“Identify all ADFS servers in production, verify current version, and stage CVE-2026-56155 patches in test environments before EOB today.”
SharePoint Server 2016 & 2019 Reach End of Extended Support — CVE-2026-56164 Patch Lands on Last Day
SharePoint Server 2016 and 2019 both reached end-of-extended-support on July 14, 2026 — the same day Microsoft patched the actively exploited CVE-2026-56164 zero-day affecting those versions. Organisations still running either version are now patching an out-of-support product with a known active exploit in the wild. Immediate upgrade to SharePoint Subscription Edition or migration to SharePoint Online is strongly recommended.
Read more →CVE-2026-56155: Actively Exploited ADFS Elevation of Privilege — CISA KEV Deadline July 28
CVE-2026-56155 is an actively exploited elevation-of-privilege flaw in Active Directory Federation Services (ADFS) with a CVSS of 7.8, allowing a low-privileged local attacker to escalate to administrator. It was exploited in the wild before the patch shipped and is confirmed on the CISA KEV catalog with a remediation deadline of July 28, 2026 for federal agencies. A compromised ADFS server can enable arbitrary security token issuance, bypassing authentication for all federated applications; patch immediately and review ADFS hardening guidance.
Read more →CVE-2026-57092: Hyper-V VMSwitch Guest-to-Host Escape, CVSS 9.9 — Highest Score This Month
CVE-2026-57092 is a use-after-free flaw in Windows VMSwitch rated CVSS 9.9, allowing an authenticated guest VM attacker to elevate privileges on the host via specially crafted network requests through the Hyper-V Virtual Switch. Successful exploitation crosses the guest VM boundary to gain elevated privileges on the hypervisor host. Patch all Hyper-V hosts running VMSwitch as an urgent priority, particularly in multi-tenant or shared infrastructure environments.
Read more →Palo Alto Networks Releases PAN-OS Patches Across Multiple Branches — July 2026
Palo Alto Networks released PAN-OS patch updates across versions 10.2, 11.1, 11.2, and 12.1, addressing security vulnerabilities and stability issues. Customers should review applicable release notes before upgrading, particularly for internet-facing firewalls and GlobalProtect VPN gateways. Apply updates in a maintenance window; consult the Palo Alto Networks Security Advisories portal for specific CVE details affecting each branch.
Read more →Microsoft Copilot RCE Bug CVE-2026-48561 Patched — CVSS 9.6 Network-Exploitable
July 2026 Patch Tuesday includes CVE-2026-48561, a remote code execution flaw in Microsoft Copilot with a CVSS score of 9.6 that allows an unauthorised attacker to execute code over the network without authentication. While no active exploitation has been confirmed, the severity and the broad deployment of Copilot across M365 tenants make this a high-priority patch. Apply July Patch Tuesday updates across all M365-connected endpoints and verify Copilot-enabled tenants are updated.
Read more →Kaseya 2026 Report: AI and Automation Now Top Client Priority for MSPs, Overtaking Security
Kaseya's 2026 MSP industry report found that AI and automation has overtaken even security as the number-one client need, with 59% of MSPs expecting AI to eliminate tedious tasks and 44% expecting it to free up time for strategic work. The talent gap has become the industry's primary operational constraint, with difficulty hiring skilled technicians jumping from 9% to 16% year-over-year. MSPs seeing the highest ROI are targeting AI at a single operational bottleneck — typically ticket triage or documentation — rather than broad tool adoption.
Read more →53% of MSPs Now Use AI to Automate Ticketing, Patching and Monitoring — July 2026 Update
As of July 2026, 67% of MSPs sell AI-related services, and 53% already use AI to automate ticketing, patching, and monitoring, with providers reporting up to 40% faster ticket resolution and up to 80% less time on dispatch queues. The three layers of MSP AI adoption are 'watch' (RMM anomaly detection), 'answer' (copilots and documentation), and 'act' (agentic tools like Neo Agent and Rewst for autonomous remediation). Agentic tooling remains the least-adopted layer but offers the highest leverage for MSPs with the right workflows in place.
Read more →ASD Announces Essential Eight to Be Retired and Replaced Over 24 Months
The Australian Signals Directorate announced in June 2026 that the Essential Eight framework will be retired over approximately 24 months and replaced by a new domain-based 'Essentials' framework. This is a significant shift for Australian MSPs who have built compliance practices, client assessments, and security service offerings around the Essential Eight. MSPs should begin monitoring ASD communications for the replacement framework details and plan client conversations about the transition timeline.
Read more →Microsoft Marketplace Expands Multiparty Private Offers to Australia in July 2026
Microsoft announced in July 2026 that the Azure Marketplace multiparty private offers program is expanding to Australia (along with Japan and South Africa). This enables Australian software companies and channel partners to collaborate on deals, simplify transactions, and scale across borders through the marketplace. Australian MSPs with Solutions Partner designations should review eligibility and consider how marketplace-led selling fits their 2026 commercial strategy.
Read more →CRN Australia 2026 Channel Awards Shortlist Announced — MSP Categories Expanded
CRN Australia has announced the shortlist for the 2026 Channel Awards, with MSP of the Year and Service Provider of the Year categories split into headcount-based tiers due to a record number of applications. The awards recognise MSPs, Solution Providers, and MSSPs across the Australian IT channel. MSPs not yet engaged with the CRN community should consider the awards as a business development and brand visibility opportunity in the local market.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.