“Inventory all SharePoint deployments and Fortinet instances in your client base today — you need a prioritized patch list before EOD.”
Microsoft Copilot RCE Patch: CVE-2026-48561 (CVSS 9.6) in July Update
July 2026 Patch Tuesday includes a patch for CVE-2026-48561, a remote code execution vulnerability in Microsoft Copilot with a CVSS score of 9.6, allowing an unauthorised attacker to execute code over the network. This was among the previously fixed-before-Tuesday advisories excluded from the main Patch Tuesday count, meaning it may have been silently addressed earlier this month. MSPs deploying M365 Copilot to clients should confirm tenant environments have received the update.
Read more →SQL Server 2016 Enters Paid Extended Security Updates Phase from July 15, 2026
SQL Server 2016 has transitioned from regular extended support into the paid Extended Security Updates (ESU) phase as of July 15, 2026, while SQL Server 2014 moves into its third and final year of ESU. Organisations still running SQL Server 2016 without ESU enrolment will no longer receive security patches at no additional cost. MSPs should audit client SQL Server versions immediately and initiate ESU enrolment or migration planning.
Read more →CVE-2026-56164: Actively Exploited SharePoint Zero-Day — CISA Mandates Urgent Patch
CVE-2026-56164 is an unauthenticated, pre-auth privilege escalation flaw in SharePoint Server 2016, 2019, and Subscription Edition, discovered by Mandiant/Google FLARE during real-world incident response. CISA has issued an advisory noting exploitation includes IIS machine key theft, deserialization techniques, and malware deployment for persistence. Critically, SharePoint Server 2016 and 2019 reached end-of-extended-support on July 14, 2026 — the same day the patch shipped. Workaround: enable AMSI and set IIS Request Body Scan to Full immediately.
Read more →Critical RDP RCE CVE-2026-56190 (CVSS 9.8) Patched — Workaround Available
July 2026 Patch Tuesday includes CVE-2026-56190, a critical 9.8 CVSS remote code execution vulnerability in Windows Remote Desktop Services caused by use of uninitialised memory. While assessed as difficult to exploit in mass campaigns, the vulnerability is only exploitable when Network Level Authentication (NLA) is disabled. Workaround: enabling NLA entirely closes the pre-auth attack path without requiring an immediate patch deployment.
Read more →Fortinet FortiSandbox OS Command Injection Added to CISA KEV (CVE-2026-39808)
CISA has added CVE-2026-39808 to the KEV catalog — an OS command injection vulnerability in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that allows an unauthenticated attacker to execute arbitrary commands via crafted HTTP requests. The advisory references FortiGuard PSIRT advisory FG-IR-26-100. Organisations running any FortiSandbox product should apply patches per CISA BOD 26-04 requirements without delay.
Read more →Microsoft MDASH AI System Credited for Record July Patch Tuesday Volume
Microsoft attributed part of the unprecedented scale of July 2026 Patch Tuesday — the largest ever — to its internal AI-powered vulnerability discovery system (MDASH), which proactively scanned the Windows codebase and surfaced a large number of previously unknown bugs. This signals an ongoing increase in monthly patch volumes as AI tooling surfaces legacy code flaws at scale. MSPs should plan for elevated patching workloads in H2 2026 and ensure automated patch deployment pipelines are configured and tested.
Read more →ASD Essential Eight and SMB1001:2026 — Compliance Frameworks Update for Australian MSPs
The updated SMB1001:2026 standard has been released, bringing changes relevant to Australian SMB clients alongside the existing ACSC Essential Eight framework. The ACSC's most recent threat data indicates the average cost of cybercrime for Australian SMBs has reached over $46,000 per incident for small businesses and over $97,000 for medium businesses. MSPs aligned with Essential Eight as a service offering should review SMB1001:2026 changes and update client assessment documentation accordingly.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.