// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Tuesday, July 21, 2026

2 CRITICAL3 WARNING7 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Inventory all SharePoint deployments and Fortinet instances in your client base today — you need a prioritized patch list before EOD.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE2 items
WARNING☁️ M365/Azure

Microsoft Copilot RCE Patch: CVE-2026-48561 (CVSS 9.6) in July Update

July 2026 Patch Tuesday includes a patch for CVE-2026-48561, a remote code execution vulnerability in Microsoft Copilot with a CVSS score of 9.6, allowing an unauthorised attacker to execute code over the network. This was among the previously fixed-before-Tuesday advisories excluded from the main Patch Tuesday count, meaning it may have been silently addressed earlier this month. MSPs deploying M365 Copilot to clients should confirm tenant environments have received the update.

Read more →
WARNING☁️ M365/Azure

SQL Server 2016 Enters Paid Extended Security Updates Phase from July 15, 2026

SQL Server 2016 has transitioned from regular extended support into the paid Extended Security Updates (ESU) phase as of July 15, 2026, while SQL Server 2014 moves into its third and final year of ESU. Organisations still running SQL Server 2016 without ESU enrolment will no longer receive security patches at no additional cost. MSPs should audit client SQL Server versions immediately and initiate ESU enrolment or migration planning.

Read more →
🔐 SECURITY2 items
CRITICAL🔐 Security

CVE-2026-56164: Actively Exploited SharePoint Zero-Day — CISA Mandates Urgent Patch

CVE-2026-56164 is an unauthenticated, pre-auth privilege escalation flaw in SharePoint Server 2016, 2019, and Subscription Edition, discovered by Mandiant/Google FLARE during real-world incident response. CISA has issued an advisory noting exploitation includes IIS machine key theft, deserialization techniques, and malware deployment for persistence. Critically, SharePoint Server 2016 and 2019 reached end-of-extended-support on July 14, 2026 — the same day the patch shipped. Workaround: enable AMSI and set IIS Request Body Scan to Full immediately.

Read more →
WARNING🔐 Security

Critical RDP RCE CVE-2026-56190 (CVSS 9.8) Patched — Workaround Available

July 2026 Patch Tuesday includes CVE-2026-56190, a critical 9.8 CVSS remote code execution vulnerability in Windows Remote Desktop Services caused by use of uninitialised memory. While assessed as difficult to exploit in mass campaigns, the vulnerability is only exploitable when Network Level Authentication (NLA) is disabled. Workaround: enabling NLA entirely closes the pre-auth attack path without requiring an immediate patch deployment.

Read more →
🔥 NETWORKING1 item
CRITICAL🔥 Networking

Fortinet FortiSandbox OS Command Injection Added to CISA KEV (CVE-2026-39808)

CISA has added CVE-2026-39808 to the KEV catalog — an OS command injection vulnerability in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that allows an unauthenticated attacker to execute arbitrary commands via crafted HTTP requests. The advisory references FortiGuard PSIRT advisory FG-IR-26-100. Organisations running any FortiSandbox product should apply patches per CISA BOD 26-04 requirements without delay.

Read more →
🤖 AI/TOOLING1 item
INFO🤖 AI/Tooling

Microsoft MDASH AI System Credited for Record July Patch Tuesday Volume

Microsoft attributed part of the unprecedented scale of July 2026 Patch Tuesday — the largest ever — to its internal AI-powered vulnerability discovery system (MDASH), which proactively scanned the Windows codebase and surfaced a large number of previously unknown bugs. This signals an ongoing increase in monthly patch volumes as AI tooling surfaces legacy code flaws at scale. MSPs should plan for elevated patching workloads in H2 2026 and ensure automated patch deployment pipelines are configured and tested.

Read more →
📡 INDUSTRY1 item
INFO📡 Industry

ASD Essential Eight and SMB1001:2026 — Compliance Frameworks Update for Australian MSPs

The updated SMB1001:2026 standard has been released, bringing changes relevant to Australian SMB clients alongside the existing ACSC Essential Eight framework. The ACSC's most recent threat data indicates the average cost of cybercrime for Australian SMBs has reached over $46,000 per incident for small businesses and over $97,000 for medium businesses. MSPs aligned with Essential Eight as a service offering should review SMB1001:2026 changes and update client assessment documentation accordingly.

Read more →
Monday, July 20, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice