Join Senserva Watch

Free, and the alerts start right away. One email when something you follow changes, and the Patch Tuesday wire on release day.

Free. Unsubscribe by replying to any Watch message; your email is never sold or shared. By joining you agree to the EULA and privacy policy. No tenant data is collected by this form.

Senserva Watch: free Patch Tuesday, CISA KEV and CVE alerts by email

We follow your CVEs and patches, and the security news around them, so you do not have to. One email when something you watch changes, the Patch Tuesday wire on release day, and a note when a CVE you follow enters the CISA Known Exploited Vulnerabilities catalog. On a quiet week we send nothing.

Behind it is one of the largest free Microsoft security destinations on the web: the live Microsoft patch tracker, the exploited-CVE tracker, the hot ranking, the Patch Tuesday page, and more than 10,000 per-CVE and per-KB reference pages, refreshed twice a day from MSRC, NVD, CISA KEV and FIRST EPSS. Every alert we have ever sent is printed below, so you can judge the emails before you hand over your address.

Every alert we have sent

Judge the emails before you hand over your address. This is the full log of the mass alerts Senserva Watch has emailed members, added as each one goes out: the date, the CVEs and KBs it covered, and the exact text. What was sent, never to whom. We email when something actually moved, a KEV add, a critical security update, a revision to a CVE we cover, or Patch Tuesday, and on a quiet week we send nothing. The newest alert stays with members until the next one ships. The log also lives at every Watch alert we have sent and as a free JSON feed at api/watch-alerts.json.

  1. KB5124008 KB5129195

    KB5124008: Windows 11 domain sign-ins failing — Microsoft's workaround

    CyberSecurityNews reports that domain-joined machines are failing to sign in after KB5124008: correct credentials rejected, Test-ComputerSecureChannel returning False, and machine-account failures logged on the domain controller.

    Microsoft documents this one. Its known-issues text says Credential Guard protected machine accounts can lose their secure channel with on-premises Active Directory, and it gives a workaround: disable Machine Identity Isolation the same way you enabled it, restart, then run Test-ComputerSecureChannel -Repair. The report adds that the September 14 out-of-band update, KB5129195, does not address it.

    One correction, ours. KB5124008 is the September 8 update for Windows 11 24H2 and 25H2, builds 26100.9445 and 26200.9445. Our own page for it currently says Windows Server 2019, and that is our error, not Microsoft's — we are fixing the page. Check Windows 11 fleets, not your 2019 servers.

    If you turned Machine Identity Isolation on, check that first.

    Our page, with Microsoft's full text: https://senserva.com/kb/5124008.html
    The report:

  2. KB5002914

    KB5002914 is a security update, released 2026-09-08. It carries fixes for 31 CVEs.

    Microsoft lists a known issue on it: "In Microsoft Excel 2024, 2021, 2019, and 2016, the paste operation might fail silently. Although users try to paste content, the source remains selected and the destination is unmodified.

    When this issue occurs, users receive no indication of the failure, such as a beep or error message.". Read the known-issues section before a wide rollout, and check whether a later update resolves it.

    You need to make the final call, but there are a number of issues that patch fixes so please be sure to consider that in your process. Breaking cut and paste for those that depend it is an issue to consider as well. One choice is to notify users of the possible issue and then push the patch. Tell them why the security risk must be addressed.

    Our page carries the builds it applies to, Microsoft's known-issues text, the CVEs it fixes and a PowerShell check for whether it is installed. https://senserva.com/kb/5002914.html

    Microsoft's article:

  3. BleepingComputer reports on 2026-09-16: "Google fixes actively exploited Android zero-day on Pixel devices".

    Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.

    It only matters if you manage the product named; if you do not, there is nothing to do here of course.

  4. CVE-2026-62721 KB5129195

    ** Not News, but FYI **

    KB5129195 is an out-of-band update for Windows 11, released 2026-09-14 (26200.9457).

    Microsoft ships an update outside the monthly cycle only when a fix cannot wait, so treat it as one to deploy this week rather than next month. It carries fixes for 1 CVE: CVE-2026-62721.

    Microsoft lists a known issue on it: "USB Audio Class 1.0 devices with error Code 10 or no output".

