2026-08-17 and gave federal agencies until 2026-08-20 to remediate it. Three
days is unusually short, and that is the part to read: exploitation is
confirmed in the wild, not predicted.The flaw is in Ray, the open source framework used to scale AI and machine
learning workloads. Senserva records a CVSS score of 8.8, the version 3.1 base
score from the National Vulnerability Database. The assigning authority also
published a version 4 score of 9.4, so an advisory quoting the higher number is
describing the same flaw on a newer rubric. FIRST puts the 30 day exploitation
probability near 1 percent, which is the one signal here pointing the other way.
When a confirmed exploitation source and a predictive score disagree, the
confirmed source wins.Senserva Watch leans Microsoft. This one is not, and it is in your inbox because
exploitation is confirmed and the clock is three days.Two things make it different from the usual Ray exposure story. It reaches Ray
instances that were never exposed to the internet, by way of a developer's own
browser, so firewall rules and network segmentation do not stop it. And the
machines most at risk are workstations and laptops running Ray locally, not only
clusters.What to do this week. Upgrade Ray to 2.52.0 or later everywhere it runs, and
inventory by package rather than by host role: pip and conda environments,
container images, notebook kernels, continuous integration runners, and
developer laptops. Turn on the token authentication that 2.52.0 introduced,
because it ships off by default. Then assess: on any machine that ran an earlier
version, review Ray job submission history for entries nobody recognizes, and
rotate the credentials that were reachable from those environments. If the
upgrade has to wait for a change window, separate the two halves of the attack
and do not run Ray and a web browser on the same machine.The full record, with every change we have tracked since it was listed:
https://senserva.com/cve/CVE-2025-62593.htmlEverything CISA has added beyond Microsoft this month:
https://senserva.com/non-microsoft-cve-tracker.html - CVE-2026-58231 CVE-2026-34480 CVE-2026-5598
August 2026
SAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.
CVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.
The fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.
THREE DAYS
SAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.
Be precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.
THE EXPOSURE
Shadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.
What makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.
THE REST OF THE RELEASE
A 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.
Onapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.
THREE THINGS THIS WEEK
Determine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.
Include everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.
Patch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.If patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.
WHERE THESE NUMBERS COME FROM
Severity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis.
Track it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html
- CVE-2026-58231 CVE-2026-34480 CVE-2026-5598
August 2026
SAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.
CVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.
The fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.
THREE DAYS
SAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.
Be precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.
THE EXPOSURE
Shadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.
What makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.
THE REST OF THE RELEASE
A 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.
Onapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.
THREE THINGS THIS WEEK
Determine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.
Include everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.
Patch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.If patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.
WHERE THESE NUMBERS COME FROM
Severity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis.
Track it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html
- CVE-2026-58231 CVE-2026-34480 CVE-2026-5598
August 2026
SAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.
CVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.
The fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.
THREE DAYS
SAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.
Be precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.
THE EXPOSURE
Shadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.
What makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.
THE REST OF THE RELEASE
A 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.
Onapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.
THREE THINGS THIS WEEK
Determine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.
Include everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.
Patch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.If patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.
WHERE THESE NUMBERS COME FROM
Severity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis.
Track it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html
The 41 alerts sent so far, newest first; the 12 most recent are printed here and the full table loads above them.
What membership is worth
Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.
One email address. No tenant connection, no agent, no call.
- The audits
- Senserva Watch members start with Three Free Unlimited Audits and earn a fresh audit credit every quarter: one full run of everything Siemserva does, all users, all settings, all patches, all tenants. Each audit comes with the complete Senserva MCP server for Claude, so you can ask your own questions of the results, and with validated AI remediation that proposes the fix for what it finds and shows its working.
- A standing discount
- Members also get 20% off when they buy. Membership is free and stays free; the discount is there because members are the people who already know what we do.
- The alerts
- Patch and security alerts on what you follow, the Patch Tuesday wire on release day, and a message when something you track enters the CISA Known Exploited Vulnerabilities catalog, which is the change that actually alters your priorities.
- The patch scanner beta
- Membership includes the beta of the new patch scanner from Mark Shavlik, 25 years after he created HfNetChk, when it becomes available. It goes after the hard ones: the missing updates Intune and the other tools do not find. Local patching comes first, then the rest of the Senserva Watcher family as each one ships, the GitHub and Azure auditors among them, members first in line. Read the Shavlik story for where it comes from.
- Watch any CVE or KB
- Follow the updates and vulnerabilities that matter to your environment; we record what moved and when, and tell you when it does.
- Exports and a member API key
- Bulk exports and programmatic access to the member endpoints, as they roll out.
- Coming
- A family of Senserva Watcher applications is coming: the same tracked data working inside the tools you already run. Members are first in line, and get the applications free.
How it works
Drop your email
Just your email, on this page or on any CVE or KB page you are already reading. Nothing else to fill in.
Get today's read instantly
The moment you join, you see the current Senserva read: what changed today across Microsoft patches, exploited CVEs, and CISA KEV, written fresh every day.
Then we watch for you
The Patch Tuesday wire at the next release, member updates as benefits ship, and change alerts for your watched CVEs and KBs as alerting rolls out.
The data behind membership is the same data on the site: MSRC, NVD, CISA KEV, and FIRST EPSS, refreshed twice a day, with every source credited on data sources and thanks.
Questions people ask before joining
How often will Senserva Watch email me?
Only when something actually moved: a CVE you follow enters the CISA Known Exploited Vulnerabilities catalog, a Critical security update lands, Microsoft ships an out-of-band update, or Patch Tuesday releases. On a quiet week we send nothing, and the log above is the record.
What is the Patch Tuesday wire?
Microsoft publishes its monthly security updates on the second Tuesday of each month. On release day members get one email with the counts, the Critical updates, any zero-days, and links to our per-KB and per-CVE pages. The Patch Tuesday page carries the current month and the next date.
Where does the data come from?
MSRC, NVD, CISA KEV and FIRST EPSS, refreshed twice a day, plus coverage from a fixed list of trusted outlets. Every source is credited on data sources and thanks, and every alert links the page the facts came from.
Does it cover products other than Microsoft?
Alerts lead with Microsoft, because members run Microsoft 365, Intune, Defender, and Entra ID. A non-Microsoft bug earns an email when it is actively exploited and widely run, and it is written as "only if you run this", kept short.
What does it cost, and how do I leave?
Nothing. Membership is free and stays free. Unsubscribe by replying to any Watch message. Your email is never sold or shared, and no tenant data is collected by joining.
Do members see more on the site?
No. Today membership changes what arrives by email and the audit credits you hold; nothing on a page differs for a member. The trackers, the rankings and the reference pages stay free for everyone.