    Read the known-issues section before a wide rollout, and check whether a later update resolves it. Our page carries the builds it applies to, Microsoft's known-issues text, the CVEs it fixes and a PowerShell check for whether it is installed: https://senserva.com/kb/5129195.html Microsoft's article:

  5. CVE-2026-85046

    ** Not News, but important FYI **

    Chromium: CVE-2026-85046 Type confusion in V8 (CVE-2026-85046) is the CVE to watch right now.

    The Microsoft Chromium V8 flaw is rated High with a CVSS score of 8.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-04, which means it is being attacked in the wild, not just in theory.

    If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-85046.html

  6. CVE-2026-81963 CVE-2026-85880 CVE-2024-43451 CVE-2024-49039 CVE-2026-75650 CVE-2026-86218 KB5122878 KB5124008 KB5122880 KB5046615

    Microsoft's September 2026 Patch Tuesday shipped today: 1,169 CVEs across 60 updates, 118 rated Critical, and two Windows zero-days that CISA added to the KEV list the same day.

    PATCH THESE FIRST, EVERYWHERE
    - CVE-2026-81963, Windows Update Stack, elevation of privilege, CVSS 7.8, exploitation detected, on CISA KEV.
    - CVE-2026-85880, Windows Advanced Local Procedure Call (ALPC), elevation of privilege, CVSS 7.8, exploitation detected, on CISA KEV.
    Both landed on the KEV list on release day, which is faster than the usual few days. Federal agencies have until September 22. Everyone else should treat that as the deadline too.
    Both are local: the machines people log into come first. The fixes ride in this month's cumulative updates. Each CVE page lists every update carrying it, by Windows version:
    https://senserva.com/cve/CVE-2026-81963.html
    https://senserva.com/cve/CVE-2026-85880.html

    TODAY'S 60 UPDATES, BY FAMILY
    - Windows 10, Windows 11 and Windows Server cumulative updates, including KB5122878 (Windows 10 / Server 2019), KB5124008 and KB5122880 (Windows 11).
    - 18 .NET updates, 10 SQL Server updates, 14 Office and SharePoint updates, and 8 others.
    Also this month: CVSS 10.0 entries in Azure AI Language and Azure AD B2C, a 9.9 in Entra ID, and a 9.8 remote code execution in Skype for Business Server.
    Every update, worst first: https://senserva.com/patch-tuesday-2026-09.html#updates

    HOT KBs RIGHT NOW
    The hottest Microsoft updates on the Senserva Ranking today are still the November 2024 cumulative updates, KB5046615 and its siblings for Windows 10 1809, Server 2019 and Server 2022: two of their CVEs (CVE-2024-43451, CVE-2024-49039) are on the CISA KEV list with ransomware use, CVSS 9.8, EPSS 0.84, and they are what people are searching for this week. Any machine on those builds that never took them is exposed today; this month's cumulative update carries the same fixes.
    The full list: https://senserva.com/whats-hot-cve-kb.html

    The same CISA alert also added CVE-2026-75650 in Adobe Commerce and Magento, and CVE-2026-86218 in N-able N-central. Not Microsoft, but if you run either, they belong in this week's queue.

    The release, ranked by risk: https://senserva.com/patch-tuesday.html
    The write-up: https://senserva.com/blog/september-2026-patch-tuesday

  7. CVE-2026-82329 CVE-2026-66384

    CISA added CVE-2026-82329 to the Known Exploited Vulnerabilities catalog on
    2026-09-02 and gave federal agencies until 2026-09-05 to remediate it. Three
    days again, and for the same reason: exploitation is confirmed in the wild, not
    predicted. JFrog shipped the patch on August 28. Attackers were on it by
    September 1.

    The flaw is in JFrog Artifactory, the artifact repository that holds your
    binaries, containers, packages, and models. Senserva records a CVSS score of
    9.8, the v3.1 base score from the National Vulnerability Database. No
    v4 score has been published. Earlier this week FIRST still had the 30 day exploitation
    probability under half a percent, which is the one signal here pointing the
    other way. While a predictive score is useful, the confirmed exploitation bumps
    up the priority.

    Two things make it worse than a normal authentication bug. It is the default
    configuration that is vulnerable, so there is no misconfiguration to point at
    and no hardening step anyone skipped. Artifactory is a control plane, not an
    application. Administrative access there reaches repository configuration, the
    identities and tokens stored alongside it, and the distribution paths that feed
    your build and production systems.

    What attackers actually did matters for your response. WatchTowr observed them
    minting administrator tokens, then enumerating users, groups, credential sets,
    and federated access relationships. In a smaller number of cases they created
    backdoor users. That is persistence that survives the patch, so make sure to
    audit as well after applying the update.

    What to do this week. Upgrade self-hosted Artifactory to 7.161.20, 7.146.38,
    7.133.29, 7.125.20, 7.117.28, or 7.111.21, whichever matches your branch. JFrog
    has already patched cloud instances, so this is a self-managed problem. Then
    assess, because patching alone does not close it: review the admin user list for
    accounts nobody created, audit access tokens and revoke ones you cannot account
    for, and rotate the credentials and integration secrets that Artifactory held.
    Check your CI/CD service accounts and any federated trust Artifactory brokers to
    other systems. If the upgrade has to wait for a change window, take the instance
    off any network path that does not need it.

    Worth noting that this is the second Artifactory entry in KEV in a week.
    CVE-2026-66384 was added on August 27. If you are only tracking one, you are
    tracking half the problem.

    The full record, with every change we have tracked since it was listed:
    https://senserva.com/cve/CVE-2026-82329.html

    Everything CISA has added beyond Microsoft this month:
    https://senserva.com/non-microsoft-cve-tracker.html

  8. Siemserva by Senserva now includes a browser-based Interactive UI. Download the latest release and work with your results in the browser: every missing patch ranked by real attacks, all 600+ security checks across Microsoft 365, Intune, Defender, and Entra ID, and full reports. Setup takes minutes, and your data stays local, in a results database only you hold.

    The download is open to everyone, so pass it along: anyone can install Siemserva and explore the Interactive UI on the built-in demo data, no key needed.

    As a Senserva Watch member, you get more. Your personalized key unlocks your Three Free Unlimited Audits of your own tenant: one to Find it, one to Fix it, one to Prove it. All users, all settings, all patches, all tenants, no time limit. Each audit includes the complete Senserva MCP server for Claude, so you can ask your own questions of the results. Included in this message is a reminder of your personalized key.

    Direct downloads:

    Windows (x64), signed executable:

    Windows (x64), ZIP:

    macOS (Apple Silicon):

    Latest release:

    Thank you for being part of Senserva Watch,
    The Senserva team

  9. CVE-2026-8452 CVE-2026-8451 CVE-2026-19490

    CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on
    2026-08-26 and gave federal agencies until 2026-08-29 to remediate it. Three
    days again, and the same reason as last time: exploitation is confirmed, not
    predicted.

    The flaw is in Citrix NetScaler ADC and NetScaler Gateway, the appliances that
    terminate SSL VPN, ICA proxy, clientless VPN, and RDP proxy sessions at the
    edge. Senserva records a CVSS score of 8.8, the version 4 base score Citrix
    assigned in advisory CTX696604 on June 30. Credit for the original report goes
    to Michael Tucker of the JPMorgan Chase XOR team.

    Read the vendor description carefully, because it is the weak point in this one.
    Citrix calls it a memory overflow leading to unpredictable or erroneous behavior
    and denial of service, and CISA's KEV entry repeats the denial of service
    framing. watchTowr Labs published the root cause and carried the same bug
    through to a webshell. Bishop Fox reproduced the memory corruption in a lab on a
    build the public proof of concept was not written for. Scoping your response to
    the vendor's wording would understate this.

    The mechanism is worth one sentence because it explains the scoping. Before
    NetScaler verifies the signature on an inbound SAML message, it first rewrites
    the signed content into canonical form, and one attacker-supplied field in that
    step, the PrefixList, gets copied into a fixed-size buffer without a length
    check. The rewrite happens before any authentication, so a single unsigned
    POST from a stranger reaches the vulnerable code.

    That means the unit of work is the virtual server, not the appliance. Citrix
    names Gateway and AAA virtual servers without mentioning SAML, but Bishop Fox
    found the vulnerable endpoints exist only where SAML is actually configured and
    a policy is attached. An appliance with three virtual servers can be vulnerable
    on one and unreachable on the other two. Standby HA nodes count, since an
    unpatched secondary is fully exposed the moment it takes over.

    Senserva Watch leans Microsoft. This one is not, and it is in your inbox because
    exploitation is confirmed and the clock is three days.

    What to do this week. Upgrade to at least 13.1-63.18 or 14.1-72.61, which are
    the minimum builds carrying the fix, and go past them to the latest on your
    branch. FIPS and NDcPP fleets run their own cadence: 14.1-72.61 FIPS, or
    13.1-37.272 for 13.1-FIPS and 13.1-NDcPP. Nothing is coming for 12.1 or 13.0, so
    those need migration rather than patching. Inventory with
    "show ns runningConfig | grep -i saml" to find where SAML policies are actually
    bound, then confirm the installed build with "show ns version" on active and
    standby nodes both.

    Then assess, because the patch does not tell you whether someone already came
    through. Look for unexpected files under /var/vpn/theme/, nsppe crashes in
    ns.log with pitboss reporting the process died, and fresh NSPPE-* core files
    under /var/core. One correction to the intuition here: a reboot does not
    distinguish a failed attempt from a successful one, so triage on what is in the
    file system.

    While you have the inventory open, two siblings share the same exposure.
    CVE-2026-8451 is a memory disclosure bug in the same SAML feature and is also
    under active exploitation. CVE-2026-19490, from the August 19 bulletin, is a
    different bug that needs the same SAML configuration on current builds. One pass
    covers all three.

    The full record, with every change we have tracked since it was listed:
    https://senserva.com/cve/CVE-2026-8452.html

    Everything CISA has added beyond Microsoft this month:
    https://senserva.com/non-microsoft-cve-tracker.html

  10. CVE-2026-55040

    Microsoft SharePoint Server Security Feature Bypass Vulnerability (CVE-2026-55040) is the CVE to watch right now. The Microsoft SharePoint flaw is rated Critical with a CVSS score of 9.1. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18, which means it is being attacked in the wild, not just in theory. Rapid7 covered it on 2026-08-11: "Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)".

    If it is in your environment, patch it now.

    Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-55040.html

  11. CVE-2025-62593

    CISA added CVE-2025-62593 to the Known Exploited Vulnerabilities catalog on
    2026-08-17 and gave federal agencies until 2026-08-20 to remediate it. Three
    days is unusually short, and that is the part to read: exploitation is
    confirmed in the wild, not predicted.

    The flaw is in Ray, the open source framework used to scale AI and machine
    learning workloads. Senserva records a CVSS score of 8.8, the version 3.1 base
    score from the National Vulnerability Database. The assigning authority also
    published a version 4 score of 9.4, so an advisory quoting the higher number is
    describing the same flaw on a newer rubric. FIRST puts the 30 day exploitation
    probability near 1 percent, which is the one signal here pointing the other way.
    When a confirmed exploitation source and a predictive score disagree, the
    confirmed source wins.

    Senserva Watch leans Microsoft. This one is not, and it is in your inbox because
    exploitation is confirmed and the clock is three days.

    Two things make it different from the usual Ray exposure story. It reaches Ray
    instances that were never exposed to the internet, by way of a developer's own
    browser, so firewall rules and network segmentation do not stop it. And the
    machines most at risk are workstations and laptops running Ray locally, not only
    clusters.

    What to do this week. Upgrade Ray to 2.52.0 or later everywhere it runs, and
    inventory by package rather than by host role: pip and conda environments,
    container images, notebook kernels, continuous integration runners, and
    developer laptops. Turn on the token authentication that 2.52.0 introduced,
    because it ships off by default. Then assess: on any machine that ran an earlier
    version, review Ray job submission history for entries nobody recognizes, and
    rotate the credentials that were reachable from those environments. If the
    upgrade has to wait for a change window, separate the two halves of the attack
    and do not run Ray and a web browser on the same machine.

    The full record, with every change we have tracked since it was listed:
    https://senserva.com/cve/CVE-2025-62593.html

    Everything CISA has added beyond Microsoft this month:
    https://senserva.com/non-microsoft-cve-tracker.html

  12. CVE-2026-58231 CVE-2026-34480 CVE-2026-5598

    August 2026

    SAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.

    CVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.

    The fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.

    THREE DAYS

    SAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.

    Be precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.

    THE EXPOSURE

    Shadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.

    What makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.

    THE REST OF THE RELEASE

    A 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.

    Onapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.

    THREE THINGS THIS WEEK

    Determine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.
    Include everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.
    Patch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.

    If patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.

    WHERE THESE NUMBERS COME FROM

    Severity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis.

    Track it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html

The 43 alerts sent so far, newest first; the 12 most recent are printed here and the full table loads above them.

What membership is worth

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

One email address. No tenant connection, no agent, no call.

The audits
Senserva Watch members start with Three Free Unlimited Audits and earn a fresh audit credit every quarter: one full run of everything Siemserva does, all users, all settings, all patches, all tenants. Each audit comes with the complete Senserva MCP server for Claude, so you can ask your own questions of the results, and with validated AI remediation that proposes the fix for what it finds and shows its working.
A standing discount
Members also get 20% off when they buy. Membership is free and stays free; the discount is there because members are the people who already know what we do.
The alerts
Patch and security alerts on what you follow, the Patch Tuesday wire on release day, and a message when something you track enters the CISA Known Exploited Vulnerabilities catalog, which is the change that actually alters your priorities.
The patch scanner beta
Membership includes the beta of the new patch scanner from Mark Shavlik, 25 years after he created HfNetChk, when it becomes available. It goes after the hard ones: the missing updates Intune and the other tools do not find. Local patching comes first, then the rest of the Senserva Watcher family as each one ships, the GitHub and Azure auditors among them, members first in line. Read the Shavlik story for where it comes from.
Watch any CVE or KB
Follow the updates and vulnerabilities that matter to your environment; we record what moved and when, and tell you when it does.
Exports and a member API key
Bulk exports and programmatic access to the member endpoints, as they roll out.
Coming
A family of Senserva Watcher applications is coming: the same tracked data working inside the tools you already run. Members are first in line, and get the applications free.

Start my free audit  ·  See pricing

How it works

Step 1

Drop your email

Just your email, on this page or on any CVE or KB page you are already reading. Nothing else to fill in.

Step 2

Get today's read instantly

The moment you join, you see the current Senserva read: what changed today across Microsoft patches, exploited CVEs, and CISA KEV, written fresh every day.

Step 3

Then we watch for you

The Patch Tuesday wire at the next release, member updates as benefits ship, and change alerts for your watched CVEs and KBs as alerting rolls out.

The data behind membership is the same data on the site: MSRC, NVD, CISA KEV, and FIRST EPSS, refreshed twice a day, with every source credited on data sources and thanks.

Questions people ask before joining

How often will Senserva Watch email me?

Only when something actually moved: a CVE you follow enters the CISA Known Exploited Vulnerabilities catalog, a Critical security update lands, Microsoft ships an out-of-band update, or Patch Tuesday releases. On a quiet week we send nothing, and the log above is the record.

What is the Patch Tuesday wire?

Microsoft publishes its monthly security updates on the second Tuesday of each month. On release day members get one email with the counts, the Critical updates, any zero-days, and links to our per-KB and per-CVE pages. The Patch Tuesday page carries the current month and the next date.

Where does the data come from?

MSRC, NVD, CISA KEV and FIRST EPSS, refreshed twice a day, plus coverage from a fixed list of trusted outlets. Every source is credited on data sources and thanks, and every alert links the page the facts came from.

Does it cover products other than Microsoft?

Alerts lead with Microsoft, because members run Microsoft 365, Intune, Defender, and Entra ID. A non-Microsoft bug earns an email when it is actively exploited and widely run, and it is written as "only if you run this", kept short.

What does it cost, and how do I leave?

Nothing. Membership is free and stays free. Unsubscribe by replying to any Watch message. Your email is never sold or shared, and no tenant data is collected by joining.

Do members see more on the site?

No. Today membership changes what arrives by email and the audit credits you hold; nothing on a page differs for a member. The trackers, the rankings and the reference pages stay free for everyone.

Know an admin who chases CVEs?

Senserva Watch grows when a member sends it to the next person. Pass the page on; the log above makes the case without a pitch.